Chameleon

PII compliance.
Found, tracked,
proven deleted.

A control plane for data warehouses_

Chameleon maps warehouse tables and columns automatically, records ghost-data findings from scans, and generates deletion proof across connected downstream systems.


Live scan

stg_users.data - 8 columns scanned

columntypedeclaredfinding
user_idINT64yes-
created_atTIMESTAMPyes-
emailSTRINGnoGHOST_DATA
plan_tierSTRINGyes-
phone_hashSTRINGnoSUSPECT_PII
regionSTRINGyes-
mrr_usdFLOAT64yes-
deleted_atTIMESTAMPyes-

The problem

Customer data spreads faster than compliance teams can track.

Warehouses, dbt models, SaaS tools, exports, and analytics copies all accumulate customer data. When a deletion request arrives, most teams cannot answer what exists, where it lives, or whether it was ever removed.


What Chameleon does

Discover PII

Map warehouse tables and columns automatically, then maintain a live registry of where customer data lives and who owns each resource.

Detect ghost data

Surface undeclared PII columns that exist in the warehouse but are not registered — before they become an audit finding.

Enforce policy

Evaluate each resource against deletion strategy requirements and flag policy drift before a compliance review arrives.

Execute deletion

Trigger deletion workflows that reach the warehouse, connected SaaS systems, and downstream copies in a single request.

Prove deletion

Generate a signed, timestamped certificate of destruction that answers GDPR Article 17 and DSAR evidence requirements.

Decrypt on your terms

Call the Key Vault directly, or declare a live-decrypting BigQuery view for warehouse joins. Either way, plaintext is never persisted — and a crypto-shred stops both instantly.


How it works

A control plane for PII policy, deletion, and proof.

01 / Warehouse

Connect BigQuery. Chameleon maps every table and column automatically and registers declared PII fields.

02 / Registry

A live asset registry tracks which columns hold PII, which policies govern them, and which dbt models inherit that data.

03 / Policy

Ghost-data findings from configured scans remain visible for policy review before drift becomes an audit risk.

04 / Deletion

When a deletion request arrives, the Key Vault destroys the user's encryption key. Every copy of that data — warehouse tables, dbt models, backups, exports — becomes mathematically unreadable instantly. No row scans. No missed copies.

05 / Proof

A signed, timestamped proof record is generated. Auditor-ready, immediately.


Demo console

Watch one user go from raw data to deletion proof.

Playing on its own — click any step, or type a different user id, to take over and explore it yourself.

● Auto-playing
READY

Start with a customer id

A privacy operator enters the user id from a deletion request.

Raw table

stg_users.data

tenant_idtenant_demo
user_iduser_1042
emailwaiting
phonewaiting
Protected warehouse

encrypted + modeled

tokennot created
ciphertextnot created
surrogatenot modeled
Key Vault
active

dek_141d74

Active key protects encrypted PII.

Deletion request

No request yet

SHRED_REQUESTEDKEY_DESTROYEDCASCADE_COMPLETECERTIFICATE_ISSUED
Janitor receipts
warehouseBigQuery

not requested

saasHubSpot

not requested

saasSalesforce

not requested

evidenceGCS audit logs

not requested

Proof certificate

Certificate pending

subjectuser_1042
requestdelreq_141d74d1
statusPENDING
evidencegcs://audit/lineage

Integrations

BigQuery

Where encrypted PII lives. Chameleon maps tables and columns, tracks policy, and crypto-shreds data on deletion.

dbt

dbt model lineage tells Chameleon which downstream tables inherit PII from upstream sources.

Snowflake

Where encrypted PII lives, same as BigQuery. Chameleon maps tables and schemas, tracks policy, and crypto-shreds data on deletion.

HubSpot

Connected SaaS wipe target. Chameleon sends deletion instructions and collects the receipt as deletion proof.

Salesforce

Connected SaaS wipe target. Contact deletion receipts are collected and included in the proof certificate.


Learn

PII deletion, explained.

Crypto-shredding

Why destroying an encryption key is a more complete and provable deletion than deleting rows — and why auditors accept it.

GDPR Article 17

What the right to erasure actually requires, what auditors check, and how to produce evidence that survives a regulator review.

Deletion proof

How Chameleon coordinates deletion across the warehouse and connected SaaS systems, then issues a signed certificate of destruction.


Ready to know exactly where customer data lives and prove it is gone?

Contact us