Trust surface / control record

Autonomy is earned at every boundary.

Chronicle is a native AI operator, not an invisible automation layer. Its proposed actions pass through policy, its consequential stops remain human decisions, and its operating record stays attributable.

Authority path

Policy before transport

  1. 01Proposed actionRecorded
  2. 02Policy resultEvaluated
  3. 03Human decisionWhen required
  4. 04Delivery attemptAfter approval
Consequential stops remain human decisions

Architectural principles / Truthful controls

Implemented principles Chronicle is built on — nothing borrowed.

Every tile below is an implemented architectural boundary. There are no unverified compliance badges or borrowed ratings on this page.

  • Authority gateCTRL-01

    Policy runs before transport. Consequential stops remain human decisions.

  • Operating principle

    Autonomy is earned at every boundary. A control surface never claims an audit or certification it has not completed.

    Chronicle trust standard / implemented controls
  • Write-only secretsAES-256-GCM

    Customer-owned connector credentials are size-validated, encrypted before database storage, and never displayed again.

  • Tenant isolationRLS Scoped

    Authenticated Clerk session resolved to business entity; database tables enforce business scope with no public access.

  • Ingress integritySigned webhooks

    Provider signatures or shared secrets verified for Twilio, Meta, Resend, and Vapi before accepting work.

  • Data boundary

    Customer conversations are processed solely to operate the service. Chronicle does not build a shared training corpus across tenants.

    Chronicle data policy / strict tenant isolation
  • Boundary holdFail-closed

    Urgent, fallback-routed, or unapproved actions stay pending for authenticated operator review.

Assurance posture

Implemented application controls, described without borrowed trust marks.

This record describes implemented application controls. Chronicle does not claim a third-party certification or independent audit on this page.

Control sourceApplication behavior
Human approvalPolicy enforced
CertificationNot claimed
Last reviewed16 July 2026

Security boundaries / 03 controls

Provider calls must prove origin.

Precise product boundaries, without certification badges or blanket guarantees.

Layered control object

Ingress → ownership → credential

Chronicle-controlled system
01 / Verified ingressProvider signature or shared secret
02 / Tenant scopeSigned-in Clerk user → business
03 / Write-only secrets

AES-256-GCM before database storage

Invalid requests → rejectedGoogle OAuth tokens → removed on disconnect
CTRL-04

Tenant scope

Business ownership is checked

Authenticated control-plane APIs resolve the signed-in Clerk user to a business and scope records to that business. Database tables use business identifiers and row-level security with no public policies; privileged server access remains responsible for enforcing ownership.

CTRL-05

Write-only secrets

Connector credentials are bounded

Customer-owned connector credentials are validated, encrypted with AES-256-GCM before database storage, and never displayed again by the control surface. Server provider keys stay in deployment environment variables; Google OAuth tokens are tenant-scoped and removed on disconnect.

CTRL-06

Verified ingress

Provider calls must prove origin

Configured Twilio, Meta, Resend, and Vapi ingress validates a provider signature or shared secret before processing. Routes reject invalid requests, and route-specific body limits and provider event identifiers reduce unbounded or duplicate work.

Human authority / 02 controls

What the operator does before it acts.

Its proposed actions pass through policy, its consequential stops remain human decisions, and its operating record stays attributable.

Decision sequence

Human gate before delivery

Authority held
  1. 01Proposed actionRecorded
  2. 02Policy resultEvaluated
  3. 03Pending draftHuman when required
  4. 04Approve, edit, or rejectAuthenticated operator
  5. 05Delivery attemptOnly after approval
CTRL-01

Human gate

Policy runs before transport

Before an agent reply can reach a provider, Chronicle records the proposed action and its policy result. Urgent, fallback-routed, low-confidence, SMS or missed-call, unconfirmed-booking, missing-draft, and draft-only cases remain pending for a human.

CTRL-02

Operator decision

Approve, edit, or reject

An authenticated operator can approve, edit, or reject a pending draft. The decision is tenant-scoped; edits and supplied corrections can become business-specific rules, and delivery is attempted only after approval.

Audit trail / CTRL-03

The operating trail is retained.

Chronicle records inbound work, triage metadata, action intent, policy outcome, delivery attempts, and key human or configuration actions with an actor and timestamp. This is an operational audit trail, not an external assurance report.

Operational record

Activity record anatomy

CTRL-03
  1. 01Inbound workRecorded
  2. 02Triage metadataRecorded
  3. 03Action intentRecorded
  4. 04Policy outcomeRecorded
  5. 05Delivery attemptsRecorded
  6. 06Key human or configuration actionsActor + timestamp
Operational audit trail / not an external assurance report

Data controls / CTRL-07

Use is limited to operating the service.

Conversation content is used to triage, draft, deliver, and improve rules for the same business. Model providers receive the content needed for inference under their API terms; Chronicle does not build a shared training corpus from customer conversations.

Data boundary

Conversation content / bounded uses

Same business

Input

Conversation content

Content needed to operate the service

Operational use

  1. 01Triage
  2. 02Draft
  3. 03Deliver
  4. 04Improve rules

For the same business

Provider boundary

Model providers

Content needed for inference / under their API terms

Shared training corpus

Not built from customer conversations

Shared responsibility / read before deployment

A control surface cannot replace your authority.

01Chronicle

Tenant-scoped application access, outbound policy gates, provider-ingress checks, operational records, and the security of Chronicle-controlled systems.

02Your business

Lawful collection and messaging, TCPA and channel consent, contact lists and opt-outs, approval settings, connected-account access, and review of AI output before relying on it.

03Connected providers

Delivery, availability, and their handling of data under the terms you or Chronicle have with them. Provider failure can delay or prevent an action.

Security report

Coordinated disclosure

Found a vulnerability?

Send reproduction steps, affected surface, and potential impact to support@chronicles.systems. Please avoid accessing data that is not yours and allow a reasonable remediation window before public disclosure.

24/7 AI Employee

Calls answered, maintenance triaged, and work moved forward across the tools your team already runs on.

The 24/7 AI Employee for property operations — handling the front line of resident calls, maintenance, and coordination so your people focus on the work that needs a human.

© 2026 ChronicleBuilt for property operations teams.