Transparency reports
What we will publish, and how often, about requests for data, security incidents and changes to the algorithms on Compass Platform.
1. What the reports cover
Each report will state, for the period: the number of requests for data received from authorities and how we responded; security incidents that affected customer data and the notifications made; releases of Compass Platform and the algorithms, with version numbers and the verification records attached to each release; and service availability.
2. Where the data comes from
The platform keeps an audit log of 27 event types covering slide access, analyses, exports and every permission, group and account change. Every release tag generates test reports, coverage, a CycloneDX software bill of materials, a SOUP list and a CVE scan per component, permanently attached to the release.
3. Security incidents
We follow the disclosure policy published in our repository: acknowledgement within 2 business days, assessment within 5, and fix targets of 48 hours for critical, 7 days for high, 30 days for medium and the next release for low severity issues.
4. Model changes
Each algorithm has a code, a version and the indications it has been validated on, shown in the platform before it is run. Changes to a model’s version or validated indications will be listed.
5. Schedule
Reports will be published [annually / half-yearly] on this page. First report: [date].
6. Previous reports
None yet.
Contact
Questions about this document: info@octopath.ai. Data protection: privacy@octopath.ai. Security: security@octopath.ai.