PART 08 · THE DIFFERENCE
Us & the category

It comes down to shape.

Almost every product like this does the same thing with your messages: it pools every client's permanent records into the supplier's own cloud. We do the opposite. The permanent record of truth rests in your own Microsoft 365, per organisation, never in one shared vendor vault. We run the channel and hold a working copy to operate it, which you can purge on a 90-day cycle or keep in your own Azure. Two shapes. One of them pools everyone's record of truth. One of them doesn't.

The usual shape

The supplier's own store

Your conversations are copied off to the supplier's servers and pooled with everyone else's. One system, one login, one place where every customer's messages sit together. It is easy to build, and easy to attack: one store, holding the lot, with a single door. The whole field was shaped this way because it was built for the largest, most heavily regulated buyers.

One vault · everyone's messages in it
Our shape

Your own Microsoft 365

Your permanent records live in your own Microsoft 365, under your own rules for keeping them, holding them and searching them. The system of record you answer from rests there, per organisation, never pooled with anyone else's – we never become your system of record. We run the channel and hold a working copy to operate it, which you can switch to a 90-day purge or, on a dedicated deployment, keep in your own Azure. There is no single shared vendor vault holding everyone's record of truth, so there is no pooled archive to lose. To take a hundred organisations' permanent records, an attacker would have to break into a hundred organisations, one at a time. Of the thirty-four vendors we surveyed in June 2026, twenty-five keep every client's permanent records in their own cloud. The only other architecture that leaves the record in the customer's own Microsoft 365 is Microsoft's own governance tooling – and that is not somewhere a parent can message you.

A hundred separate stores · no shared one
26/ 34
vendors we surveyed won't publish a price. We publish ours in full, on this page.
25/ 34
pool every client's permanent records in their own cloud. Ours rests in your own Microsoft 365, per organisation, never ours – we run the channel on a working copy you control.
1at a time
is how many organisations an attacker can reach when there is no shared store to empty.
The honest trade

Here is what we are not. The big suites capture fifty, a hundred, more channels – email, voice, social, the lot – and if you must keep all of that in one place, that is what they are for. We are deliberately narrower: a few places done properly – your own channels, which people can open in a browser or reach by text, and Microsoft Teams – with the record kept in the Microsoft 365 you already have. That is the right size for a UK trustee or council board – a charity or care provider, a school or college, a chartered body or regulator – and the wrong size for a bank. We would rather do a few things well, in a shape we can stand behind, than fifty in a shape that has already been broken into once. The full story of why – the break-in that taught this whole field its lesson – is in Security, further down. Here, the point is only the shape.

PART 09 · SECURITY
Security & data protection

The safest record of truth is the one your tenant owns, not ours.

Start with the part no certificate can grant: your permanent record of truth – the SAR-answerable, eDiscovery archive – rests in your own Microsoft 365, per organisation and never pooled. We never become your system of record. The permanent record lands in your own Microsoft 365 whichever way the conversation comes in – made in our system and handed straight to your Microsoft 365 from your own channel, or captured and passed in from Microsoft Teams. To run the channel we hold a working copy of message content, which you control: switch on a 90-day purge from your admin portal, or take a dedicated deployment where even the working copy sits in your own Azure, so we keep nothing long-term. A break-in at our hosted service would expose recent operational conversation data, never a permanent, pooled archive of every client – your authoritative record is in your own tenant, not on our servers. The rest is below, and where we're still earning a certificate, we say so.

01 · Custody

Your tenant owns the record of truth

Your permanent record lives in your own Microsoft 365, never pooled with anyone else's. We hold a working copy in our own systems to run the channel, and you decide how long it lasts – a 90-day purge, or a dedicated deployment where it sits in your own Azure. If you let our support team in, it is only for the moment they need, and they take no copies out of your Microsoft 365. Ask any supplier what a break-in at their end would spill. Our honest answer: your account and billing details, and at most recent operational conversation data – never a permanent, pooled archive of every client.

02 · Standards

Designed to ISO 27001

Our security is built to the ISO 27001:2022 standard from day one, across the whole of CIaaS Limited's Microsoft 365 and Azure systems – not just one corner of the product. The independent certificate is on its way, and until we've earned it we'll keep saying so plainly. A certificate shows how carefully a supplier guards what it holds – our first safeguard was to keep your permanent record of truth in your own tenant, never pooled in ours.

03 · Government

Cyber Essentials & Cyber Assurance

Targeting Cyber Essentials and IASME Cyber Assurance at whole-organisation scope (CIaaS Limited), under the UK NCSC-backed schemes. Increasingly expected by funders and public-sector partners; until certified, we say "targeting", not "certified".

04 · Residency

Your data stays in the UK

Your record lives in your own UK-based Microsoft 365. It reaches you whichever way the conversation comes in – made in your own channel and handed straight to your Microsoft 365, or passed in from Microsoft Teams – and lands in Microsoft's UK data centres. Every other company we rely on – Microsoft for hosting, calls, real-time message delivery and our own mailboxes, Twilio for the SMS verification text, Andrews & Arnold for the SMS doorbell number, and the browser push services that carry a content-free "new message" nudge – is named, with what it does and where it processes, in our published list of sub-processors.

