CHIEF is served over HTTPS in production.
Enterprise trust documentation by Megawebvision
RETURN TO CHIEF ↗SECURITY / PRIVACY / CUSTOMER CONTROL
Security & Trust Center
CHIEF is built for organizations that entrust critical business operations, connected systems and business data to AI-assisted workflows. Security, privacy and customer control are incorporated into the architecture and operating model from the beginning.
Last updated: August 9, 2026
Enterprise review posture
CHIEF is designed to carry connective operating work without weakening the boundaries around consequential information, decisions or actions.
Security architecture information, the DPA, subprocessor disclosures and additional due-diligence documentation are available to support qualified enterprise vendor reviews.
Control overview
Security
Connected services are default-off, narrowly requested and resolved to the relevant account or client before access.
Privileged-access configuration is available for qualified enterprise review and is not described publicly as a certification claim.
OAuth and connector secrets are designed for protected Keychain-backed storage and are excluded from the repository.
Public intake and connector workflows apply narrow queries, field limits and scoped context handling.
Security-relevant external-write decisions are audit recorded without credentials or message content. Application-wide monitoring details are available during review.
Provider and service recovery details are available during qualified enterprise due diligence.
Credential exposure and external-write containment procedures are documented; customer incident procedures are described in the Security and DPA documents.
Dependencies and security-sensitive changes are version controlled and subject to repository security checks. Remediation timelines are handled through the security review process.
Customer control
Customer Data
Customers retain control of the business information they provide and the connected services they authorize.
Megawebvision does not sell Customer Personal Data.
Customer content is not used to train, fine-tune, distill, publicly benchmark or improve a shared model unless the customer affirmatively opts into a separately stated purpose.
AI processing is described in the Security, Privacy and Subprocessor documents.
See the public registry at /subprocessors.
Deletion and return are addressed in the DPA and applicable customer agreement.
The enterprise DPA is published at /dpa.
Megawebvision supports customer requests through the Privacy Officer contact.
Customer content is not used to train, fine-tune, distill, publicly benchmark or improve a shared model unless the customer affirmatively opts into a separately stated purpose.
Independent assurance
Assurance Status
An independent security assessment of CHIEF's externally accessible application environment is in progress. An executive summary will be made available to qualified enterprise customers following completion.
CHIEF is preparing its CSA STAR Level 1 self-assessment based on the CSA Cloud Controls Matrix and CAIQ. This is a self-assessment, not an independent certification.
Privacy program
Privacy & Regulatory Alignment
CHIEF maintains a privacy program designed to support applicable requirements under the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act / CPRA amendments, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Québec's Act respecting the protection of personal information in the private sector, as amended by Law 25.
The DPA covers processor terms, customer instructions, subprocessors, incidents, assistance, deletion and international transfers.
The registry identifies service providers that may process Customer Personal Data in connection with CHIEF.
Good-faith security reports are welcomed through the contact published on the Security page and security.txt.
Qualified prospects and customers may request additional documentation and questionnaire responses.
Procurement support
Security documentation available upon request
Qualified enterprise prospects and customers may request additional security documentation, questionnaire responses and independent assessment summaries when available. Requests are handled by the Privacy Officer and routed for the appropriate review.
- Security architecture and technical-organizational measure details
- Data Processing Addendum and transfer terms
- Subprocessor and connected-service disclosures
- Independent assessment summary when available
Questions
Start with the document that matches your review.
For security, privacy, DPA or subprocessor questions, contact the Privacy Officer at legal@megawebvision.com.
Report or review a security issue