Security and data.
This page is written for the IT, security, and quality reviewers who evaluate Chrona Actions for an organization. It summarises how the product handles identity, credentials, content, and AI processing. The Privacy Policy and Terms of Service are the binding documents; where this page and those disagree, they win.
The write model
Chrona Actions is read-only until a person approves a change. Every proposed change is a draft carrying its own evidence, and a named reviewer keeps, edits, or dismisses it, per item. There is no batch approval and no setting that grants standing permission.
Approved changes write to coordination fields only: assignee, status, dates. Chrona never changes the substance of the work, never deletes, and never writes anything a person did not confirm. Changes supersede rather than erase, so history stays intact, and every write is attributed to the person who approved it rather than to the system.
Identity and access
Sign-in is through Microsoft Entra ID, or a single-use numeric code sent to a work email
address, depending on the organisation's configuration. The Entra sign-in requests only the
openid, profile and email scopes.
It grants Chrona Actions no access to files, mail, calendar, or any other
Microsoft 365 content.
Access is by invitation, enforced at the database layer: an account can only be created for an address an authorised administrator of your organisation has already added to a workstream.
Tracker credentials
Access to your system of record is a separate, explicit authorisation a named person grants in that system itself, through its own OAuth flow. The credential is held in an encrypted secret store, keyed to the person who authorised it, and is never readable by the browser or by any signed-in user. Disconnecting the system deletes the stored credential.
What Chrona reads, stores, and writes
Reads. The meeting artifacts your team provides: transcripts, recaps, notes, and status documents. The items in the tracker you connect, read-only. Chrona does not record or transcribe meetings, and it does not crawl your tenant.
Stores. Its own working record: workstreams, lanes, topics and actions; findings awaiting review; the evidence behind each finding, kept as the relevant excerpt together with a pointer identifying its source, so a reviewer can check every claim against where it came from; reviewer decisions; and a timeline of changes. The artifacts themselves are not retained: a transcript, recap, or note is read in transit during a reconciliation run, and only the evidence excerpts its findings cite are kept. Retention terms are in the Privacy Policy, Section 10.
Writes. Coordination fields only, on a person's approval, as described above.
AI processing
Chrona Actions uses Anthropic as its large language model provider, under an agreement that prohibits the provider from retaining your content or using it to train models. We do not train models on your content either, and we do not permit any provider to.
Enterprise deployments that hold their own model-provider agreement can route Chrona's model calls through their own key instead.
Separation between customers
Each customer's data is isolated at the database level through row-level security, and access is scoped by workstream and role. Within a customer, a person invited only to respond to a request sees only what is directed to them.
Audit history
Every finding carries its evidence and a pointer to the source it came from. Every approved change carries the reviewer who approved it and when. Because nothing is deleted and changes supersede visibly, the full history of what was proposed, decided, and written remains inspectable.
Retention and offboarding
Evidence excerpts are kept for the duration of your subscription, unless your agreement specifies a shorter period; the artifacts they came from are never stored, as described above. After closure there is a 90-day export window, account information is deleted within 30 days, and remaining content is deleted or de-identified within 60 days after the export window. The Privacy Policy, Section 10, is the binding statement of these terms. Changes already applied to your own systems of record stay in your systems, because they are your records.
Subprocessors
The full list is published in the Privacy Policy, Section 7: Supabase (database, authentication and file storage), Vercel (hosting), Railway (the reconciliation engine), Resend (sign-in codes and service email), Microsoft Entra ID (single sign-on), PostHog (product analytics), and Anthropic (model provider). We give at least 30 days' notice before adding or replacing a subprocessor that handles customer content.
Certifications
A2 Foundry does not yet hold SOC 2 or ISO 27001 certification. We are a small team early in the product's life, and we would rather say that plainly than imply otherwise. We will walk your security reviewers through the architecture, the data model, and the controls directly.
Questions
contact@chronaactions.com. Ask for as much technical detail as your review needs.