Your product description is the only thing ComplianceMap needs to build your model. Nothing else leaves your organization. Your requirements, risks, tests, and design history stay where they are today, in your ALM platform, in your environment.
The model is built from that description alone, then you choose how it reaches you. The fast way: ComplianceMap publishes into your existing tool through its API. The hands-off way: we build it in our own ALM environment and send you an export. You import it yourself, and we never hold a login to your systems.
Forensics will run the other way round. It works from your change history, so it runs inside your environment, not ours. It will read through your platform's official API and never the database directly. Every answer is going to respect the permissions the user already has, on the infrastructure of your choice. When a reason is captured, it will be saved as an entry into your development diary, in that user's name.
We designed ComplianceMap around security: your intellectual property and your decision records stay yours, and nothing foreign runs inside your workflow.