Discover PII
Map warehouse tables and columns automatically, then maintain a live registry of where customer data lives and who owns each resource.
A control plane for data warehouses_
Chameleon maps warehouse tables and columns automatically, records ghost-data findings from scans, and proves data is gone from the warehouse with a signed certificate — not a vague promise.
stg_users.data - 8 columns scanned
| column | type | declared | finding |
|---|---|---|---|
| user_id | INT64 | yes | - |
| created_at | TIMESTAMP | yes | - |
| STRING | no | GHOST_DATA | |
| plan_tier | STRING | yes | - |
| phone_hash | STRING | no | SUSPECT_PII |
| region | STRING | yes | - |
| mrr_usd | FLOAT64 | yes | - |
| deleted_at | TIMESTAMP | yes | - |
Warehouses, dbt models, SaaS tools, exports, and analytics copies all accumulate customer data. When a deletion request arrives, most teams cannot answer what exists, where it lives, or whether it was ever removed.
Discover PII
Map warehouse tables and columns automatically, then maintain a live registry of where customer data lives and who owns each resource.
Detect ghost data
Surface undeclared PII columns that exist in the warehouse but are not registered — before they become an audit finding.
Enforce policy
Evaluate each resource against deletion strategy requirements and flag policy drift before a compliance review arrives.
Execute deletion
Trigger a crypto-shred that makes every warehouse copy — tables, dbt models, backups, exports — mathematically unreadable instantly. Optionally reaches connected SaaS tools too.
Prove deletion
Generate a signed, timestamped certificate proving warehouse erasure — the claim it can fully back — that answers GDPR Article 17 and DSAR evidence requirements.
Decrypt on your terms
Call the Key Vault directly, or declare a live-decrypting BigQuery view for warehouse joins. Either way, plaintext is never persisted — and a crypto-shred stops both instantly.
Connect BigQuery. Chameleon maps every table and column automatically and registers declared PII fields.
A live asset registry tracks which columns hold PII, which policies govern them, and which dbt models inherit that data.
Ghost-data findings from configured scans remain visible for policy review before drift becomes an audit risk.
When a deletion request arrives, the Key Vault destroys the user's encryption key. Every warehouse copy of that data — tables, dbt models, backups, exports — becomes mathematically unreadable instantly. No row scans, no missed copies. Connected SaaS tools get wiped too, when configured.
A signed, timestamped proof record is generated. Auditor-ready, immediately.
Playing on its own — click any step, or type a different user id, to take over and explore it yourself.
A privacy operator enters the user id from a deletion request.
Active key protects encrypted PII.
Optional — shown for visibility, not part of the certified claim.
not requested
not requested
not requested
not requested
BigQuery
Where encrypted PII lives. Chameleon maps tables and columns, tracks policy, and crypto-shreds data on deletion.
dbt
dbt model lineage tells Chameleon which downstream tables inherit PII from upstream sources.
Snowflake
Where encrypted PII lives, same as BigQuery. Chameleon maps tables and schemas, tracks policy, and crypto-shreds data on deletion.
HubSpot
Optional: once warehouse erasure is proven, Chameleon can also send a deletion instruction to HubSpot and record the receipt.
Salesforce
Optional: same as HubSpot — a bonus cleanup step on top of the certified warehouse erasure, not a substitute for it.
Crypto-shredding
Why destroying an encryption key is a more complete and provable deletion than deleting rows — and why auditors accept it.
GDPR Article 17
What the right to erasure actually requires, what auditors check, and how to produce evidence that survives a regulator review.
Deletion proof
How Chameleon proves warehouse erasure with a signed certificate of destruction — and optionally tracks connected SaaS cleanup alongside it.