Discover PII
Map warehouse tables and columns automatically, then maintain a live registry of where customer data lives and who owns each resource.
A control plane for data warehouses_
Chameleon maps warehouse tables and columns automatically, records ghost-data findings from scans, and generates deletion proof across connected downstream systems.
stg_users.data - 8 columns scanned
| column | type | declared | finding |
|---|---|---|---|
| user_id | INT64 | yes | - |
| created_at | TIMESTAMP | yes | - |
| STRING | no | GHOST_DATA | |
| plan_tier | STRING | yes | - |
| phone_hash | STRING | no | SUSPECT_PII |
| region | STRING | yes | - |
| mrr_usd | FLOAT64 | yes | - |
| deleted_at | TIMESTAMP | yes | - |
Warehouses, dbt models, SaaS tools, exports, and analytics copies all accumulate customer data. When a deletion request arrives, most teams cannot answer what exists, where it lives, or whether it was ever removed.
Discover PII
Map warehouse tables and columns automatically, then maintain a live registry of where customer data lives and who owns each resource.
Detect ghost data
Surface undeclared PII columns that exist in the warehouse but are not registered — before they become an audit finding.
Enforce policy
Evaluate each resource against deletion strategy requirements and flag policy drift before a compliance review arrives.
Execute deletion
Trigger deletion workflows that reach the warehouse, connected SaaS systems, and downstream copies in a single request.
Prove deletion
Generate a signed, timestamped certificate of destruction that answers GDPR Article 17 and DSAR evidence requirements.
Decrypt on your terms
Call the Key Vault directly, or declare a live-decrypting BigQuery view for warehouse joins. Either way, plaintext is never persisted — and a crypto-shred stops both instantly.
Connect BigQuery. Chameleon maps every table and column automatically and registers declared PII fields.
A live asset registry tracks which columns hold PII, which policies govern them, and which dbt models inherit that data.
Ghost-data findings from configured scans remain visible for policy review before drift becomes an audit risk.
When a deletion request arrives, the Key Vault destroys the user's encryption key. Every copy of that data — warehouse tables, dbt models, backups, exports — becomes mathematically unreadable instantly. No row scans. No missed copies.
A signed, timestamped proof record is generated. Auditor-ready, immediately.
Playing on its own — click any step, or type a different user id, to take over and explore it yourself.
A privacy operator enters the user id from a deletion request.
Active key protects encrypted PII.
not requested
not requested
not requested
not requested
BigQuery
Where encrypted PII lives. Chameleon maps tables and columns, tracks policy, and crypto-shreds data on deletion.
dbt
dbt model lineage tells Chameleon which downstream tables inherit PII from upstream sources.
Snowflake
Where encrypted PII lives, same as BigQuery. Chameleon maps tables and schemas, tracks policy, and crypto-shreds data on deletion.
HubSpot
Connected SaaS wipe target. Chameleon sends deletion instructions and collects the receipt as deletion proof.
Salesforce
Connected SaaS wipe target. Contact deletion receipts are collected and included in the proof certificate.
Crypto-shredding
Why destroying an encryption key is a more complete and provable deletion than deleting rows — and why auditors accept it.
GDPR Article 17
What the right to erasure actually requires, what auditors check, and how to produce evidence that survives a regulator review.
Deletion proof
How Chameleon coordinates deletion across the warehouse and connected SaaS systems, then issues a signed certificate of destruction.