Trust Center
Public compliance, security, and privacy documentation for Data Chimp Labs and Kanzi - the Private AI for Healthcare platform.
DataChimp Labs - Trust Center
Welcome to the public Trust Center for DataChimp Labs. This site is the canonical, public-facing source for our corporate compliance and policy documentation. It exists so customers, partners, and reviewers can verify how DataChimp Labs identifies, mitigates, and monitors risk across its platform and products.
- Security contact: security@datachimplabs.com
- Privacy contact / DPO: privacy@datachimplabs.com
- Repository: github.com/DataChimp-Labs/compliance-docs
Public policies
The following policies are current, effective, and published for public review. Each renders on this site and can be downloaded as PDF using the button that appears on every policy page.
- Information Security Policy - risk management program, control framework, audit posture.
- Privacy Policy - end-user privacy commitments, including Plaid Link deployments.
- Access Control Policy - RBAC, zero-trust posture, IAM, joiner-mover-leaver, periodic access reviews.
- Authentication & MFA Policy - workforce phishing-resistant MFA and consumer MFA at every authentication point.
- Encryption in Transit Policy - TLS 1.2+ baseline, HSTS, ACM lifecycle, mTLS.
- Encryption at Rest Policy - AWS KMS, envelope encryption, encryption context, all Plaid API data encrypted at rest.
- Vulnerability Management Policy - endpoint and production scanning, patch SLAs, EOL monitoring, penetration testing, responsible disclosure.
Framework coverage
Framework-specific control mappings are being produced under frameworks/
in the source repository (GDPR, HIPAA, SOC 2, ITAR, IL6). The underlying
controls in the policies above apply today; framework-specific narratives
will be published here as they are completed.
Attestations & questionnaires
Attestation reports, filled vendor questionnaires, and gated evidence are distributed under NDA on request. Contact security@datachimplabs.com.