Trust Center

Security you can feel, not just certify.

Chrysalis is built so the guarantees are structural: each person owns their context, consent is scoped and revocable, and vaults stay encrypted and unreadable — even to us. Below: how that works, where we are on certification, and how to reach us for support, data requests, or security concerns.

SOC 2 Type IIAudit in progress
HIPAAIn progress
Encrypted & never trained onActive today
SupportContact us ›Answered by a person
Data requestsExport or delete ›Your rights, on demand
Security & privacyReport a concern ›Never buried
Help Center

Search our FAQ.

Answers to the questions people ask most — data handling, response times, deletion, and how to reach us. No login required.

How does Chrysalis handle my data?
Your data lives in an encrypted vault that stays unreadable until you grant access. You decide what enters a Space, who can see it, and for how long. We don't sell your data, and we never use it to train models.Data & privacy
Do you train AI models on my data?
No. We never train models on user or client content — full stop. Your context is used only to serve you and the relationships you explicitly grant access to.Data & privacy
Is my data encrypted, and who can read it?
Data is encrypted in transit and at rest. Vaults remain unreadable until access is granted, and internal access is scoped and logged — there's no standing access to your content by default.Data & privacy
Who owns my context and memory?
You do. Each person's context belongs to them; a business's IP belongs to the business. They're governed separately, never blended into a pool someone else controls.Data & privacy
How do I delete my data?
You can permanently delete your data at any time. Email chrysalis@chrysalis.inc to request it, and see our Data Deletion Policy for the process and timelines. This maps to GDPR Art. 17 and our HIPAA obligations.Deletion & rights
How long does a deletion request take?
We confirm receipt within 2 business days and complete verified deletions within the window documented in our Data Deletion Policy. You'll receive confirmation when it's done.Deletion & rights
Can I export a copy of my data?
Yes. You can export a full, portable copy of your context and memory at any time, so ownership is something you can actually act on.Deletion & rights
How do I revoke access I've already granted?
Open the Space and revoke its access — it takes effect immediately, with no support ticket required. A revoked Space can't quietly keep reading, because permissions are enforced in the architecture.Deletion & rights
How do I report a security or privacy concern?
Email security@chrysalis.inc — it's monitored and never buried. See the Security & privacy reporting section for what to include, especially anything touching health information (PHI).Security
What happens if there's a breach?
We maintain an incident response process and, where required by law and our HIPAA obligations, will notify affected users and authorities within mandated timelines. Report anything you notice to security@chrysalis.inc.Security
How do I contact support?
Email chrysalis@chrysalis.inc and a real person gets back to you. See the Support section for every way to reach us.Support
What are your response times?
We reply to support requests within 2 business days, and confirm data and security requests within the same window. Urgent security matters should go to security@chrysalis.inc.Support
Are you SOC 2 and HIPAA compliant?
Both are in progress. Our SOC 2 Type II audit is underway, and we're aligning HIPAA controls and agreements as part of our HHS Invisible Illness work. Encryption, no-training, consent controls, and data deletion are active in the product today.Compliance
Do you have a documented data deletion policy?
Yes — it's public. Read the Data Deletion Policy for the process, timelines, and how to submit a request.Compliance
No answers match that yet. Try different words, or contact support and we'll help directly.
The foundation

Three guarantees, built into the architecture.

Certifications describe how a company operates. These describe how the product is built — the parts a policy can't quietly change.

You own it

User-controlled by design

Each person's context belongs to them. A business's IP belongs to the business. Two different things, under two different sets of rules, governed by one platform — not blended into a pool someone else controls.

Consent as a system

Scoped, revocable, visible

People choose what enters a Space, who can see it, and for how long — and can pull it back at any time. Consent is a first-class control surface, not a checkbox buried in preferences.

Never trained on

Unreadable, even to us

Vaults are encrypted and stay unreadable until access is explicitly granted. We don't train models on anyone's data, and there's no back channel where your context becomes someone else's product.

Certifications & compliance

Where each certification stands.

Some controls are live in the product today. Others are formal audits still underway. Every item below shows its current status.

SOC 2 Type II

Independent audit of our security controls is underway. Report available under NDA to qualified partners on request.

In progress

HIPAA

Aligning controls and agreements for regulated health contexts as part of our HHS Invisible Illness work.

In progress

Encryption in transit & at rest

Data is encrypted end to end; vaults remain unreadable until access is granted.

Active

No model training on your data

We never train models on user or client content. Full stop.

Active

Data export & deletion

You can export or permanently delete your data. See our Data Deletion Policy for the full process and timelines.

Active

User-controlled consent

Scoped, revocable permissions on every Space, visible to the person at all times.

Active
Your data, your rights

The controls are yours, not a favor we grant.

Ownership only means something if you can act on it. Every person and business on Chrysalis can do all of this, on their own, whenever they want — no request form, no waiting.

  • Export everythingTake a full copy of your context and memory with you, in a portable form.
  • Delete permanentlyRemove your data for good, with clear timelines documented in our Data Deletion Policy.
  • Revoke any accessCut off a Space or a relationship's access to your context instantly.
  • See where it livesKnow what's shared, with whom, and for how long — no hidden copies.
Under the hood

The security details, for the people who ask.

If you evaluate vendors for a living, here's the short version of how the platform is built. A deeper architecture brief is available under NDA.

Isolated vaults

Each person and program has its own encrypted vault. Access is granted per-Space and stays unreadable until it is.

Encryption everywhere

Data is encrypted in transit and at rest, with key management separated from application access.

Least-privilege access

Internal access is scoped and logged. No standing access to user or client content by default.

No training, no resale

Your data is never used to train models and is never sold or shared beyond the access you grant.

Consent-aware data flows

Permissions are enforced in the architecture, so a revoked Space can't quietly keep reading.

Vendor review ready

Security questionnaires, our SOC 2 report (once complete), and an architecture brief are available under NDA.

Reach us

It should be obvious how to get help.

Three clear channels — everyday support, data requests, and security. Each one easy to find, and answered by a person.

Support

Questions about your account, a Space, or how something works. Email us and a real person gets back to you.

Replies within 2 business days
chrysalis@chrysalis.inc →

Data requests

Ask for a copy of your data, or request that we delete it. See the full process and submit a request.

Export or delete, anytime
Request your data →

Security & privacy

Report a vulnerability, a privacy issue, or anything touching health information (PHI). Monitored, and never buried behind a login.

Priority handling
security@chrysalis.inc →
Talk to us

Have a security or compliance question?

We'd rather have the real conversation than hand you a badge and hope. Reach our security team, or request documentation for your review.

Security disclosures: security@chrysalis.inc