Chion data security starts with a read-only role you control.

The role you supply sets the ceiling: your grants and your row-level security policies decide which tables and rows any SELECT can read. Chion checks each generated statement in code and rejects anything that is not a read-only SELECT before it reaches your database.

Anthropic receives your question, your table and column names, and the rows your query returned, because the narrative is written from those rows. What reaches the model is listed below.

Get answers for your security review →

AES-256-GCM vaultIn production
TLS 1.3 in transitIn production
Read-only SELECTIn production

Read-only SELECT. Credentials in an AES-256-GCM vault. Results capped at 1,000 rows. Each executed query leaves an audit row, written by the service role and hashed rather than transcribed, fire-and-forget so a logging failure never blocks your answer. What reaches the model is listed below.

"In production" means the control is implemented and enforced in code today. Chion does not yet publish a live status page or third-party SLO telemetry.

Every query is checked before it runs.

Two validator layers, a typed SQL contract, execution under the role you supply.

Chion runs every question through a typed contract and a two-layer validator before it reaches your database. Read-only SELECT enforced at the first layer. SQL contract bound to your RLS-aware schema at the second layer. That is how a SQL agent differs from a plain text-to-SQL tool. Read-only stops writes. It does not stop a slow scan or a SELECT that reads a column someone considers sensitive, so the role you grant still matters more than the prompt.

Top 10 security questions answered

The questions your security team will ask, answered upfront.

1Can Chion write to, modify, or delete data in my database?
No. Every query Chion generates is a SELECT statement. Multi-stage safety: the read-only database role you provide, the SQL contract that bounds generation, and runtime validation (a two-layer validator that blocks writes and enforces the SQL contract) before execution. Any non-SELECT is rejected before it reaches your database.
2Does Chion train AI models on my data?
No. We use Anthropic Claude (Haiku, Sonnet, and Opus) via paid commercial API tiers. Provider terms prohibit training on customer inputs. OpenAI and Google are available on request.
3Does Chion sell my data?
No. Chion will never sell, license, rent, or share your data or metadata with any third party. There is no advertising business model here.
4Where are my database credentials stored?
In an encrypted vault using AES-256-GCM. Plaintext is decrypted into memory for a single request, held for at most 60 seconds or five reads, then purged. Credentials are never logged and never returned in API responses.
5What data leaves my database?
The results of the SELECT you asked for, capped at 1,000 rows or 12,000 cells. Those rows are held in memory for the session to draw the chart. The narrative step then writes from those returned rows, so their values reach the model along with your table and column names.
6Who can see my queries inside Chion?
Only you, under your authenticated session. Chion's own tables carry PostgreSQL Row-Level Security policies scoped to your authenticated user. Each executed query writes an audit row that only service-role functions can insert: event type, user, connection, a query hash, the row count, and the mode. That write is fire-and-forget, so treat the trail as a signal rather than a complete ledger.
7Is Chion SOC 2 certified?
Not today. Chion is a pre-seed startup. Security controls are implemented in code. Formal certifications are not yet scoped.
8Is Chion GDPR compliant?
Chion stores schema metadata and sampled column values. The model receives your table and column names plus the rows your query returned, because the narrative is written from those rows. Sampled column values reach the model too, both in the prompts that match your wording to your columns and in the passes that compile your export. Those values are also written into the CHION.md skill itself, except for columns classed as PII. Query results are held for the session and discarded when it ends. A formal GDPR program is not yet scoped.
9What happens to my data if I cancel?
When you disconnect a data source, all semantic metadata, embeddings, and cached samples for that source are purged. Query results are session-only and discarded when the session ends. Conversation history is deleted on account deletion.
10How do I report a vulnerability?
Email contact@chion.ai.

What the model sees, and what it never touches.

A table of exactly what data Chion accesses, and what it never touches.

What Chion seesWhat Chion never sees
Table names, column names, and data typesRaw rows from tables you haven't queried
The specific SELECT query you asked forYour database password (encrypted and purged after each connection)
Aggregated results of that query (≤1,000 rows)The contents of tables outside your connected role's permissions
Randomly sampled column values used to teach the system your nomenclatureProduction writes: Chion cannot INSERT, UPDATE, DELETE, or DROP
Your questions and the SQL we generate for youAnything another Chion customer's database contains
Whether a query succeeded or failedFiles, application logs, or anything outside your PostgreSQL instance
Instructions hidden in your dataTreated as data, never executed: user input is escaped before it reaches the model

Guardrails you would otherwise build, already built.

Most teams assemble this themselves: a read-replica, a least-privilege role, a hand-written query allowlist, or an MCP gateway you configure and maintain yourself. Chion enforces all of it in code by default.

Read-only SQL enforcement

Every query is SELECT-only. The read-only database role you provide, the SQL contract that bounds generation, and runtime validation (a two-layer validator that blocks writes and enforces the SQL contract) before execution. Any non-SELECT is rejected before it reaches your database.

AES-256-GCM credential vault

Database credentials are encrypted at rest with AES-256-GCM using a Load-Consume-Purge pattern. Plaintext is decrypted into memory for a single request, held for at most 60 seconds or five reads, then purged.

Row-level security

We connect using the role you provide, and every query runs under it, from schema ingestion through execution. The policies that apply are the ones attached to that role: grant it broadly and it reads broadly. Chion never escalates privileges or bypasses access controls.

