Public versions of Chronos's core security policy documents. Each describes the controls that actually exist — verified at the infrastructure and code level — rather than aspirational commitments.
Top-level security controls: encryption, access management, data classification, AI processing, incident response, backups, and insurance. The foundational policy for all systems that handle PHI.
Read policy →How every change reaching production is scoped, tested, reviewed, deployed, and rolled back. Covers the truthful-claims gate for public-facing compliance and marketing content.
Read policy →RPO/RTO commitments, backup posture (daily 30 days / monthly 12 months), recovery runbooks for data loss and ransomware, vendor concentration risk, and annual testing cadence.
Read policy →