Complium - AI-Native PCI DSS Compliance Platform
EIC · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 7 captures on record
What the publisher says
As described on Microsoft Marketplace.
Complium: QSA-Engineered SaaS for PCI DSS v4.0.1
Complium is an end-to-end SaaS platform for achieving and maintaining PCI DSS v4.0.1 compliance. Built by EIC Limited—a Qualified Security Assessor (QSA) company—the platform mirrors an assessor's exact workflow. Evidence is structured per requirement for Report on Compliance (ROC) work, guiding you from scoping to the final deliverables. The entire workflow is strictly human-gated: AI operates as a tool to organize data, not as an assessor. EIC's embedded QSA independently reviews all evidence to determine final compliance, validate the ROC, and sign the Attestation of Compliance (AOC).
Show the rest of the publisher’s description (20 more lines)
One Firm, Platform, and Validation: Most tools provide software only, forcing you to separately engage an assessment firm. Complium is exclusively delivered by EIC Limited. Because the SaaS platform and the assessment come from the same firm, EIC's QSA is embedded in the workflow. Your evidence is automatically structured for the exact process they use to validate your environment. EIC confirms QSA qualification for your region prior to onboarding.
Azure-Connected Evidence Automation (Read-Only):
- Microsoft Entra ID: Access-control and authentication evidence (Req 7, 8).
- Azure Activity Logs: Audit-logging evidence (Req 10).
- Microsoft Defender for Cloud: Configuration posture across network, secure-configuration, data-protection, and vulnerability families (Req 1–4, 6, 11). (Note: Cloud evidence covers a subset of testable controls; the rest is assessed via the platform by EIC's embedded QSA).
Six AI Capabilities (All Human-Reviewed): Powered by Azure OpenAI through a configurable provider layer:
- Evidence Analysis: Extract and classify documents.
- Compliance Copilot: Retrieval-augmented Q&A on PCI DSS v4.0.1.
- Requirement-Status Suggestions: Proposed status with reasoning.
- ROC Finding Narratives: Draft justifications for review.
- Cloud Control Mapping: Map Defender findings to requirements.
- Remediation Guidance: Plain-language steps for gaps.
Every AI output is a draft. No status is recorded or report produced until EIC's embedded QSA explicitly reviews and accepts it, in strict alignment with PCI SSC AI guidelines.
Data Isolation & Graph API Scopes: Complium requests zero write permissions, protects data with strict row-level security, and connects via Admin-Consent OAuth2, Azure Lighthouse, or Service Principal using these read-only scopes:
- — Account-status inventory (Req 8)
- — Directory configuration (Req 8)
- — Sign-in and directory audit logs (Req 10, 7)
- — Authentication and MFA policy (Req 8)
- — Directory role assignments (Req 7)
Published by EIC Limited, a Qualified Security Assessor (QSA) company.
Preview
5 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Plans and pricing as listed
4 listedSources
Publisher resources
1 linkLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.