What the model receives

The model receives your question and your table and column names. It also receives the rows your query returned, because the narrative is written from those rows. Sampled column values reach the model too, both in the prompts that match your wording to your columns and in the passes that compile your export. Those values are also written into the CHION.md skill itself, except for columns classed as PII. Results (≤1,000 rows) are processed server-side for chart rendering, held in memory during your session, and discarded when it ends. Anthropic's paid commercial API tiers prohibit training on customer inputs.

How your data is handled.

What we store, what we discard, and when.

Query results are held in memory during your session for chart rendering. They are not persisted to disk or stored long-term. When you close the session, results are discarded.

Schema metadata (table names, column types, cardinality) is stored server-side to enable contract-based SQL generation. This metadata contains no actual data values.

What we store. Randomly sampled column values (e.g., top categories by frequency) used to build a semantic catalog, and structural metadata (table names, column types, relationships). This teaches the system your nomenclature, not your data.

Credentials are encrypted in our vault and never transmitted in plain text. Decrypt and purge events have named audit types, and coverage is not uniform: some consume and purge paths still run without an audit callback.

Conversations (your questions and generated SQL) are stored to enable conversation history. They do not contain raw data rows.

Full data retention terms are in our Privacy Policy.

How credentials and sessions are handled.

Rolling sessions, automatic renewal, and credential purge.

Sessions renew on their own

Database sessions roll on a 24-hour cycle with automatic renewal on successful validation. Credentials are scrubbed after 3 consecutive failures or explicit disconnect. A 30-day reconnect hint preserves non-secret topology (host, port, schema names) so re-authentication requires only a password, no full reconfiguration.

Everything your security team will ask for.

The controls enterprise buyers expect at scale.

For enterprise buyers evaluating Chion at scale: DPA on request, full sub-processor disclosure. Managed cloud today. Dedicated GPU compute and on-premise model hosting are Enterprise roadmap items discussed under contract. Current authentication does not include SAML or SCIM. Same read-only pipeline as Starter/Pro/Max.

See Enterprise pricing or contact us to scope a deployment.

Deploy where you need to.

Managed cloud today. Dedicated GPU compute and on-premise model hosting are Enterprise roadmap items discussed under contract.

Your deployment, your rules

Today Chion runs as a managed cloud service on Anthropic's paid API tiers. Dedicated GPU compute, on-premise model hosting, and per-deployment model choice are Enterprise roadmap items discussed under contract. Every deployment runs the same read-only SELECT path through the same validators.

Whether the model runs on a managed provider's API or a self-hosted instance, the same pipeline applies: a code-checked read-only SELECT, and a narrative written from the rows that SELECT returned.

Who owns security at Chion

Security principles and ownership across the engineering team.

When in doubt, the query stops

When any invariant is violated, the system stops and surfaces the error. No silent recovery.

Owner: Engineering

Only what is needed

We collect only the structural metadata we need to generate correct SQL. We do not hoard.

Owner: Engineering

Credentials live only in the vault

Every database password lives in an AES-256-GCM vault and is purged from memory within milliseconds of use.

Owner: Engineering Lead

Every query leaves an audit record

Each executed query writes one row to the security audit log through a service-role function: event type, user, connection, a query hash, the row count, and the mode. The write is fire-and-forget, so a failed insert never blocks or fails the query. That makes the trail best effort rather than a guarantee of completeness. The prompt and the SQL text are not columns, and credential teardown coverage is not yet uniform. Target retention: up to 12 months for security events, 30-day rolling for diagnostic logs. Actual retention is governed by our database retention policy.

Owner: Engineering

Compliance, stated plainly

We publish what's shipped and what's in progress. We do not claim certifications we do not hold.

Owner: Jonathan Dag & Legal

Where we stand on compliance.

What certifications we hold, what's in progress, and what's honest.

Chion is a pre-seed startup. Security controls are implemented in code and described on this page. Formal third-party audits (SOC 2, ISO 27001, pen test) are not yet scoped. We will add audit commitments when we have them.

HIPAA. Not supported. Do not connect databases containing protected health information (PHI) to Chion.

GDPR. Chion stores schema metadata and sampled column values. The model receives your table and column names plus the rows your query returned, because the narrative is written from those rows. Sampled column values reach the model too, both in the prompts that match your wording to your columns and in the passes that compile your export. Those values are also written into the CHION.md skill itself, except for columns classed as PII. Query results are held for the session and discarded when it ends. A formal GDPR program is not yet scoped.

DPA. Data Processing Agreement available on request for enterprise customers. Covers data handling, sub-processor disclosure, and breach notification procedures.

Our Terms of Service cover service-level commitments and breach-notification timelines.

Sub-processors

Every service we send anything to, what we send, and why.

Chion is only as trustworthy as the services it touches. Every tool in your stack is a liability if it touches your data. Here's every service we send anything to, what we send, and why. No hidden processors.

In production today

ProviderRoleLocation
SupabaseAuthentication, database, edge functionsUS/EU
AnthropicLLM provider, primary model (Claude)US
StripePayment processingUS
ResendTransactional email deliveryUS

Planned / roadmap

ProviderRoleLocation
OpenAILLM provider, planned (GPT)US
GoogleLLM provider, planned (Gemini)US
MistralLLM provider, planned (Mistral)EU
CoreWeaveDedicated GPU compute for isolated model hosting (planned)US

Planned processors are listed for transparency. They are not yet integrated and receive no production data today. We will move them above when they ship.

Vulnerability reporting

How to report a security issue to our team.

If you discover a security vulnerability or suspect unauthorized access, email contact@chion.ai.

By using Chion, you agree to the disclosure obligations in our Terms of Service.

Last reviewed: September 2, 2026