Security your review team can actually evaluate
People share sensitive things with their Peer Coach. Protecting that information is foundational to how Chaperone is built and operated: encryption, least-privilege access, continuous monitoring, and a SOC 2 readiness and reporting process across the platform and our managed infrastructure.
Defense in depth, written for the people doing the diligence
This page is a buyer- and procurement-level overview of how we protect data: what we encrypt, who can access what, how we monitor, and how we manage the vendors and infrastructure beneath the platform. As our SOC 2 readiness and reporting process completes, control-level evidence will be available to qualifying organizations under NDA.
The headline controls, in one view
A fast orientation before the detail below, useful for an initial security questionnaire pass.
Encrypted in transit, encrypted at rest, minimized by default
We treat behavioral-health information as the most sensitive data we hold. Protection starts with strong encryption and continues through data minimization, isolation between environments, and disciplined key management.
We collect what is needed to provide and improve support, and no more. Production data is kept separate from non-production environments.
- Encryption in transit with TLS 1.2 or higher
- Encryption at rest using AES-256 across data stores
- Managed key storage with controlled rotation
- Data minimization: collect only what support requires
- Production isolated from non-production environments
- Backups encrypted, with tested restore procedures
Least privilege, by role, with a record of who did what
Access to sensitive data is scoped to the people who need it for their role and recorded so it can be reviewed.
Role-based access
Permissions are granted by role under a least-privilege model. People see only the data their work requires, and nothing more.
Strong authentication
Multi-factor authentication is required for administrative and privileged access, with single sign-on supported for partner organizations.
Audit trails
Sensitive actions are logged to an audit trail so access can be reviewed, attributed, and investigated when needed.
Joiner / mover / leaver
Access is provisioned on a need-to-know basis and promptly revoked when roles change or people leave, with periodic recertification.
Network segmentation
Systems are segmented and access is restricted between environments, limiting the blast radius if any single component is compromised.
People, not surveillance
Access controls protect data and accountability. They are not used to monitor the people we support. Oversight stays focused on safety and quality.
- Centralized logging of platform and infrastructure activity
- Alerting on anomalous or unauthorized access patterns
- Regular vulnerability scanning and patch management
- Periodic third-party penetration testing
- Documented incident response plan with defined notification
- Backup and disaster-recovery objectives, tested on a schedule
We watch the systems, and we have a plan for when something goes wrong
Activity across the platform is logged and monitored so that unusual behavior is surfaced quickly. Scanning, testing, and a documented incident-response process keep our defenses current and our response predictable.
Monitoring is oriented toward security and reliability of the systems, not toward watching the people who use Chaperone for support.
Our security extends to the partners beneath the platform
We hold our infrastructure providers and subprocessors to the same expectations we hold ourselves, and we map our controls to recognized frameworks.
SOC 2 readiness
Our controls are evaluated through our SOC 2 readiness and reporting process. Qualifying organizations can request the report under NDA as it becomes available, as part of diligence.
Request the SOC reportHIPAA-informed
We operate under a HIPAA-informed posture, including business associate considerations and safeguards for protected health information.
See HIPAA postureSubprocessor diligence
Infrastructure providers and subprocessors are vetted, covered by appropriate agreements, and reviewed for their own security posture.
Responsible AI controls
Intelligent guidance operates within defined guardrails with human review. Model use is governed alongside the rest of our security program.
Read our AI guardrailsPrivacy by design
Security and privacy are designed together. Data handling follows minimization, consent, and role-based access principles end to end.
Understand privacySafety & escalation
Security supports safety. Clear protocols connect people to appropriate resources, including crisis services like 988, when a moment needs more.
See safety protocolsReviewing Chaperone? Bring your questionnaire to a person.
Our security team works directly with procurement and information-security reviewers. We can complete vendor security questionnaires, walk through our controls, and share documentation appropriate to your diligence.
What we can support during your review
- Completed vendor security questionnaires
- SOC 2 report under NDA as it becomes available
- Control walkthroughs with our security team
- Business associate and data-handling discussions
For general contact details, see our contact page.
Have a security review underway?
Bring your questionnaire, your timeline, and your team. We’ll walk through our posture and get your reviewers what they need.
