# Trust & Compliance | Chainsaw

> The evidence packet your auditor and security questionnaire ask for after a supply-chain incident — NIS2, DORA, CRA, GDPR articles mapped to Chainsaw artifacts. Trust packet, subprocessor list, DPA on request.

Source: https://chain305.com/security/

---

Trust & Compliance

# A public supply-chain attack hit. Now the questionnaire asks how you stop the next install.

An install-path firewall in front of 16 package registries. SaaS, VPC, air-gapped: one binary. Below, the evidence your auditor asks for, by article.

[Request trust packet](#trust-packet)

Compliance statements with subprocessor list, security architecture, data-flow diagrams and a completed CAIQ. DPA on request.

Compliance mapping

## Regime, article, Chainsaw artifact

No regime requires install-time prevention, and Chainsaw claims to satisfy none. Each row is evidence, and each is deep-linkable.

Regime

Article / Control

Chainsaw evidence

NIS2

Art. 21(2)(a) — risk analysis & information system security policies [#](#nis2-art-21-2-a-risk-analysis-information-system-security-policies)

Signed, Sigstore-verified OPA bundle; digest on every decision. Same Rego at PR, install, publish, K8s admission and the local guard; PR sees only the package coordinate, so CVSS and malware rules apply from the install path on. held

NIS2

Art. 21(2)(b) — incident handling [#](#nis2-art-21-2-b-incident-handling)

Signed audit row per decision, tamper-evident chain. SIEM export via webhook or JSONL. held

NIS2

Art. 21(2)(c) — business continuity, backup, crisis management [#](#nis2-art-21-2-c-business-continuity-backup-crisis-management)

Air-gapped tier runs offline; the binary keeps enforcing after license expiry; registry outages served from cache. Hourly database backups with a tested restore procedure. held

NIS2

Art. 21(2)(d) — supply chain security [#](#nis2-art-21-2-d-supply-chain-security)

The product: refuses malicious installs on the path across 16 registries. held

NIS2

Art. 21(2)(e) — security in acquisition, development, maintenance [#](#nis2-art-21-2-e-security-in-acquisition-development-maintenance)

Signed commits. SBOM-of-Chainsaw per release. Chainsaw's own dependencies enforced by its own policy bundle. held

NIS2

Art. 21(2)(f) — policies on effectiveness of risk-management measures [#](#nis2-art-21-2-f-policies-on-effectiveness-of-risk-management-measures)

Audit row + bundle digest per decision reconstruct control state at any point in time. held

NIS2

Art. 21(2)(g) — cyber hygiene & training [#](#nis2-art-21-2-g-cyber-hygiene-training)

Customer responsibility. Chainsaw provides enforcement; customer provides program. customer

NIS2

Art. 21(2)(h) — cryptography [#](#nis2-art-21-2-h-cryptography)

TLS 1.2+ in transit, AES-256 at rest, cosign-signed bundles. CMEK/BYOK on Enterprise (target Q3). target

NIS2

Art. 21(2)(i) — human resources, access control, asset management [#](#nis2-art-21-2-i-human-resources-access-control-asset-management)

SAML/OIDC, SCIM 2.0, RBAC, auto-expiring JIT break-glass. Identity audit log separate from policy log. held

DORA

Art. 6 — ICT risk management framework [#](#dora-art-6-ict-risk-management-framework)

Signed bundle → cosign verify → OPA eval → signed audit row. Reproducible from artifact. held

DORA

Art. 28 — third-party ICT risk (subcontracting chain) [#](#dora-art-28-third-party-ict-risk-subcontracting-chain)

Subprocessors below; SCCs where applicable. Customer region for VPC, customer residency for air-gapped. held

CRA

Annex I §1 — security properties [#](#cra-annex-i-1-security-properties)

SHA-256 checksums per CLI binary (Sigstore-signed releases land with the release-signer-bot cutover). Strict JWT defaults. Tenant isolation at the query layer. in progress

CRA

Annex I §2 — vulnerability handling [#](#cra-annex-i-2-vulnerability-handling)

security@chain305.com + security.txt. CVE triage 1 business day, critical patch 7 days (target). Bug bounty: planned. target

GDPR

Art. 5(1)(c) — data minimisation [#](#gdpr-art-5-1-c-data-minimisation)

No application source code; no developer secrets at rest. Captured: package, version, who installed, when, rationale. held

GDPR

Art. 28 — processor obligations [#](#gdpr-art-28-processor-obligations)

