Security & Trust

Your audit trail is our only product.

DecisionChain is built to be the record that survives a regulator's request. This page is maintained by DecisionChain to answer common security and privacy questions about the platform.

  • Tamper-evident by design

    Every audit record is hashed and chained to the previous one. Alteration breaks the chain and every downstream signature, provably.

  • Encryption in transit and at rest

    TLS 1.2+ for all traffic. AES-256 at rest. Data is encrypted before it hits our storage layer.

  • Customer-managed keys (Enterprise)

    Bring your own KMS. Rotate keys on your schedule. We never see plaintext for records under CMK.

  • Regional isolation

    US and EU regions available. Data does not leave the region you provision, including backups and evidence exports.

  • External anchoring

    The chain head is periodically anchored to an external witness so tampering is detectable even in the case of a full compromise.

  • Least-privilege access

    SSO and SCIM for Enterprise. Audit-role separation so viewers, exporters, and admins are distinct.

Compliance framework references

DecisionChain produces evidence your compliance team submits. We are not a substitute for a certification — we make the evidence work tractable.

  • EU AI Act — Article 12. Automatic recording of events across the lifecycle of high-risk systems.
  • ISO/IEC 42001. AI management system evidence for controls, monitoring, and human oversight.
  • SOC 2 (Type II). Security, availability, and processing integrity attestations for the service.
  • NIST AI RMF. Govern · Measure · Manage — mapped to our logging, monitoring, and evidence workflows.

Report a vulnerability

Found a security issue? Email hello@decisionchain.dev with reproduction steps. We respond within one business day and coordinate disclosure with reporters.