Chatstat exists to help protect people, so protecting their data is a design requirement, not an afterthought. This page summarizes how we secure the service. Detailed documentation, including our Data Processing Addendum and completed security questionnaires, is available to enterprise customers under NDA.
Architecture and enforcement
- Encryption. Data is encrypted in transit and at rest.
- Hosting. Primary application infrastructure and data storage in Australia (Sydney), with AI processing through Microsoft's Azure OpenAI Service in the United States.
- Database-layer enforcement. Customer separation and child-protection rules are enforced with row-level security in our database, not only in application code. The rule that raw content of any person under 18 is never available to a third-party AI agent is enforced at this layer and cannot be overridden by configuration.
- Data minimization. We collect month and year of birth only for monitored young people, never exact dates, and our integrations default to structured metadata (Tier 1) with no names, handles, or content.
- Authentication. Enterprise API and MCP access uses OAuth 2.0 with customer-scoped tokens. Access is least-privilege and role-based across the company.
- Audit logging. Integration and administrative access is logged and retained for 12 months.
- Redaction. Where redacted excerpts (Tier 2) are enabled, personal identifiers are removed server-side before any data leaves Chatstat.
- No-training commitments. Our AI providers are contractually restricted from training their models on Chatstat data.
- Deletion and retention. Retention periods are published in our Privacy Policy and enforced in code, with deletion propagated across systems and backups held on a 35-day rolling cycle.
- Abuse resistance. Rate limiting, prompt-injection defenses, and region-aware routing are built into our integration layer.
Certification program
- ISO/IEC 27001. Chatstat is implementing an ISO/IEC 27001 information security management system. Certification through an accredited certification body is in progress.
- SOC 2 Type II. Scheduled to follow ISO 27001 certification.
We publish certification status accurately and update this page as milestones are reached. We do not claim certifications we do not yet hold.
Privacy governance
Chatstat Pty Ltd is the data controller for the service. Our appointed Data Protection Officer is Nicola Cook of DPO Solutions for Schools. Our Privacy Policy, Sub-processor List, and AI and Notification Disclaimer describe how data is handled, and a Data Processing Addendum is available to customers that require one.
Reporting a vulnerability
If you believe you have found a security vulnerability in a Chatstat service, email security@chatstat.com with enough detail for us to reproduce the issue. We ask that you give us a reasonable opportunity to remediate before public disclosure, and we will not pursue good-faith research conducted within these guidelines.
Contact
security@chatstat.com