DPA available. SCCs Module 2/3. 30-day subprocessor change notice. held

GDPR

Art. 30 — records of processing [#](#gdpr-art-30-records-of-processing)

The signed audit row is the record of processing for policy events. JSONL + CSV export. held

GDPR

Art. 32 — security of processing [#](#gdpr-art-32-security-of-processing)

Encryption in transit and at rest. Strict JWT, httpOnly cookie sessions. Pseudonymisation where applicable. held

SOC 2

CC6 — logical & physical access [#](#soc-2-cc6-logical-physical-access)

SAML/OIDC, SCIM 2.0, Passkeys, TOTP, RBAC, JIT break-glass. Designed against the SOC 2 Trust Services Criteria; no SOC 2 attestation today. Need one as a contract pre-condition? Flag it on your first call. designed against

SOC 2

CC7 — system operations / monitoring [#](#soc-2-cc7-system-operations-monitoring)

Signed audit row → SIEM export. Incident runbook (in progress). in progress

SOC 2

CC8 — change management [#](#soc-2-cc8-change-management)

Signed policy bundles (cosign-verified at load), checksummed release binaries, audited change history. Bundle promotion gated by cosign verification. held

ISO 27001

A.5 / A.8 / A.12 / A.14 — policies, asset mgmt, ops security, secure dev [#](#iso-27001-a-5-a-8-a-12-a-14-policies-asset-mgmt-ops-security-secure-dev)

Designed against ISO 27001 Annex A; no certification today. designed against

ISO 27017

Cloud-specific controls [#](#iso-27017-cloud-specific-controls)

Hosted in the EU (Germany); self-host or in-VPC for your own region. held

ISO 27018

PII in public cloud [#](#iso-27018-pii-in-public-cloud)

PII limited to signup + billing (name, work email, org slug); none from package contents. EU residency for SaaS. held

Attestation chain

## A tampered policy bundle refuses to load

1.  01 · Signed
    
    cosign signature
    
    Recorded in the Sigstore transparency log
    
2.  02 · Verified at load
    
    -   signature
    -   signing identity
    -   transparency-log entry
3.  03 · Enforced
    
     OPA evaluates the bundle
    
    Its digest is exported with every decision
    

 Tampered bundle refused. It never loads.

Operational resilience

## What happens when Chainsaw is degraded

Hourly database backups with a tested restore procedure. Availability, RPO and RTO for Enterprise are agreed in your order form.

Mode

When a data source is degraded

`Monitor`

Records every decision; never refuses.

`Enforce`

By default, a degraded database or threat-intel source fails open, with an audit row.

`Enforce + CHAINSAW_COVERAGE_MODE=closed`

Refuses any package it could not fully evaluate against the sources you declare mandatory.

Upstream-registry outages are served from cache.

Subprocessors

## Subprocessor list

30-day notice of change. SCCs Module 2 or adequacy for every active subprocessor; none on the air-gapped tier.

Subprocessor

Purpose

Region

Transfer mechanism

Contabo GmbH

SaaS hosting, object storage

EU (Germany)

Intra-EU; no third-country transfer

Cloudflare

Edge TLS termination, Turnstile bot defense

Global anycast; EU-resident logs

SCCs Module 2 + Cloudflare DPA

Paddle

Billing, merchant of record

Global (merchant of record)

SCCs Module 2 + Paddle DPA

Sigstore (public good)

Transparency log for signed bundles

Public log (verifiable, no PII)

Public infrastructure; no personal data submitted

Postmark

Transactional email

US

SCCs Module 2 + Postmark DPA

PostHog Inc.

Product analytics (consent-gated)

US

SCCs Module 2 + PostHog DPA

Google LLC (Google Analytics)

Marketing-site analytics (consent-gated)

US

EU-US Data Privacy Framework + SCCs

Controls in detail

## Open any control for the detail

Data flows & PII surface

No application source code is processed. No developer secrets at rest: install-script exfiltration is detected on ephemeral install traffic, and secrets it observes are not stored.

**Captured per decision:** package name, version, ecosystem, upstream URL, requesting identity, timestamp, policy bundle digest, decision (allow / refuse / quarantine) and the Rego rule that fired.

**PII (GDPR Art. 5(1)(c)):** signup and billing only (name, work email, org slug). Audit rows carry a stable internal ID; the mapping to a person lives in your identity provider.

EU data residency

SaaS runs on **Contabo in Germany**, with backups kept in the same region, so no GDPR Chapter V transfer is required.

