Security & Data Protection

ChatLMS is built to clear your security review: per-org isolation, an append-only audit log, two-factor authentication, encryption in transit and at rest, and content that never trains external AI. Here's how each control works.

How We Protect Your Data

Per-Tenant Isolation

Every organization's content, users, and analytics are scoped to that tenant. Data never crosses organizational boundaries, enforced at the application layer with a database row-level-security backstop.

Encryption

All traffic is encrypted in transit (TLS). Sensitive secrets (including two-factor authentication keys) are encrypted at rest, and passwords are stored using a strong one-way hash.

Authentication & Access Control

Role-based access control, optional org-wide two-factor authentication (TOTP), session revocation, and fine-grained permission profiles. SSO/SAML is available for enterprise plans.

Audit Logging

Security-relevant actions (sign-ins, permission changes, deletions, and data access) are recorded to a per-organization audit log that admins can review.

Your Data Isn't Used to Train External Models

Your content is used only to power answers for your organization. It is not used to train third-party foundation models. See our Data Privacy page and subprocessor list.

Compliance Program

We are pursuing SOC 2 and align our controls to its Trust Services Criteria (security, availability, confidentiality). Security documentation is available to prospective customers under NDA.

Need Our Security Documentation?

We share our security overview, subprocessor list, and SOC 2 status with prospective enterprise customers.

Request Security Docs

Found a vulnerability? Email support@chatlms.ai.