Access control
Team roles
| Role | Requests | Policy | Keys | Audit |
|---|---|---|---|---|
| Admin | allowed | allowed | allowed | allowed |
| Compliance lead | allowed | allowed | —no access | allowed |
| Analyst | allowed | —no access | —no access | —no access |
| Developer | —no access | —no access | allowed | —no access |
| Auditor | allowed | —no access | —no access | allowed |
11:05 · access.role_changed · max@ → Analyst · by anna@
Every decision is verifiable. Every action is logged.
PilotChain is built for teams accountable to a regulator, a partner bank and their own auditor.
Who changed what and when — always visible.
Decisions, manual overrides, changes to policies, keys and access — with author and time.
Log export — on the auditor's request
Audit log Today
5 events- 13:34POLICY
policy.updated
RULE_07: weight 18 → 22 · anna@
- 13:12DECISION
decision.overridden
pc_82a61: REVIEW → ALLOW · max@
- 12:48API_KEY
api_key.rotated
sk_live_…4f2a · dev@
2 more: access.role_changed, bundle.updated
What protects your data and decisions.
Least privilege, environment isolation and data minimization — by default, not as an option.
Full audit log
Decisions, overrides, changes to policies, keys and access.
AUDIT_LOGRoles and access
Who sees requests, who changes the policy, who manages keys.
RBACKey isolation
Separate sandbox and production keys, rotation and revocation.
SK_TEST · SK_LIVEData minimization
Providers receive only the fields a check needs.
DATA_MINEncryption
Data is encrypted in transit and at rest.
TLS · AT RESTMonitoring and status
A public status page and incident notifications.
STATUSDocuments for your compliance team and partner bank.
We send the document pack on request under NDA and answer security questionnaires from your team and partner bank.
Request the packOn request under NDA.
What's in the pack:
- Architecture and data flow description
- Personal data processing policy
- Data Processing Agreement (DPA)
- List of subprocessors and data providers