Trust FAQ
Trust and Security FAQ
Full answers to the questions security teams, enterprise buyers, partners, and technically curious users ask about Chameleon Eye AI.
Frequently Asked Questions
Is Chameleon Eye AI open source?
No. Chameleon Eye AI is a private-source business AI platform. The source code, routing rules, Business DNA logic, industry systems, and workflow engines are proprietary. This is intentional — the platform is designed for business operations, not open collaboration or model experimentation. Private-source design ensures that routing rules, business context layers, and industry intelligence remain under controlled development.
Is Chameleon Eye AI only a wrapper around an AI model?
No. Approved AI infrastructure may be connected behind the scenes, but Chameleon adds a complete routing layer, Business DNA profiling, document intelligence, workflow logic, role permissions, risk scoring, report generation, decision tracking, and industry-specific systems. The platform's value is the private business intelligence layer — not the underlying compute model. A raw model call produces text. Chameleon produces structured business outputs: risk reviews, reports, decisions, workflows, and operational intelligence.
What AI model does Chameleon use?
Chameleon uses an internal intelligence routing layer. The platform classifies each task by type, applies business context and privacy checks, and selects the most appropriate approved intelligence path. The technical routing is kept internal so business users can focus on their reports, risk reviews, decisions, and operations — not on managing or comparing model providers. The intelligence infrastructure may change over time as better options become available, without affecting the user experience.
Where does my data go?
Chameleon is designed with local-first and approval-based workflows. Supported local data — including local file previews, workspace cache, setup data, and local notes — stays on your device. Cloud analysis is used only when you approve sending selected prompts, file excerpts, or connected system data through Chameleon-controlled backend routes. The browser does not make direct calls to external AI providers. All cloud-bound data travels through Chameleon's server-side routing layer.
Can I use Chameleon through an API?
Yes. Chameleon provides secure API workflows for business intelligence, document review, risk review creation, report generation, webhook event subscriptions, and industry system operations. It is not a raw model API — it is a structured business intelligence API. API keys are scoped to specific permissions, separated into test and live environments, and can be revoked at any time. Keys follow the format che_live_**** and are managed through the platform.
Can enterprise clients restrict AI routing?
Enterprise customers can request approved-routing policies, private deployment discussions, data retention controls, role permissions, and workspace separation depending on implementation scope. Custom routing rules and private infrastructure deployment are available as enterprise options — the exact scope, timeline, and availability depend on the implementation agreement. Contact the enterprise team to begin a scoping conversation.
Does the browser call third-party AI providers directly?
No. The intended and implemented architecture ensures that the browser calls only Chameleon-controlled backend routes. AI infrastructure keys must remain server-side and must not be exposed in frontend environment variables, client bundles, or browser network calls. You can verify this by inspecting the browser's network tab during a Chameleon session — you will see calls to Chameleon routes only, not to external AI provider endpoints.
