Security you can feel, not just certify.
Chrysalis is built so the guarantees are structural: each person owns their context, consent is scoped and revocable, and vaults stay encrypted and unreadable — even to us. Below: how that works, where we are on certification, and how to reach us for support, data requests, or security concerns.
Search our FAQ.
Answers to the questions people ask most — data handling, response times, deletion, and how to reach us. No login required.
How does Chrysalis handle my data?
Do you train AI models on my data?
Is my data encrypted, and who can read it?
Who owns my context and memory?
How do I delete my data?
How long does a deletion request take?
Can I export a copy of my data?
How do I revoke access I've already granted?
How do I report a security or privacy concern?
What happens if there's a breach?
How do I contact support?
What are your response times?
Are you SOC 2 and HIPAA compliant?
Do you have a documented data deletion policy?
Three guarantees, built into the architecture.
Certifications describe how a company operates. These describe how the product is built — the parts a policy can't quietly change.
User-controlled by design
Each person's context belongs to them. A business's IP belongs to the business. Two different things, under two different sets of rules, governed by one platform — not blended into a pool someone else controls.
Scoped, revocable, visible
People choose what enters a Space, who can see it, and for how long — and can pull it back at any time. Consent is a first-class control surface, not a checkbox buried in preferences.
Unreadable, even to us
Vaults are encrypted and stay unreadable until access is explicitly granted. We don't train models on anyone's data, and there's no back channel where your context becomes someone else's product.
Where each certification stands.
Some controls are live in the product today. Others are formal audits still underway. Every item below shows its current status.
SOC 2 Type II
Independent audit of our security controls is underway. Report available under NDA to qualified partners on request.
In progressHIPAA
Aligning controls and agreements for regulated health contexts as part of our HHS Invisible Illness work.
In progressEncryption in transit & at rest
Data is encrypted end to end; vaults remain unreadable until access is granted.
ActiveNo model training on your data
We never train models on user or client content. Full stop.
ActiveData export & deletion
You can export or permanently delete your data. See our Data Deletion Policy for the full process and timelines.
ActiveUser-controlled consent
Scoped, revocable permissions on every Space, visible to the person at all times.
ActiveThe controls are yours, not a favor we grant.
Ownership only means something if you can act on it. Every person and business on Chrysalis can do all of this, on their own, whenever they want — no request form, no waiting.
- →Export everythingTake a full copy of your context and memory with you, in a portable form.
- →Delete permanentlyRemove your data for good, with clear timelines documented in our Data Deletion Policy.
- →Revoke any accessCut off a Space or a relationship's access to your context instantly.
- →See where it livesKnow what's shared, with whom, and for how long — no hidden copies.
The security details, for the people who ask.
If you evaluate vendors for a living, here's the short version of how the platform is built. A deeper architecture brief is available under NDA.
Isolated vaults
Each person and program has its own encrypted vault. Access is granted per-Space and stays unreadable until it is.
Encryption everywhere
Data is encrypted in transit and at rest, with key management separated from application access.
Least-privilege access
Internal access is scoped and logged. No standing access to user or client content by default.
No training, no resale
Your data is never used to train models and is never sold or shared beyond the access you grant.
Consent-aware data flows
Permissions are enforced in the architecture, so a revoked Space can't quietly keep reading.
Vendor review ready
Security questionnaires, our SOC 2 report (once complete), and an architecture brief are available under NDA.
It should be obvious how to get help.
Three clear channels — everyday support, data requests, and security. Each one easy to find, and answered by a person.
Support
Questions about your account, a Space, or how something works. Email us and a real person gets back to you.
chrysalis@chrysalis.inc →Data requests
Ask for a copy of your data, or request that we delete it. See the full process and submit a request.
Request your data →Security & privacy
Report a vulnerability, a privacy issue, or anything touching health information (PHI). Monitored, and never buried behind a login.
security@chrysalis.inc →
Have a security or compliance question?
We'd rather have the real conversation than hand you a badge and hope. Reach our security team, or request documentation for your review.
Security disclosures: security@chrysalis.inc