Security

Security

Chameleon Eye AI is built with server-side key protection and clear architecture controls at every layer of the platform. Compliance certifications are on the roadmap.

Compliance and Assurance Status

Current status of compliance programmes and planned assurance milestones.

Early-Stage Product

SOC 2, ISO 27001, and penetration testing are planned milestones — none have been completed yet. See the compliance roadmap for timeline context.

SOC 2 Type II

In Planning

SOC 2 readiness programme is in planning. Not yet completed.

ISO/IEC 27001

In Planning

ISO 27001 preparation is planned. Not yet certified.

Penetration Testing

Planned

Independent security testing is planned before commercial launch. Not yet conducted.

DPA

Available

Data Processing Agreement available on request for business customers.

Responsible Disclosure

Published

Responsible disclosure process published.

Security Architecture

Every request passes through authentication, entitlement checks, privacy guard, and consent gate before reaching the intelligence router.

User App / Web / Desktop
Chameleon Eye API
Authentication
Entitlement Check
Privacy Guard
Consent Gate
Intelligence Router
Approved AI Route
Response Validation
Usage Audit Metadata

The browser communicates only with Chameleon Eye AI-controlled API routes. No AI provider keys are exposed in the frontend.

API Key Protection

Provider API keys are held server-side and are not embedded in browser, desktop, or mobile clients.

Provider API keys are held server-side and are not embedded in browser, desktop, or mobile clients. Customer apps should call from server-side. API keys must not be embedded in clients.

Data in Transit

Encryption and transport security for all platform communications.

Chameleon Eye AI uses HTTPS/TLS for data transmitted between users and the platform.

Password and Account Security

Credential handling and authentication security.

Authentication credentials are handled using secure practices. Passwords are never stored in plain text.

Desktop Connector Security

Short-lived tokens and device activation protect desktop workflows.

+Secure login flow
+Device activation
+Short-lived tokens
+Token refresh mechanism
+Device limits
+Revoke-device capability
+No master API keys in desktop client

Logging Policy

Private content is not written to normal application logs.

+No raw private prompts in normal application logs
+No private document text in logs by default
+No provider keys in logs
+Usage metadata only for billing, abuse prevention, and audit integrity

Access Control

Customer data is separated at account level with workspace permissions and role-based controls.

+Account-level access control
+Workspace permissions
+Role-based controls where applicable
+Authorized-data-only processing policy
+Audit metadata for accountability

Security Headers

All responses include standard security headers and HTTPS enforcement.

+HTTPS/TLS
+Content Security Policy
+Referrer Policy
+Permissions Policy
+HSTS in production
+Frame restrictions

Continuous Security

Ongoing security assurance processes.

+Independent penetration testing — planned before launch
+Vulnerability disclosure process published
+Security review cycle ongoing