VPC deploys into your region. Air-gapped runs entirely on your infrastructure with no Chainsaw-operated egress; the CLI's server URL can be baked into the binary.

Encryption

**In transit:** TLS 1.2+ on every ingress, AEAD suites only (AES-GCM, ChaCha20-Poly1305), HSTS on the SaaS edge.

**At rest:** SSO client secrets, TOTP seeds and SIEM credentials are encrypted in the application with AES-256-GCM before they reach the database. For keys you hold yourself, self-host or run in your VPC.

CLI release binaries ship with published SHA-256 checksums today; Sigstore-signed releases land once the release-signer bot is provisioned.

Open engine

The proxy, policy evaluation and the risk / typosquat / malware / provenance libraries are open source at [github.com/chain305/chainsaw-core](https://github.com/chain305/chainsaw-core). Read how a refusal is reached before you route installs through it.

The multi-tenant control plane (dashboard, SSO/SCIM, premium intelligence, policy signing, SIEM delivery) is closed. The compiler enforces the boundary: enterprise code depends on the open core, never the reverse.

Identity & access

SAML 2.0 and OIDC against Okta and Entra ID. SCIM 2.0. WebAuthn + Passkeys and TOTP. CLI credentials in the OS keyring, never plaintext on disk.

RBAC at org / workspace / policy / registry granularity. JIT break-glass with auto-expiry (default 4 hours, configurable). Identity events write to a **separate** audit stream from policy decisions.

Short-lived JWT in an httpOnly cookie, revocable. Chainsaw refuses to boot without an explicit CHAINSAW\_JWT\_SECRET or persistent secret store.

Vulnerability handling & SDLC

**Disclosure:** security@chain305.com and `/.well-known/security.txt`. Acknowledgement within 1 business day. Safe harbor for good-faith research. Bug bounty: planned (target H2 2026).

**Pen test:** no third-party report to share yet. Scope one with us as part of your review.

**CVE response SLA (target):** triage 1 business day; critical patch 7 days, high 30, medium 90.

**SDLC:** signed commits on protected branches, SBOM-of-Chainsaw per release, and Chainsaw's own dependencies enforced by a Chainsaw policy bundle.

Termination & escape hatch

**Data export:** audit rows as JSONL + CSV, policy bundles as signed archives, configuration as YAML. Available during the contract and for 90 days after termination, then hard-deleted.

**License expiry does not brick enforcement.** The checksum-verified binary keeps enforcing the last-signed bundle offline; new bundles require renewal.

**Source-available clause:** if Chain305 ceases operations, the enforcement core is released under a source-available license per the Enterprise MSA escrow clause.

Trust packet

## Send this to legal

Compliance statements with subprocessor list, security architecture, data-flow diagrams and a completed CAIQ. DPA on request.

Still have questions?

## Talk to security engineering

Not sales. The engineer who wrote the signed-bundle verifier, the isolation tests or the JWT strict-default.

[Book a 30-minute call](https://cal.com/chain305/30min) [Talk to sales](https://cal.com/chain305/30min)

---

## Long form

The full text behind this page, including detail the page itself leaves out.

Trust & Compliance

### A public supply-chain attack hit. Now the questionnaire asks how you stop the next install.

Chainsaw is an install-path firewall sitting in front of 16 package registries. Same Rego at PR, install, publish, K8s admission, runtime. The PR check reads a dependency diff, so it decides on the package coordinate and not the bytes: a rule keyed on a CVSS score or a malware verdict takes effect from the install path on. Same rule at five surfaces, not the same coverage at all five. SaaS, VPC, air-gapped — one binary. Your installs route through us, so if we fail, your install path fails — that's the responsibility we took on, and this page is how we show our work. No regime mandates install-time prevention, but after Shai-Hulud, xz-utils, or your own near-miss, the security questionnaire does. Below: the evidence packet your auditor and questionnaire ask for, mapped to NIS2, DORA, CRA, and GDPR articles your legal team can forward.

[Request trust packet](#trust-packet)

Compliance statements with subprocessor list, security architecture, data-flow diagrams and a completed CAIQ. DPA on request.

