Security
Security
Chata.ai Never Sees Your Data
Chata.ai Never Sees Your Data
Chata.ai Never Sees
Your Data
Chata.ai trains on your schema structure, not your data. It generates a database query. Your database returns the answer.
Chata.ai trains on your schema structure, not your data. It generates a database query. Your database returns the answer.



ISO 27001 Certified

SOC 2 Type II Certified



How a Question Becomes an Answer
Chata.ai trains on table names, columns, and relationships. It learns the structure. It never sees the content in your rows.
Chata.ai trains on table names, columns, and relationships. It learns the structure. It never sees the content in your rows.
Your Data Never Leaves Your Environment
Chata.ai runs where your data lives. During implementation, we connect through a read-only credential. No bulk data transfer, no data replication, no access to anything beyond schema metadata.
Your Cloud
Deploys inside your Azure, AWS, or GCP account. Chata.ai operates within your network boundary. Data doesn't route through our infrastructure at any point.
On-Premises
Deploys on your infrastructure via Kubernetes. Runs on your hardware, on your network. Nothing touches an external endpoint.
Also available as edge deployment for streaming and real-time use cases, or multi-tenant SaaS with logical tenant isolation. Talk to us about what fits your environment.
Users Only See What They're Allowed To See
Users Only See What
They're Allowed To See
Chata.ai deploys inside your environment and connects directly to the access controls you already have in place. Your identity provider remains the single source of truth. No duplicate permission systems, no extra configuration from your team.



