CommScore.AI
The score How it works Revenue Why us FAQ
Sign in Book a demo →
Trust

Data Security

How CommScore.AI protects your data - from upload, through scoring, to storage. This is a summary; the full security document is available on request.

The short version

CommScore.AI runs on Microsoft Azure, behind Azure Front Door. It is operated by Customer Science Group, which holds ISO 27001:2022 certification for information security management.

  • The communications you submit may contain personal information. That content stays inside the Azure boundary.
  • The original file you upload is never stored - only the text you confirm.
  • Your content is never used to train any model, and is never reviewed by humans.
  • Nothing is scored until you have read the extracted text and confirmed it.
  • Every score carries its supporting evidence, so a result can always be traced back to the words that produced it.

What CommScore.AI processes

CommScore.AI scores only the communications and brand context you explicitly provide:

  • Communications to score - the emails, letters, notices and other messages you submit, either as an uploaded file (PDF, Word, text or Markdown) or pasted directly.
  • Brand guidelines - tone-of-voice and brand documents uploaded to ground the scoring.
  • Brand configuration and lexicon - values, charter, preferred tone, audience profiles, approved and discouraged terminology.
  • Account context - subscription, user and role records, for access and audit.

Personal information

We do not pretend that the content you submit is free of personal information. A customer's email, a claim update or a bill may contain it. CommScore.AI's posture is built on keeping that content contained rather than on assuming it is absent.

  • All content stays in Azure. Every flow that touches an uploaded document, its extracted text, or any communication content runs on Azure OpenAI, authenticated with Managed Identity, inside the Azure boundary. This is enforced as a code-level guard rail, not a convention.
  • Original binaries are not stored. Uploaded files are extracted to text and the file is discarded. Brand-document text is held transiently and purged once the flow that consumes it completes.
  • Prompt content is never logged. AI request logging is restricted to minimal, non-identifying context - the model and basic request parameters. Instructions, messages and tool arguments are never written to logs.
  • Analytics run on derived data. Structured scores and findings, scoped to your subscription - never raw content.

There is one narrow exception, and we would rather state it than bury it: brand web-search enrichment calls OpenAI directly, outside Azure, and receives only non-identifying brand metadata - the brand name, its public website address, and the country. It never receives a document, a communication, or personal information.

How a communication is processed

  1. Upload or paste. You submit a file or paste text.
  2. Extraction. Uploaded files are extracted to text inside the application. No image or vision processing is performed.
  3. Your confirmation. The extracted text is shown to you to review and edit. Uploaded documents are scored only from the text you confirm. There is no path that scores a raw file you have not seen.
  4. Scoring. The confirmed text is scored against your brand context, on Azure OpenAI inside the Azure boundary.
  5. Results. Scores, supporting evidence and insights are stored as structured data against the item. The original upload is not retained.

AI model security

All AI processing that touches customer content is performed via Azure OpenAI Service, authenticated with Managed Identity. CommScore.AI does not route customer content to OpenAI-direct, to third-party models, or to any non-Microsoft model provider.

Under Microsoft's Azure OpenAI data-processing terms:

  • Your data is not used to train models. Prompts, completions and embeddings are not available to other customers and are not used to improve OpenAI, Microsoft or third-party models. This is a contractual commitment from Microsoft.
  • No human review. Prompts and completions are not stored or reviewed by Microsoft or OpenAI staff.

Organisations that prefer it can point CommScore.AI at Azure OpenAI in their own Azure subscription.

Responsible AI

  • Evidence-backed scoring. Every score is accompanied by supporting evidence quoted from the communication, which is what makes a result auditable rather than a black box.
  • Structured output constraints. AI responses are schema-constrained, reducing hallucination and unintended output.
  • Repeatable by design. Calls use low-temperature settings and fail closed on incomplete output, rather than emitting a silently degraded score.
  • Human in the loop. Documents are scored only from user-confirmed text. Improvement rewrites are generated only when explicitly enabled for your subscription.

Encryption

At rest: Azure platform encryption throughout - Transparent Data Encryption on the database, and AES-256 on storage.

In transit: TLS 1.2 or higher on every hop - browser to API via Azure Front Door, API to database, and API to Azure OpenAI.

Network security

  • Azure Front Door fronts both the application and the API, providing TLS termination, web application firewall capability, DDoS protection and global load balancing.
  • Credential-free service access. The application authenticates to its database and to Azure OpenAI using Managed Identity. No database passwords, API keys or connection strings live in application configuration.
  • Private networking. Backend data services are reached over private endpoints within an Azure virtual network, with public access restricted.
  • CORS allow-listing restricts the API to the application origin.

Access control and isolation

  • Authentication uses OAuth 2.0 / OpenID Connect with cryptographically verified tokens. Signing algorithms are pinned, and audience and issuer are validated on every request.
  • Enterprise SSO to your own Microsoft Entra tenant is supported, gated by an explicit per-subscription allow-list. A validly-signed token from any other tenant is rejected.
  • Enumeration protection. Sign-in returns an identical response for unknown, malformed and locally-managed email domains, so it cannot be used to discover which organisations are onboarded.
  • Role-based access control is enforced server-side, with safeguards against self-demotion and against removing the last administrator.
  • Subscription isolation. Every request is bound to a single subscription and every query is filtered by it. No data from one subscription is ever used in scoring, calibration or retrieval for another.

Audit and observability

Mutating actions are recorded in an immutable audit log. Request tracing, error logging and performance metrics are captured in Azure Application Insights. Static analysis, a software bill of materials, and a secret scan run on every build.

Your responsibilities

  • Manage user access and role assignments within CommScore.AI.
  • Ensure you are authorised to upload and score the communications and brand material you submit.
  • Secure any identity-provider configuration you federate.
  • Notify us of any suspected security incident.

Contact

For security enquiries, data processing agreements, or the full security document, contact your Customer Science account representative or email info@customerscience.com.au.

At a glance

Certification:
ISO 27001:2022

Infrastructure:
Microsoft Azure, behind Azure Front Door

AI processing:
Azure OpenAI, via Managed Identity

Model training:
Your data is never used

Uploaded files:
Never stored

Privacy Policy →

Terms of Service →

Request the full document →

CommScore.AI

CommScore.AI measures customer communications against the brand you built, then proves the improvement.

Product
  • The report
  • The score
  • How it works
  • Revenue
  • FAQ
Customers
  • Sign in →
  • Book a demo
Company
  • About Customer Science
  • Contact
  • Data Security
  • Terms of Service
  • EULA
  • Privacy Policy
© 2026 Customer Science Group · CommScore.AI
Built by Customer Science Group