Compliance mapping

#### Regime, article, and the Chainsaw artifact that maps to it.

No regime requires install-time prevention — Chainsaw doesn't "satisfy" NIS2 or DORA, and won't claim to. What it does: produce the signed artifact, configuration, or export your auditor and security questionnaire ask for, mapped to the article they cite. Generic "GDPR compliant" claims fail GRC review; article-level evidence doesn't. "In progress" and "target" used honestly where the claim isn't yet contractually backed. Each row is deep-linkable — legal can forward a URL straight to the evidence. One reading note before you paste a row into a questionnaire: where a row says the same Rego runs at five surfaces, that is the same rule, not the same inputs. The PR check reads a dependency diff and decides on the package coordinate, so a rule keyed on a CVSS score or a malware verdict takes effect from the install path on. Write that sentence, not "the same rule runs everywhere".

Regime

Article / Control

Chainsaw evidence

NIS2

Art. 21(2)(a) — risk analysis & information system security policies [#](#nis2-art-21-2-a-risk-analysis-information-system-security-policies)

Signed policy bundle (Sigstore-verified OPA). Same Rego at PR, install, publish, K8s admission, runtime. PR reads a dependency diff, so it decides on the package coordinate; rules keyed on a CVSS score or a malware verdict take effect from the install path on. Bundle digest exported with every decision. held

NIS2

Art. 21(2)(b) — incident handling [#](#nis2-art-21-2-b-incident-handling)

Signed audit row per decision. Tamper-evident chain. Export to SIEM (Splunk, Elastic, Datadog) via webhook or JSONL. held

NIS2

Art. 21(2)(c) — business continuity, backup, crisis management [#](#nis2-art-21-2-c-business-continuity-backup-crisis-management)

Air-gapped tier runs offline. Checksum-verified binary keeps enforcing after license expiry. Upstream-registry outages are served from cache. Hourly database backups with a tested restore procedure. held

NIS2

Art. 21(2)(d) — supply chain security [#](#nis2-art-21-2-d-supply-chain-security)

This is the product. Refuses malicious installs on the path across 16 registries. SBOM-of-Chainsaw published per release. held

NIS2

Art. 21(2)(e) — security in acquisition, development, maintenance [#](#nis2-art-21-2-e-security-in-acquisition-development-maintenance)

Signed commits. SBOM-of-Chainsaw. Dependencies enforced by Chainsaw against Chainsaw's own policy bundle. held

NIS2

Art. 21(2)(f) — policies on effectiveness of risk-management measures [#](#nis2-art-21-2-f-policies-on-effectiveness-of-risk-management-measures)

Per-decision audit row + policy bundle digest = reconstructable control state at any point in time. held

NIS2

Art. 21(2)(g) — cyber hygiene & training [#](#nis2-art-21-2-g-cyber-hygiene-training)

Customer responsibility. Chainsaw provides enforcement; customer provides program. held

NIS2

Art. 21(2)(h) — cryptography [#](#nis2-art-21-2-h-cryptography)

TLS 1.2+ in transit. AES-256 at rest. Sigstore/cosign attestation chain for bundles. CMEK/BYOK on Enterprise (target Q3). target

NIS2

Art. 21(2)(i) — human resources, access control, asset management [#](#nis2-art-21-2-i-human-resources-access-control-asset-management)

SAML/OIDC (Okta, Entra ID), SCIM 2.0, RBAC, JIT break-glass with auto-expiry, identity audit log separate from policy audit log. held

DORA

Art. 6 — ICT risk management framework [#](#dora-art-6-ict-risk-management-framework)

Policy-as-code lifecycle: signed bundle → cosign verify → OPA eval → signed audit row. Reproducible from artifact. held

DORA

Art. 28 — third-party ICT risk (subcontracting chain) [#](#dora-art-28-third-party-ict-risk-subcontracting-chain)

Subprocessor table below. SCCs in place where applicable. Customer-region for VPC tier; customer-residency for air-gapped tier. held

CRA

Annex I §1 — security properties [#](#cra-annex-i-1-security-properties)

Published SHA-256 checksums for every CLI binary (Sigstore-signed releases land with the release-signer-bot cutover). Strict JWT secret defaults. Multi-tenant isolation enforced at the query layer. held

CRA

Annex I §2 — vulnerability handling [#](#cra-annex-i-2-vulnerability-handling)

Coordinated disclosure via security@chain305.com + security.txt. CVE SLA: triage 1 business day, critical patch 7 days (target). Bug bounty: planned. target

GDPR

Art. 5(1)(c) — data minimisation [#](#gdpr-art-5-1-c-data-minimisation)

Zero application source code processed. Zero developer secrets at rest. Metadata captured = package name, version, who-installed, when, decision rationale. held