+ any SAML / OAuth / OIDC provider
Certified and Auditable
ISO 27001
Information security management certified to ISO/IEC 27001:2022.
SOC 2 Type II
Independent audit confirming security, availability, and confidentiality controls.
Full Audit Trail
Every query, every access event, every result logged with timestamps and user identity.
Policy-Driven Validation
Each query is validated against your security policies, and out-of-scope queries are blocked before execution.
SSO via SAML, OAuth, and OpenID Connect. Role-based access control aligned with your existing permission model.
Info-Tech Research Group's Review
Customer data never enters the training process. The model is built from the schema, not the underlying data. That distinction matters enormously for any organization operating under data residency or privacy requirements.
Igor Ikonnikov
Advisory Fellow, Data and Analytics, Info-Tech Research Group
About Security at Chata.ai
Security is a top priority at Chata.ai. We take several measures to help ensure every implementation of AutoQL is secure and meets the highest standards of data protection.
AutoQL Security Architecture is built on four foundational layers:
Integrator Partner Security & Network Connectivity – Secure communication protocols between partner systems and AutoQL
Customer-Level Security – JWT-based authentication ensuring customer data isolation
User-Level Security – Unique Customer ID with role-based (RBAC) /ACL-based access control
Database-Level Security – Defence in depth protecting data at the storage layer
Security is a top priority at Chata.ai. We take several measures to help ensure every implementation of AutoQL is secure and meets the highest standards of data protection.
AutoQL Security Architecture is built on four foundational layers:
Integrator Partner Security & Network Connectivity – Secure communication protocols between partner systems and AutoQL.
Customer-Level Security – JSON Web Token (JWT)-based authentication ensuring customer data isolation, so each customer's data stays fully separated from every other's.
User-Level Security – Unique Customer ID with role-based access control (RBAC) or access control list (ACL)-based access control, restricting exactly what each user can see and do.
Database-Level Security – Defence in depth protecting data at the storage layer, so a breach at one layer doesn't expose the rest.
Compliance, Certifications & Controls
Chata.ai maintains the highest security standards:
SOC 2 Type II attestation – Demonstrating controls over security and availability.
ISO 27001 Certified – Comprehensive information security management system.
Annual Vulnerability Assessments – Regular security scans and penetration testing.
Managed Security Services – Leveraging Google Cloud Platform (GCP) enterprise-grade security infrastructure.
Automatic backup & data replication to protect against data loss or destruction.
Data Encryption
- Transport Layer Security (TLS) encryption for all data in transit.
- Private connections between your systems and our cloud infrastructure.
- End-to-end encryption for data at rest, so information stays protected even if storage itself is ever compromised.
Read-Only Data Separation
- AutoQL pulls data from original sources (e.g. SaaS customer databases, data warehouses).
- All data is replicated into the cloud in read-only mode.
- No write functionality in the application — no one, including authorized users, can modify source data through AutoQL.
Compliance, Certifications & Controls
Chata.ai maintains the highest security standards:
SOC 2 Type II attestation – Demonstrating controls over security and availability.
ISO 27001 Certified – Comprehensive information security management system.
Annual Vulnerability Assessments – Regular security scans and penetration testing.
Managed Security Services – Leveraging Google Cloud Platform (GCP) enterprise-grade security infrastructure.
Automatic backup & data replication to protect against data loss or destruction.
Data Encryption
- Transport Layer Security (TLS) encryption for all data in transit.
- Private connections between your systems and our cloud infrastructure.
- End-to-end encryption for data at rest, so information stays protected even if storage itself is ever compromised.
Read-Only Data Separation
- AutoQL pulls data from original sources (e.g. SaaS customer databases, data warehouses).
- All data is replicated into the cloud in read-only mode.
- No write functionality in the application — no one, including authorized users, can modify source data through AutoQL.
Core Security Commitments
• Chata.ai notifies customers of any security incidents without undue delay upon discovery.
• Only authorized persons have access to customer data on a principle of need-to-know basis
• Peer review and approval of application development code required prior to implementation
• Continuous source code analysis through automated and manual review processes to identify and remediate vulnerabilities and code quality issues
• Regular business continuity planning and disaster recovery testing
• Background checks, confidentiality agreements, and annual security training for all employees.
Core Security Commitments
• Chata.ai notifies customers of any security incidents without undue delay upon discovery.
• Only authorized persons have access to customer data on a principle of need-to-know basis
• Peer review and approval of application development code required prior to implementation
• Continuous source code analysis through automated and manual review processes to identify and remediate vulnerabilities and code quality issues
• Regular business continuity planning and disaster recovery testing
• Background checks, confidentiality agreements, and annual security training for all employees.
Product Details & Security Features
AutoQL SaaS (Chata-Managed Cloud Platform)
AutoQL SaaS is a Chata.ai-managed, cloud-hosted platform that enables natural-language access to customer data while maintaining strict data governance.
Data Management
• The platform stores limited nominal data necessary to support service functionality, including:
– Metadata and configuration information
– Query history for optimization and audit purposes
– Customer-specific settings and integrations
• All data is associated with a unique Customer ID and is cryptographically isolated
• Data is refreshed on a configurable schedule
• All management occurs through the AutoQL Integrator Portal
AutoQL Deployable (Privacy-First, Customer-Hosted Solution)
AutoQL Deployable is designed for organizations requiring maximum control and zero data movement. The solution runs entirely within your own environment.
