Skip to content

Data Security & WORM Storage FAQ

WORM stands for Write Once, Read Many. It is a data storage method where information, once written, cannot be modified or deleted until the retention period expires. SEC Rule 17a-4 requires that electronic communications be stored in WORM-compliant format.

Comma stores all archived messages in WORM-compliant storage, ensuring that records cannot be tampered with, accidentally deleted, or altered after capture.

Comma uses multiple layers of encryption:

  • In transit - All data is encrypted using TLS 1.3 during transmission between devices, Comma servers, and storage
  • At rest - Archived messages are encrypted using AES-256 encryption in storage
  • Key management - Encryption keys are managed through a dedicated key management service with regular rotation

Comma uses SOC 2-compliant data centers. Data residency options are available for firms with geographic requirements. Contact your account representative for specific data center locations.

Access is controlled through role-based permissions:

  • Compliance officers - Full access to all archived messages, policies, and review queues
  • Supervisors - Access to messages from their direct reports
  • Auditors - Read-only access with export capabilities
  • Individual users - Can view their own archived messages (if enabled by admin)

All access is logged in an immutable audit trail.

Yes. Every action in Comma is logged, including:

  • Who accessed which messages and when
  • Search queries executed
  • Exports performed
  • Policy changes
  • User permission changes
  • Integration connections and disconnections

The audit trail itself is stored in WORM format and cannot be modified.

  • Continuous replication - Data is replicated across multiple availability zones in real time
  • Point-in-time recovery - Restore data to any point within the retention window
  • Disaster recovery - Full site failover with RPO (Recovery Point Objective) under 1 hour

What compliance certifications does Comma hold?

Section titled “What compliance certifications does Comma hold?”
  • SOC 2 Type II — examination in progress. A signed status letter confirming the engagement is available under NDA. Contact security@commacompliance.com to request it.
  • SEC Rule 17a-4 compliant storage (third-party validated)
  • FINRA Rule 4511 compliant retention

Yes, on Enterprise plans. By default Comma manages encryption keys via Azure. Customer-managed keys (BYOK) are available on request — contact your account team to scope which data your key covers and to enable it for your tenant. BYOK isn’t self-serve; there is no key entry field in the Configuration Center.

Yes, at any time, and every self-service path is included in your subscription (an overdue invoice pauses access until it is paid):

  • Full export to your bucket - verify a bucket on the Retention screen, email support, and your complete archive of business-classified sealed records and attachments is delivered into an S3 bucket or Azure Blob container you own, within 10 business days, in the documented batch layout with a SHA-256 manifest per batch
  • Bucket copy - the same delivery running continuously, so your storage always holds a current second copy
  • Collection export - export a Case or Legal Hold as a ZIP of sealed JSON records, native attachments, readable thread PDFs, an index, and a SHA-256 manifest
  • EML - export any message or thread as EML
  • API - page through the archive with the REST API
  • Dashboard - export search results as CSV or PDF for people to read

JSON and EML are the formats to plan a migration around. See Leaving Comma: your data, your copy.

Can I forward archived messages to my existing compliance system?

Section titled “Can I forward archived messages to my existing compliance system?”

Yes. Comma supports forwarding archived messages to your existing compliance system, including self-hosted archives. Contact your account team to configure a forwarding destination.

Comma’s data security guarantees apply only to data stored within Comma’s infrastructure. Once messages are forwarded to a third-party system, the security, retention, and compliance obligations for that data are governed by your agreement with that provider. Customers are responsible for ensuring their downstream systems meet applicable regulatory requirements.