GDPR

Art. 28 — processor obligations [#](#gdpr-art-28-processor-obligations)

DPA available (download below). SCCs Module 2/3 in standard form. Subprocessor list maintained + 30-day change notice. held

GDPR

Art. 30 — records of processing [#](#gdpr-art-30-records-of-processing)

Per-decision signed audit row IS the record of processing for policy events. Exportable in JSONL + CSV. held

GDPR

Art. 32 — security of processing [#](#gdpr-art-32-security-of-processing)

Encryption in transit + at rest. bcrypt LRU+TTL auth cache. httpOnly cookie sessions. JWT strict-by-default. Pseudonymisation where applicable. held

SOC 2

CC6 — logical & physical access [#](#soc-2-cc6-logical-physical-access)

SAML/OIDC, SCIM 2.0, WebAuthn + Passkeys, TOTP, RBAC, JIT break-glass. Designed against the SOC 2 Trust Services Criteria; no SOC 2 attestation today. Need one as a contract pre-condition? Flag it on your first call. designed against

SOC 2

CC7 — system operations / monitoring [#](#soc-2-cc7-system-operations-monitoring)

Signed audit row → SIEM export. Incident runbook (in progress). in progress

SOC 2

CC8 — change management [#](#soc-2-cc8-change-management)

Signed policy bundles (cosign-verified at load), checksummed release binaries, audited change history. Bundle promotion gated by cosign verification. held

ISO 27001

A.5 / A.8 / A.12 / A.14 — policies, asset mgmt, ops security, secure dev [#](#iso-27001-a-5-a-8-a-12-a-14-policies-asset-mgmt-ops-security-secure-dev)

Designed against ISO 27001 Annex A; no certification today. designed against

ISO 27017

Cloud-specific controls [#](#iso-27017-cloud-specific-controls)

Hosted in the EU (Germany); self-host or in-VPC for your own region. held

ISO 27018

PII in public cloud [#](#iso-27018-pii-in-public-cloud)

PII surface limited to signup + billing (name, work email, org slug). No PII from package contents. EU residency for SaaS tier. held

Data flows & PII surface

#### Exactly what touches the proxy

Chainsaw inspects install-time traffic to package registries. Zero application source code is processed. Zero developer secrets at rest — the proxy detects install-script exfiltration attempts against ephemeral install traffic; it does not store secrets it observes.

**Metadata captured per decision:** package name, version, ecosystem, upstream URL, requesting identity (user or service account), timestamp, policy bundle digest, decision (allow / refuse / quarantine), and decision rationale (which Rego rule fired).

**PII surface (GDPR Art. 5(1)(c) data minimisation):** signup and billing only — name, work email, org slug. No PII extracted from package contents. Audit rows identify the requesting principal by stable internal ID; the mapping to a natural person lives in the identity provider, not in the audit log.

EU data residency

#### Germany for SaaS. Customer-region for VPC. Customer-residency for air-gapped.

SaaS runs on **Contabo in Germany**. Backups remain in the same region, so no GDPR Chapter V (third-country) transfer is required.

VPC tier deploys into the customer's own region. Air-gapped tier runs entirely within customer-controlled infrastructure with no Chainsaw-operated egress. The CLI's server URL can be baked into the binary so engineers never reach a public origin.

Subprocessors

#### Subprocessor list

30-day notice of change. SCCs Module 2 or adequacy decision in place for every active subprocessor. Air-gapped tier uses zero Chainsaw-side subprocessors.

Subprocessor

Purpose

Region

Transfer mechanism

Contabo GmbH

SaaS hosting, object storage

EU (Germany)

Intra-EU; no third-country transfer

Cloudflare

Edge TLS termination, Turnstile bot defense

Global anycast; EU-resident logs

SCCs Module 2 + Cloudflare DPA

Paddle

Billing, merchant of record

Global (merchant of record)

SCCs Module 2 + Paddle DPA

Sigstore (public good)

Transparency log for signed bundles

Public log (verifiable, no PII)

Public infrastructure; no personal data submitted

Postmark

Transactional email

US

SCCs Module 2 + Postmark DPA

PostHog Inc.

Product analytics (consent-gated)

US

SCCs Module 2 + PostHog DPA

Google LLC (Google Analytics)

Marketing-site analytics (consent-gated)

US

EU-US Data Privacy Framework + SCCs

Encryption

#### In transit, at rest, and the attestation chain

**In transit:** TLS 1.2+ on every ingress. Cipher policy restricted to AEAD suites (AES-GCM, ChaCha20-Poly1305). HSTS on the SaaS edge.

