Medical records are the most sensitive data a firm handles. Chronos treats every page as PHI — encrypted, access-controlled, audited, and covered by a signed BAA.
Your data is encrypted with AES-256 while it's stored and TLS 1.3 while it moves. Keys live in a dedicated key manager (KMS) and are rotated on a strict schedule.
Each user can reach only the cases and actions they need. SSO and SCIM provisioning are available.
We record every view, edit, export, and login in a tamper-evident log. You can export it for a compliance review anytime.
We run on Aptible's HIPAA-eligible infrastructure in U.S. data centers. Each customer's environment is kept separate on the network.
We store and process PHI inside the United States. We never use your records to train outside AI models.
Every account includes a signed Business Associate Agreement (BAA) at no extra cost — from solo lawyers to large firms.
Chronos uses the administrative, physical, and technical safeguards needed to handle PHI for covered entities and their business associates — defensibility that pays off across every case. See why teams choose Chronos.
Records are encrypted with TLS 1.3 the moment they leave your browser.
The AI reads your records in an isolated environment. No PHI is used to train outside models.
Stored and encrypted with AES-256, locked to your firm with role-based access and a full audit log.
Delete a case or your whole account whenever you want. Deletion is permanent and logged.
These commitments are not marketing copy. Each is verified at the infrastructure and code level.
For the full written policies behind these controls, see our security policy documents →
We use a BAA-covered AI gateway configured for zero data retention. Your records are processed in-context to generate the chronology and are never stored by the AI provider, used to fine-tune a model, or shared with any third party.
Our AI gateway is contractually and technically configured for Zero Data Retention (ZDR) with the underlying model provider. No input text or output is logged or retained by the LLM service after the response is returned.
You can permanently delete any case, client, or your entire account at any time. Deletion removes all associated files from object storage and all database records in a single atomic operation. Deletions are logged in the audit trail and are irreversible.
All PHI — database rows, uploaded files, generated exports — is stored and processed in United States data centers. We do not replicate PHI to international regions.
Every case view, record export, login, deletion, and administrative action is recorded in a tamper-evident audit log, scoped to your firm. The log is exportable at any time for your own compliance reviews.
We publish the full list of vendors that may process customer data on our behalf, including their BAA status and what data each receives. View subprocessors →
Chronos (Mahlum Innovations LLC) carries $2,000,000 in Technology Errors & Omissions and Cyber Liability insurance, including an Artificial Intelligence coverage endorsement extending E&O coverage to AI-delivered services. Certificate of insurance available on request.
We'll share our BAA template, security documentation package, and a security questionnaire under NDA.