05 · Privacy

GDPR by design

The data protection paperwork – impact assessment, records of processing, lawful-basis analysis – arrives drafted for your circumstances, ready for your data protection lead to adapt and sign. We do the writing; you do the owning, because only you can.

06 · Transparency

We only keep what people are told about

No secret monitoring. People are on a channel the organisation owns, and they are told it is on the record. Everyone added to a channel gets a notice telling them so, and can object or leave at any time. Lawful and fair by default.

07 · Proof

If we ever touched your data, you'd know

Every organisation gets its own access feed: a content-free, hash-chained log of each time our service touches your data, plus a monthly heartbeat email confirming the chain is unbroken. It records that something happened, never what was said. If we ever accessed your record, the feed would show it – so a quiet month proves itself, rather than asking you to take our word for it.

08 · Governance

The same rules across everything we run

ComplyChat runs inside CIaaS Limited's own Microsoft 365 and Azure systems. We set our security rules once and apply them across the Cyber Essentials, IASME Cyber Assurance and ISO 27001:2022 standards, using our own tool, Secure Compliance. We are working towards each certificate across the whole organisation – everything we run, ComplyChat included – and CIaaS Limited is registered with the ICO (ZC181640).

Why we built it this way · May 2025

In May 2025, one of the best-known names in message archiving was breached. The service ran modified versions of WhatsApp and Signal, and kept a readable copy of every client's messages on its own servers – senior US government officials' and major financial firms' alike, all in one place. The intruder reportedly needed less than half an hour. Message content was stolen, the flaw entered the US government's catalogue of actively exploited vulnerabilities, and the service was suspended.

We take no pleasure in the story – the people involved were working on the same problem we are. We retell it because the lesson is not about one company's carelessness; it is about shape. A supplier that holds everyone's records has built a single, well-signposted prize. That break-in wasn't bad luck. It was the shape.

So we built the opposite shape. The record is made in our system and handed straight into your own Microsoft 365 from your own channel, or – where the conversation runs on Microsoft Teams, no changed apps, nothing bolted on – captured and passed into the same Microsoft 365. The permanent record of truth rests in your own Microsoft 365 – with you, not us, per organisation and never pooled. We never become your system of record. To run the channel we hold a working copy of message content, which you control – a 90-day purge, or a dedicated deployment in your own Azure – and our billing systems only ever see the plan, the number of lines and whether the service is running. An attacker who wanted a hundred organisations' permanent records would have to break into a hundred organisations, one set of locks at a time. There is no single shared vendor vault pooling everyone's record of truth, so there is no pooled archive to steal.

Names, dates and sources available on the call – we'd rather argue architecture than point fingers.
PART 10 · READ BEFORE BUYING ANYTHING
Read this before buying anything in this category

What we won't promise. And nobody honest can.

We won't · 01

Read personal phones.

Nobody can, within the law. A supplier who says otherwise is selling you a data breach with a dashboard. A record can only start where ownership starts: on a channel the organisation controls.

We won't · 02

Pull in your old conversations.

A record can only cover what was on the record from the start. A channel you own has no old group to pull in – each one opens clean, on the record, and nobody – including us – can join a conversation that already exists elsewhere. So we move you forward instead, with the plan, the invites and the ready-made policies to make the switch stick.

We won't · 03

Watch anyone in secret.

Every channel is on the record and everyone on it is told so, in wording we supply; everyone added gets a notice and can object or leave at any time. Telling people is what makes the record usable as evidence and your position easy to defend.

We won't · 04

Claim nobody can read it.

Some suppliers promise that nobody – not even you – could ever read the record. A record nobody can read cannot answer a Subject Access Request: you can't have both a usable record and one nobody can read. Yours lives in your own Microsoft 365, readable by the people you choose – and we say out loud what that does and doesn't mean.

We won't · 05

Become your permanent system of record.

Your permanent record of truth lives in your own Microsoft 365, per organisation and never pooled – we never become your system of record. We run the channel and hold a working copy to operate it, which you can purge on a 90-day cycle or keep in your own Azure on a dedicated deployment. A supplier that pools every client's permanent records has built one well-signposted vault – and a vault of exactly that shape was broken into by hackers in May 2025. Yours sits in your own Microsoft 365, behind your own locks – the record of truth is never vendor-owned.

If another vendor promises any of the above, ask them to put it in the contract. Ours is in writing, on the pricing page.
The demo · from your own phone

Know where you stand before someone asks.

Thirty minutes with our team. Bring your hardest case – the group nobody admits to, the leaver with two years of messages. In the first minute or two you'll be messaging in a real channel from your own phone; before we finish, a magic link signs you into your own client portal, where you can see your own record. Then a straight answer on whether we are right for you. Even if that answer is no.

The briefing: one page on the risks in your work messaging, written for boards. No follow-up unless you ask for one.