**At rest:** SSO client secrets, TOTP seeds and SIEM credentials are encrypted in the application with AES-256-GCM before they reach the database. For keys you hold yourself, self-host or run in your VPC.

**Attestation chain for policy bundles:** Sigstore transparency log → cosign signature → OPA verification at load time. A tampered bundle refuses to load. CLI release binaries ship with published SHA-256 checksums today; Sigstore-signed releases with on-launch verification land once the release-signer bot is provisioned.

Open engine

#### Read the block decision before you route traffic through it

The engine that decides whether a package installs is open source — the proxy, the policy evaluation, and the risk / typosquat / malware / provenance libraries live at [github.com/chain305/chainsaw-core](https://github.com/chain305/chainsaw-core). An AppSec lead can read exactly how a refusal is reached — see the install gate return the 403 — before pointing their org's installs at it. No black box on the install path.

The engine is open; the server is the paid product. The multi-tenant control plane — dashboard, SSO/SCIM, premium intelligence, policy signing, SIEM delivery — is closed. The boundary is enforced by the compiler, not a marketing line: enterprise code depends on the open core, never the reverse, and a free build can't pull in an enterprise-only path.

Identity & access

#### SAML, SCIM, Passkeys, and a separate audit log for identity events

SAML 2.0 and OIDC against Okta and Entra ID. SCIM 2.0 for user lifecycle. WebAuthn + Passkeys and TOTP for second factor. OS keyring (macOS Keychain, Windows Credential Manager, libsecret) for CLI credential storage — never plaintext on disk.

RBAC at org / workspace / policy / registry granularity. JIT break-glass roles with auto-expiry (default 4 hours, configurable). Identity events (login, role grant, key issuance) write to a **separate** audit stream from policy decision events — your IAM team and your AppSec team don't have to share a query.

Session model: short-lived JWT, httpOnly cookie, revocable. JWT strict-by-default — Chainsaw refuses to boot without an explicit CHAINSAW\_JWT\_SECRET or persistent secret store. bcrypt with LRU+TTL auth cache to bound the credential-check surface.

Vulnerability & secure development

#### Disclosure, SLA, and SDLC

**Disclosure:** security@chain305.com and `/.well-known/security.txt`. Acknowledgement within 1 business day. Safe-harbor for good-faith research. Bug bounty: planned (target H2 2026).

**Pen test:** no third-party report to share yet. Scope one with us as part of your review.

**CVE response SLA (target):** triage within 1 business day, critical patch within 7 days, high within 30 days, medium within 90 days.

**SDLC:** signed commits required on protected branches. SBOM-of-Chainsaw published per release. Chainsaw's own dependencies are enforced by a Chainsaw policy bundle — the proxy eats its own dog food on the supply chain.

Operational resilience

#### Backups, availability, and what happens when Chainsaw is down

Hourly database backups with a tested restore procedure. Availability, RPO and RTO for Enterprise are agreed in your order form.

**Failure mode:** in monitor mode, Chainsaw records and never blocks. In enforce mode, a degraded database or threat-intel source fails open with an audit row by default; setting `CHAINSAW_COVERAGE_MODE=closed` inverts that, so Chainsaw refuses any package it could not fully evaluate against the data sources you declare mandatory. Upstream-registry outages are served from cache.

Business continuity & escape hatch

#### What happens at termination

**Data export:** JSONL + CSV of audit rows, policy bundles as signed archives, configuration as YAML. Available throughout contract and for 90 days after termination. After 90 days, hard-delete.

**Checksum-verified binary keeps running offline.** License expiry does not brick the install-path firewall. Enforcement continues against the last-signed policy bundle. New bundles require renewal; existing bundles keep enforcing.

**Source-available enforcement bundle clause:** if Chain305 ceases operations, the enforcement core is released under a source-available license per the Enterprise tier MSA escrow clause.

Trust packet

#### Send this to legal

Compliance statements with subprocessor list, security architecture, data-flow diagrams and a completed CAIQ. DPA on request. Gated form — email, role, company.

Still have questions?

#### Talk to security engineering

Not sales. The engineer who wrote the signed-bundle verifier, the multi-tenant isolation tests, or the JWT strict-default. Pick the topic; routing follows.

[Talk to security engineering](https://cal.com/chain305/30min) [Talk to sales](https://cal.com/chain305/30min)
