Security & trust
What your security and procurement teams will ask — answered up front. For the full security documentation package (questionnaires, DPA, subprocessors), email support@chainopus.pro.
Verifiable by design
- Every governance record is hashed and anchored to Polygon mainnet at the moment it is created. The record’s existence and timestamp are provable without trusting chainCheck’s servers — or chainCheck itself.
- Verification is public: any regulator, auditor, or court can confirm a record independently, with no account and no vendor dependency.
- Only the cryptographic fingerprint (hash) goes on-chain. Your documents and data never leave the platform.
Data protection
- All data encrypted in transit (TLS 1.2+) and at rest.
- Per-organization data isolation enforced at the database layer with row-level security.
- Organization-scoped document keys for sensitive artifacts.
Access control
- Role-based access with distinct admin, contributor, and read-only tiers.
- Scoped, expiring audit-access links for regulators and external auditors — share evidence without creating accounts or exposing your workspace.
- Invite-based membership with org-bound acceptance flows.
Infrastructure
- Hosted on SOC 2-audited cloud infrastructure (Supabase/AWS).
- Blockchain anchoring on Polygon mainnet — a public network no single vendor controls.
- Continuous automated sweeps verify anchored records against the chain and flag any divergence.
Compliance & certifications
- chainCheck’s own SOC 2 examination: contact us for current status and our security documentation package.
- Subprocessor list, DPA, and security questionnaire responses available on request.
Sentry AI security guidance
- Sentry provides cited, advisory guidance grounded in recognized AI security frameworks through chainCheck's proprietary AI security methodology.
- Sentry does not perform penetration testing, attack simulation, red-teaming, or automated mitigation, and it does not certify security.
Enforcement signaling
- Every enforcement state change in chainCheck — active, restricted, quarantined, blocked — is a governed decision: made by an authorized role, with a recorded reason, anchored on Polygon, and broadcast to your systems through HMAC-signed webhooks and an authenticated API. Your infrastructure acts on the signal and can independently verify the anchor behind it. chainCheck never holds write access to your identity provider, cloud, or runtime.
Why this matters in litigation
- Audit trails stored only on a vendor’s servers can be challenged as altered or backdated. Records anchored to a public blockchain carry independent, tamper-evident proof of existence and time.
- See the plain-English explainer: what blockchain anchoring gets you in court.
If chainCheck disappeared tomorrow
- Your proofs do not depend on us. Anchors live on Polygon, a public network no vendor controls. The public verify page runs on public RPCs — no chainCheck server in the loop.
- The Merkle specification is published, so any auditor can reconstruct & verify a proof with zero access to chainCheck systems. Records anchored today remain independently verifiable regardless of any vendor relationship.
