ChrysoSure AI

Built to be examined.

You will have to explain this platform to auditors and regulators. Here is what it does to protect your data and your decisions, stated plainly.

Controls in the platform

  • Isolation in the database

    Each organisation’s data is separated by row-level security enforced by the database itself, not only by application code.

  • Tamper-evident audit trail

    Decisions and actions, including those taken by agents, are written to a hash-chained audit trail.

  • Single sign-on

    Connect your identity provider over SAML or OIDC.

  • Passkeys and security keys

    Second-factor sign-in with passkeys and hardware security keys.

  • Data residency

    Store your data in the EU, the US, the UK or Asia-Pacific.

  • Four eyes on key decisions

    Consequential decisions need a maker and a separate checker.

  • People approve agent actions

    Irreversible and regulatory actions proposed by agents always wait for human approval.

  • Signed webhooks

    Every event we send is signed, so your systems can verify it came from us.

Mapped to the rules you answer to

Platform controls are mapped to these requirements, so you can show which part of the platform supports which obligation.

  • FATF Recommendations

  • EU anti-money laundering directives and regulation

  • US Bank Secrecy Act and FinCEN rules

  • UK Money Laundering Regulations

  • MAS Notice 626

  • FINTRAC requirements

  • The Travel Rule

  • Wolfsberg principles

Model inventory, validation and drift monitoring are aligned with SR 11-7 model risk guidance.

A mapping supports your compliance programme; it does not make you compliant on its own. ChrysoSure does not currently hold SOC 2 or ISO 27001 certification. We are preparing for both, and this page will say so when an audit report exists.

Detail of an 1854 nautical chart: hundreds of depth soundings and newly discovered shoals off Nantucket.
US Coast Survey, Preliminary Chart of Nantucket Shoals (1854). Public domain.

Reporting a vulnerability

If you believe you have found a security issue in ChrysoSure, email security@chrysosureai.com. Include the steps to reproduce it and the impact you observed, test only against accounts you own, and give us reasonable time to investigate before disclosing it publicly. Our security.txt carries the same contact.

Due diligence

Send vendor risk and security questionnaires to compliance@chrysosureai.com. How we handle personal data is set out in our privacy notice.

Bring your security questionnaire.

Access is by request while we onboard our first customers. Tell us about your programme and we will walk you through the platform.