Skip to main content
How It Works - Goals - Ask Chainworthy - KPIs - Recommendations - Actions - Data - Events - Context Library Who It's For - Sales & Marketing - Channel & Incentives - Private Equity Compare - Our Approach - vs. Traditional BI - vs. Consultants - vs. Generic AI Pricing About FAQ Roadmap
Request a Demo

Legal

Security Policy

How Chainworthy protects customer data: by architecture, not by a shared store filtered only by tenant ID.

This Security Policy describes the controls and architectural principles Chainworthy, Inc. applies to the platform and related systems. It is published for our public beta and may be updated as our program matures. Related: Privacy Policy · Terms of Service · Built on Snowflake.

1. Security principle

Chainworthy is designed so that protection of customer business data is a structural property of the platform, not solely a software filter applied to a shared multi-tenant data store. Application authentication and tenant scoping exist and matter—but they sit on top of dedicated Snowflake environments provisioned per customer. Isolation is by architecture.

2. Scope

This policy covers:

  • The Chainworthy application platform (including development and production deployments)
  • Customer data and AI processing performed in each customer’s dedicated Snowflake environment
  • Supporting cloud infrastructure used to host the application and the public marketing site

The public marketing website and demo request form are separate from the customer Snowflake data plane. Information submitted on the marketing site is handled under our Privacy Policy and is not stored in a customer’s Snowflake database.

3. Dedicated Snowflake environments

Each Chainworthy customer is provisioned a dedicated Snowflake database scoped to that organization. Customer business data used for profiling, KPIs, goals, findings, and recommendations is stored and processed in that environment. It is not comingled with another customer’s data at the storage layer by design. This is stronger than relying only on an application-layer tenant identifier to segregate rows in a shared database.

Snowflake’s native platform capabilities—including encryption, access control, and environment isolation—form the foundation of our data protection model. Chainworthy builds on those capabilities rather than substituting a weaker shared-store pattern.

4. AI processing in the customer environment

Where Chainworthy uses Snowflake Cortex and related Snowflake AI services for analysis (including data profiling, KPI assistance, recommendation generation, and Ask Chainworthy), inference is designed to run inside the customer’s Snowflake environment. The architectural intent is that customer business data used for those operations is processed where it lives—not exported to a shared Chainworthy “middle” data plane for model execution.

Customer proprietary business data is not used to train public foundation models for the benefit of other customers. Models are invoked to produce results in context; they are not treated as a mechanism to absorb one customer’s data into another’s product experience.

5. Encryption

  • In transit: TLS is used to protect data between clients and Chainworthy services, and for connections to Snowflake and other cloud services.
  • At rest: Customer data in Snowflake is protected using Snowflake’s encryption at rest. Application and marketing infrastructure hosted on AWS uses provider-managed encryption appropriate to those services.

6. Access control

Access is enforced in layers:

  • Snowflake roles: Chainworthy provisions role-based access in the customer Snowflake environment (for example administrative versus standard user capabilities) so database-level permissions reinforce product roles.
  • Application authentication: Users authenticate to the Chainworthy application; sessions and APIs require authorized access.
  • Tenant isolation middleware: Application requests are scoped to the authenticated user’s organization. This application layer is additive to—not a substitute for—dedicated-environment isolation in Snowflake.

Chainworthy personnel access to production systems is limited to what is required to operate and support the service, subject to internal controls and least-privilege practices.

7. Auditability

AI and analysis activity is designed to be auditable. Where implemented, records of AI interactions and related usage are available for query inside the customer’s Snowflake environment, so audit evidence lives under the customer’s environment controls rather than only in a vendor-only black box. Application-side operational logging also supports reliability, security monitoring, and support.

8. Application and marketing infrastructure

The Chainworthy application (web services, application database for accounts and product configuration, task processing, and related components) runs on AWS. The public marketing site is delivered via AWS (including object storage and content delivery). These systems are separated from each customer’s Snowflake data plane. Demo-form submissions are processed through dedicated marketing backends and are not written into customer Snowflake databases.

9. Vulnerability management and secure development

We apply secure development practices appropriate to our stage, including dependency management, least-privilege cloud permissions, secrets management for production credentials, and review of changes that affect authentication, tenancy, or data access. We do not claim third-party certifications in this policy unless separately published; absence of a named certification does not change the architectural controls described above.

10. Incident reporting

If you believe you have discovered a security vulnerability or suspect unauthorized access related to Chainworthy, contact us promptly at support@chainworthy.co with “Security” in the subject line. Please include enough detail for us to reproduce or investigate the issue, and avoid accessing data that is not yours.

We will investigate reported issues in good faith and may request additional information. Do not publicly disclose vulnerability details until we have had a reasonable opportunity to assess and address them.

11. Customer responsibilities

Customers are responsible for:

  • Managing user accounts, invitations, and roles within their organization
  • Ensuring they have rights to upload and process the business data they provide
  • Protecting their credentials and endpoint devices
  • Configuring any customer-owned Snowflake or network controls that sit outside Chainworthy’s managed scope, where applicable

12. Changes

We may update this Security Policy as our architecture and controls evolve. The “Last updated” date below will change when we do. For a narrative explanation of the Snowflake design, see Built on Snowflake.

13. Contact

Security and privacy inquiries: support@chainworthy.co. Chainworthy, Inc., St. Louis, Missouri.

Last updated: July 2026