Built to be examined.
You will have to explain this platform to auditors and regulators. Here is what it does to protect your data and your decisions, stated plainly.
Controls in the platform
Isolation in the database
Each organisation’s data is separated by row-level security enforced by the database itself, not only by application code.
Tamper-evident audit trail
Decisions and actions, including those taken by agents, are written to a hash-chained audit trail.
Single sign-on
Connect your identity provider over SAML or OIDC.
Passkeys and security keys
Second-factor sign-in with passkeys and hardware security keys.
Data residency
Store your data in the EU, the US, the UK or Asia-Pacific.
Four eyes on key decisions
Consequential decisions need a maker and a separate checker.
People approve agent actions
Irreversible and regulatory actions proposed by agents always wait for human approval.
Signed webhooks
Every event we send is signed, so your systems can verify it came from us.
Mapped to the rules you answer to
Platform controls are mapped to these requirements, so you can show which part of the platform supports which obligation.
FATF Recommendations
EU anti-money laundering directives and regulation
US Bank Secrecy Act and FinCEN rules
UK Money Laundering Regulations
MAS Notice 626
FINTRAC requirements
The Travel Rule
Wolfsberg principles
Model inventory, validation and drift monitoring are aligned with SR 11-7 model risk guidance.
A mapping supports your compliance programme; it does not make you compliant on its own. ChrysoSure does not currently hold SOC 2 or ISO 27001 certification. We are preparing for both, and this page will say so when an audit report exists.
Reporting a vulnerability
If you believe you have found a security issue in ChrysoSure, email security@chrysosureai.com. Include the steps to reproduce it and the impact you observed, test only against accounts you own, and give us reasonable time to investigate before disclosing it publicly. Our security.txt carries the same contact.
Due diligence
Send vendor risk and security questionnaires to compliance@chrysosureai.com. How we handle personal data is set out in our privacy notice.
Bring your security questionnaire.
Access is by request while we onboard our first customers. Tell us about your programme and we will walk you through the platform.