Security & compliance

Built to hold
protected health info.

Medical records are the most sensitive data a firm handles. Chronos treats every page as PHI — encrypted, access-controlled, audited, and covered by a signed BAA.

HIPAA-aligned
SOC 2 readiness program
256-bit AES
PHI · ENCRYPTED
AES-256 at rest
TLS 1.3 in transit
// Security pillars

Defense in depth, by default.

End-to-end encryption

Your data is encrypted with AES-256 while it's stored and TLS 1.3 while it moves. Keys live in a dedicated key manager (KMS) and are rotated on a strict schedule.

Role-based access

Each user can reach only the cases and actions they need. SSO and SCIM provisioning are available.

Immutable audit log

We record every view, edit, export, and login in a tamper-evident log. You can export it for a compliance review anytime.

Isolated infrastructure

We run on Aptible's HIPAA-eligible infrastructure in U.S. data centers. Each customer's environment is kept separate on the network.

US data residency

We store and process PHI inside the United States. We never use your records to train outside AI models.

Signed BAA, always

Every account includes a signed Business Associate Agreement (BAA) at no extra cost — from solo lawyers to large firms.

// HIPAA Safeguards

Mapped to the Security Rule.

Chronos uses the administrative, physical, and technical safeguards needed to handle PHI for covered entities and their business associates — defensibility that pays off across every case. See why teams choose Chronos.

  • Access controls (§164.312(a))

    Unique user IDs, automatic logoff, and encryption keep access to ePHI on a need-to-know basis.

  • Audit controls (§164.312(b))

    Hardware and software tools record and review activity in any system that holds ePHI.

  • Integrity (§164.312(c))

    Controls confirm that no one has changed or deleted ePHI without permission.

  • Transmission security (§164.312(e))

    TLS 1.3 protects ePHI from unauthorized access while it travels over networks.

// Data lifecycle

What happens to a record.

01

Upload

Records are encrypted with TLS 1.3 the moment they leave your browser.

02

Process

The AI reads your records in an isolated environment. No PHI is used to train outside models.

03

Store

Stored and encrypted with AES-256, locked to your firm with role-based access and a full audit log.

04

Delete

Delete a case or your whole account whenever you want. Deletion is permanent and logged.

// Data practices

What we do — and don't do — with your data.

These commitments are not marketing copy. Each is verified at the infrastructure and code level.

For the full written policies behind these controls, see our security policy documents →

Zero AI training on your data

We use a BAA-covered AI gateway configured for zero data retention. Your records are processed in-context to generate the chronology and are never stored by the AI provider, used to fine-tune a model, or shared with any third party.

Zero Data Retention with AI provider

Our AI gateway is contractually and technically configured for Zero Data Retention (ZDR) with the underlying model provider. No input text or output is logged or retained by the LLM service after the response is returned.

Customer-controlled deletion

You can permanently delete any case, client, or your entire account at any time. Deletion removes all associated files from object storage and all database records in a single atomic operation. Deletions are logged in the audit trail and are irreversible.

US-only data residency

All PHI — database rows, uploaded files, generated exports — is stored and processed in United States data centers. We do not replicate PHI to international regions.

Full audit trail

Every case view, record export, login, deletion, and administrative action is recorded in a tamper-evident audit log, scoped to your firm. The log is exportable at any time for your own compliance reviews.

Transparent subprocessors

We publish the full list of vendors that may process customer data on our behalf, including their BAA status and what data each receives. View subprocessors →

Insured for the work we do

Chronos (Mahlum Innovations LLC) carries $2,000,000 in Technology Errors & Omissions and Cyber Liability insurance, including an Artificial Intelligence coverage endorsement extending E&O coverage to AI-delivered services. Certificate of insurance available on request.

// Security FAQ

Common questions.

Need our security docs?

We'll share our BAA template, security documentation package, and a security questionnaire under NDA.

Explore features