Get started

Two ways to run Chameleon. Pick the one that fits your infra.

Every Chameleon instance is fully isolated — its own keys, its own data, nothing shared with any other customer. The only choice is who runs it: you, in your own cloud, or Chameleon, on your behalf.


Choose your path

Self-serve (BYOC)

You run one installer command against your own GCP project. Nothing — no keys, no data, no infrastructure — ever leaves your cloud. This is the tier security-conscious teams and banks choose, since Chameleon never has any access to what you're protecting.

What it needs from you: a GCP project, its project ID and number, and 10-15 minutes to run bootstrap.sh.

Hosted

Chameleon provisions and runs a fully isolated instance for you — its own dedicated GCP project, its own billing, nothing shared with any other customer. No GCP project or infrastructure knowledge required on your end.

What it needs from you: just the signup form. A person reviews and approves each hosted signup before anything is provisioned.


What happens after you sign up
01 / Sign up

Pick self-serve or hosted, tell us your warehouse (BigQuery or Snowflake) and instance details.

02 / Fulfillment

Self-serve: your terraform.tfvars is generated and emailed immediately, no waiting. Hosted: a person reviews and approves, then Chameleon provisions your dedicated project.

03 / Install

Self-serve: run bootstrap.sh once against your own project. Hosted: nothing to run — you get a console URL and password by email when it's ready.

04 / Declare & protect

Log into your console and declare which warehouse tables and columns hold PII. Chameleon starts protecting and tracking it from there.

05 / Delete & prove

Run deletion requests and get back a signed, timestamped certificate — the evidence an auditor or regulator actually asks for.


FAQ

Common questions

What's the difference between self-serve and hosted?

Self-serve (BYOC) runs entirely in your own GCP project — you run one installer command and Chameleon never touches your infrastructure or data. Hosted means Chameleon provisions and runs a fully isolated instance for you, on Chameleon's own billing, with no GCP project or infrastructure knowledge required on your side.

How long does self-serve onboarding take?

Signing up is instant. Registry access to Chameleon's images is granted automatically, and the generated terraform.tfvars is emailed to you right away. Running the installer against your own project typically takes 10-15 minutes.

How long does hosted onboarding take?

Hosted signups are reviewed before anything is provisioned, since it runs on Chameleon's own billing. Once approved, project creation and setup typically finish within the hour, and you'll get an email with your console URL and password.

What does self-serve need from my GCP project?

Just a project ID and its project number. Chameleon grants a single read-only Artifact Registry permission to your project's own Cloud Run service agent — nothing broader, and Chameleon never gets any access to your project in return.

Can I switch between self-serve and hosted later?

Each is a separate signup today — there's no in-place migration between them yet. If that's something you need, reach out and we can talk through what makes sense for your setup.


Keep reading

How Chameleon maps warehouse tables and columns and maintains a live PII registry.

Ready to pick a path? The signup form walks you through self-serve or hosted in a couple minutes.