Assurance posture
Implemented application controls, described without borrowed trust marks.
This record describes implemented application controls. Chronicle does not claim a third-party certification or independent audit on this page.
Trust surface / control record
Chronicle is a native AI operator, not an invisible automation layer. Its proposed actions pass through policy, its consequential stops remain human decisions, and its operating record stays attributable.
Authority path
Architectural principles / Truthful controls
Every tile below is an implemented architectural boundary. There are no unverified compliance badges or borrowed ratings on this page.
Policy runs before transport. Consequential stops remain human decisions.
Autonomy is earned at every boundary. A control surface never claims an audit or certification it has not completed.
Customer-owned connector credentials are size-validated, encrypted before database storage, and never displayed again.
Authenticated Clerk session resolved to business entity; database tables enforce business scope with no public access.
Provider signatures or shared secrets verified for Twilio, Meta, Resend, and Vapi before accepting work.
Customer conversations are processed solely to operate the service. Chronicle does not build a shared training corpus across tenants.
Urgent, fallback-routed, or unapproved actions stay pending for authenticated operator review.
Assurance posture
This record describes implemented application controls. Chronicle does not claim a third-party certification or independent audit on this page.
Security boundaries / 03 controls
Precise product boundaries, without certification badges or blanket guarantees.
Layered control object
Ingress → ownership → credential
AES-256-GCM before database storage
Tenant scope
Authenticated control-plane APIs resolve the signed-in Clerk user to a business and scope records to that business. Database tables use business identifiers and row-level security with no public policies; privileged server access remains responsible for enforcing ownership.
Write-only secrets
Customer-owned connector credentials are validated, encrypted with AES-256-GCM before database storage, and never displayed again by the control surface. Server provider keys stay in deployment environment variables; Google OAuth tokens are tenant-scoped and removed on disconnect.
Verified ingress
Configured Twilio, Meta, Resend, and Vapi ingress validates a provider signature or shared secret before processing. Routes reject invalid requests, and route-specific body limits and provider event identifiers reduce unbounded or duplicate work.
Audit trail / CTRL-03
Chronicle records inbound work, triage metadata, action intent, policy outcome, delivery attempts, and key human or configuration actions with an actor and timestamp. This is an operational audit trail, not an external assurance report.
Operational record
Activity record anatomy
Data controls / CTRL-07
Conversation content is used to triage, draft, deliver, and improve rules for the same business. Model providers receive the content needed for inference under their API terms; Chronicle does not build a shared training corpus from customer conversations.
Data boundary
Conversation content / bounded uses
Input
Conversation content
Content needed to operate the service
Operational use
For the same business
Provider boundary
Model providers
Content needed for inference / under their API terms
Shared training corpus
Not built from customer conversations
Shared responsibility / read before deployment
Tenant-scoped application access, outbound policy gates, provider-ingress checks, operational records, and the security of Chronicle-controlled systems.
Lawful collection and messaging, TCPA and channel consent, contact lists and opt-outs, approval settings, connected-account access, and review of AI output before relying on it.
Delivery, availability, and their handling of data under the terms you or Chronicle have with them. Provider failure can delay or prevent an action.
Security report
Coordinated disclosure
Send reproduction steps, affected surface, and potential impact to support@chronicles.systems. Please avoid accessing data that is not yours and allow a reasonable remediation window before public disclosure.