Security

Security your review team can actually evaluate

People share sensitive things with their Peer Coach. Protecting that information is foundational to how Chaperone is built and operated: encryption, least-privilege access, continuous monitoring, and a SOC 2 readiness and reporting process across the platform and our managed infrastructure.

Defense in depth, written for the people doing the diligence

This page is a buyer- and procurement-level overview of how we protect data: what we encrypt, who can access what, how we monitor, and how we manage the vendors and infrastructure beneath the platform. As our SOC 2 readiness and reporting process completes, control-level evidence will be available to qualifying organizations under NDA.

Posture at a glance

The headline controls, in one view

A fast orientation before the detail below, useful for an initial security questionnaire pass.

SOC 2
Readiness & reporting process underway
AES-256
Encryption at rest across data stores
TLS 1.2+
Encryption in transit for all connections
Continuous
Logging and monitoring of platform activity
Data protection

Encrypted in transit, encrypted at rest, minimized by default

We treat behavioral-health information as the most sensitive data we hold. Protection starts with strong encryption and continues through data minimization, isolation between environments, and disciplined key management.

We collect what is needed to provide and improve support, and no more. Production data is kept separate from non-production environments.

  • Encryption in transit with TLS 1.2 or higher
  • Encryption at rest using AES-256 across data stores
  • Managed key storage with controlled rotation
  • Data minimization: collect only what support requires
  • Production isolated from non-production environments
  • Backups encrypted, with tested restore procedures
Access controls

Least privilege, by role, with a record of who did what

Access to sensitive data is scoped to the people who need it for their role and recorded so it can be reviewed.

Role-based access

Permissions are granted by role under a least-privilege model. People see only the data their work requires, and nothing more.

Strong authentication

Multi-factor authentication is required for administrative and privileged access, with single sign-on supported for partner organizations.

Audit trails

Sensitive actions are logged to an audit trail so access can be reviewed, attributed, and investigated when needed.

Joiner / mover / leaver

Access is provisioned on a need-to-know basis and promptly revoked when roles change or people leave, with periodic recertification.

Network segmentation

Systems are segmented and access is restricted between environments, limiting the blast radius if any single component is compromised.

People, not surveillance

Access controls protect data and accountability. They are not used to monitor the people we support. Oversight stays focused on safety and quality.

  • Centralized logging of platform and infrastructure activity
  • Alerting on anomalous or unauthorized access patterns
  • Regular vulnerability scanning and patch management
  • Periodic third-party penetration testing
  • Documented incident response plan with defined notification
  • Backup and disaster-recovery objectives, tested on a schedule
Monitoring & resilience

We watch the systems, and we have a plan for when something goes wrong

Activity across the platform is logged and monitored so that unusual behavior is surfaced quickly. Scanning, testing, and a documented incident-response process keep our defenses current and our response predictable.

Monitoring is oriented toward security and reliability of the systems, not toward watching the people who use Chaperone for support.

Vendor & compliance posture

Our security extends to the partners beneath the platform

We hold our infrastructure providers and subprocessors to the same expectations we hold ourselves, and we map our controls to recognized frameworks.

SOC 2 readiness

Our controls are evaluated through our SOC 2 readiness and reporting process. Qualifying organizations can request the report under NDA as it becomes available, as part of diligence.

Request the SOC report

HIPAA-informed

We operate under a HIPAA-informed posture, including business associate considerations and safeguards for protected health information.

See HIPAA posture

Subprocessor diligence

Infrastructure providers and subprocessors are vetted, covered by appropriate agreements, and reviewed for their own security posture.

Responsible AI controls

Intelligent guidance operates within defined guardrails with human review. Model use is governed alongside the rest of our security program.

Read our AI guardrails

Privacy by design

Security and privacy are designed together. Data handling follows minimization, consent, and role-based access principles end to end.

Understand privacy

Safety & escalation

Security supports safety. Clear protocols connect people to appropriate resources, including crisis services like 988, when a moment needs more.

See safety protocols
Security questions

Reviewing Chaperone? Bring your questionnaire to a person.

Our security team works directly with procurement and information-security reviewers. We can complete vendor security questionnaires, walk through our controls, and share documentation appropriate to your diligence.

Request the SOC report

What we can support during your review

  • Completed vendor security questionnaires
  • SOC 2 report under NDA as it becomes available
  • Control walkthroughs with our security team
  • Business associate and data-handling discussions

For general contact details, see our contact page.

Let’s talk

Have a security review underway?

Bring your questionnaire, your timeline, and your team. We’ll walk through our posture and get your reviewers what they need.