Key Benefits
• True Data Privacy – All processing and data remain inside your infrastructure
• Zero Data Movement – No sensitive data leaves your environment
• Complete Control – You manage security, compliance, and operational policies
• Network Isolation – Operates within your firewall and network boundaries
Security in AutoQL Deployable
• User-Level Access Control – Unique Customer ID with role-based (RBAC) or ACL-based authority. Compatible with most IDP and support MFA.
• Network Security – Integrator Partner Security protocols for external integrations
• Audit & Logging – Full query history and access logging within your environment
• Data Governance – Metadata and configuration management on your infrastructure
AI Guardrails
Chata implements comprehensive AI Guardrails across multiple layers:
Deterministic AI architecture that eliminates hallucinations for structured analytics.
Customer-specific language models trained on each customer's schema and business logic.
Customer data is never used for model training.
Fully auditable SQL generation with transparent "show your work" capability.
Enterprise identity integration with role-based access control.
Native enforcement of row-level and column-level security.
Multi-tenant architecture with logical isolation between customers.
Secure deployment options that support enterprise governance and compliance
Secure LLM Integration Approach to Mitigate Common Risks:
Data leakage: Sensitive data is masked before reaching the LLM. The model only sees the user's query and the database schema, with embeddings hosted internally for added privacy.
Wrong or inaccurate answers: SQL generation is deterministic, validated before execution, and continuously tested to ensure accuracy.
Security attacks (prompt injection): User input is treated as data, not instructions, and all generated SQL is validated to allow only safe, read-only queries.
Unauthorized data access: Authentication, server-side access controls, and enforced row- and column-level permissions prevent unauthorized access.
Biased responses: A closed-domain design and multi-model evaluation help minimize bias in generated outputs.
Auditability and traceability: Every request is logged, versioned, and fully traceable from input to response.
Copyright/IP risks: Customer data is protected, providers do not use it for model training, and outputs are limited to SQL generated for the customer's own database.
Model drift and outdated knowledge: Queries are executed against the live database, while version-pinned models and regression testing ensure consistent performance.
Human oversight: Human review, approval workflows, curated test cases, and user feedback help maintain quality and reliability.
Product Details & Security Features
AutoQL SaaS (Chata-Managed Cloud Platform)
AutoQL SaaS is a Chata.ai-managed, cloud-hosted platform that enables natural-language access to customer data while maintaining strict data governance.
Data Management
• The platform stores limited nominal data necessary to support service functionality, including:
– Metadata and configuration information
– Query history for optimization and audit purposes
– Customer-specific settings and integrations
• All data is associated with a unique Customer ID and is cryptographically isolated
• Data is refreshed on a configurable schedule
• All management occurs through the AutoQL Integrator Portal
AutoQL Deployable (Privacy-First, Customer-Hosted Solution)
AutoQL Deployable is designed for organizations requiring maximum control and zero data movement. The solution runs entirely within your own environment.
Key Benefits
• True Data Privacy – All processing and data remain inside your infrastructure
• Zero Data Movement – No sensitive data leaves your environment
• Complete Control – You manage security, compliance, and operational policies
• Network Isolation – Operates within your firewall and network boundaries
Security in AutoQL Deployable
• User-Level Access Control – Unique Customer ID with role-based (RBAC) or ACL-based authority. Compatible with most IDP and support MFA.
• Network Security – Integrator Partner Security protocols for external integrations
• Audit & Logging – Full query history and access logging within your environment
• Data Governance – Metadata and configuration management on your infrastructure
AI Guardrails
Chata implements comprehensive AI Guardrails across multiple layers:
Deterministic AI architecture that eliminates hallucinations for structured analytics.
Customer-specific language models trained on each customer's schema and business logic.
Customer data is never used for model training.
Fully auditable SQL generation with transparent "show your work" capability.
Enterprise identity integration with role-based access control.
Native enforcement of row-level and column-level security.
Multi-tenant architecture with logical isolation between customers.
Secure deployment options that support enterprise governance and compliance
Secure LLM Integration Approach to Mitigate Common Risks:
Data leakage: Sensitive data is masked before reaching the LLM. The model only sees the user's query and the database schema, with embeddings hosted internally for added privacy.
Wrong or inaccurate answers: SQL generation is deterministic, validated before execution, and continuously tested to ensure accuracy.
Security attacks (prompt injection): User input is treated as data, not instructions, and all generated SQL is validated to allow only safe, read-only queries.
Unauthorized data access: Authentication, server-side access controls, and enforced row- and column-level permissions prevent unauthorized access.
Biased responses: A closed-domain design and multi-model evaluation help minimize bias in generated outputs.
Auditability and traceability: Every request is logged, versioned, and fully traceable from input to response.
Copyright/IP risks: Customer data is protected, providers do not use it for model training, and outputs are limited to SQL generated for the customer's own database.
Model drift and outdated knowledge: Queries are executed against the live database, while version-pinned models and regression testing ensure consistent performance.
Human oversight: Human review, approval workflows, curated test cases, and user feedback help maintain quality and reliability.


See How It Works With Your Data
Book a 20-minute call with our technical team. We'll map Chata.ai's security architecture to your specific tech stack, deployment requirements, and access control setup.


