CHIEF OSBETA

Enterprise trust documentation by Megawebvision

RETURN TO CHIEF

SECURITY / PRIVACY / CUSTOMER CONTROL

Security & Trust Center

CHIEF is built for organizations that entrust critical business operations, connected systems and business data to AI-assisted workflows. Security, privacy and customer control are incorporated into the architecture and operating model from the beginning.

Last updated: August 9, 2026

Enterprise review posture

CHIEF is designed to carry connective operating work without weakening the boundaries around consequential information, decisions or actions.

Enterprise security review ready

Security architecture information, the DPA, subprocessor disclosures and additional due-diligence documentation are available to support qualified enterprise vendor reviews.

Control overview

Security

Encryption in transitVerified

CHIEF is served over HTTPS in production.

Least-privilege accessVerified

Connected services are default-off, narrowly requested and resolved to the relevant account or client before access.

MFA-protected privileged accessReview detail

Privileged-access configuration is available for qualified enterprise review and is not described publicly as a certification claim.

Secure secrets managementVerified

OAuth and connector secrets are designed for protected Keychain-backed storage and are excluded from the repository.

Data minimizationVerified

Public intake and connector workflows apply narrow queries, field limits and scoped context handling.

Logging and monitoringScoped control

Security-relevant external-write decisions are audit recorded without credentials or message content. Application-wide monitoring details are available during review.

Backup and recovery controlsReview detail

Provider and service recovery details are available during qualified enterprise due diligence.

Incident response proceduresDocumented paths

Credential exposure and external-write containment procedures are documented; customer incident procedures are described in the Security and DPA documents.

Vulnerability managementProgram control

Dependencies and security-sensitive changes are version controlled and subject to repository security checks. Remediation timelines are handled through the security review process.

Customer control

Customer Data

Customer data controlCustomer-directed

Customers retain control of the business information they provide and the connected services they authorize.

No sale of Customer Personal DataPublished commitment

Megawebvision does not sell Customer Personal Data.

No shared-model trainingPublished commitment

Customer content is not used to train, fine-tune, distill, publicly benchmark or improve a shared model unless the customer affirmatively opts into a separately stated purpose.

Clear AI-processing disclosureAvailable

AI processing is described in the Security, Privacy and Subprocessor documents.

Public subprocessor registryAvailable

See the public registry at /subprocessors.

Data deletion and returnContractual process

Deletion and return are addressed in the DPA and applicable customer agreement.

DPA availableAvailable

The enterprise DPA is published at /dpa.

Privacy-rights assistanceAvailable

Megawebvision supports customer requests through the Privacy Officer contact.

Customer content is not used to train, fine-tune, distill, publicly benchmark or improve a shared model unless the customer affirmatively opts into a separately stated purpose.

Independent assurance

Assurance Status

Independent Penetration TestingIn Progress

An independent security assessment of CHIEF's externally accessible application environment is in progress. An executive summary will be made available to qualified enterprise customers following completion.

CSA STAR Level 1 Self-AssessmentComing Soon

CHIEF is preparing its CSA STAR Level 1 self-assessment based on the CSA Cloud Controls Matrix and CAIQ. This is a self-assessment, not an independent certification.

Privacy program

Privacy & Regulatory Alignment

CHIEF maintains a privacy program designed to support applicable requirements under the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act / CPRA amendments, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Québec's Act respecting the protection of personal information in the private sector, as amended by Law 25.

GDPRCCPA / CPRAPIPEDAQuébec Law 25
Enterprise DPAAvailable

The DPA covers processor terms, customer instructions, subprocessors, incidents, assistance, deletion and international transfers.

Public Subprocessor RegistryAvailable

The registry identifies service providers that may process Customer Personal Data in connection with CHIEF.

Coordinated Vulnerability DisclosureOpen

Good-faith security reports are welcomed through the contact published on the Security page and security.txt.

Enterprise Security ReviewsSupported

Qualified prospects and customers may request additional documentation and questionnaire responses.

Procurement support

Security documentation available upon request

Qualified enterprise prospects and customers may request additional security documentation, questionnaire responses and independent assessment summaries when available. Requests are handled by the Privacy Officer and routed for the appropriate review.

  • Security architecture and technical-organizational measure details
  • Data Processing Addendum and transfer terms
  • Subprocessor and connected-service disclosures
  • Independent assessment summary when available

Questions

Start with the document that matches your review.

For security, privacy, DPA or subprocessor questions, contact the Privacy Officer at legal@megawebvision.com.

Report or review a security issue