Three principles we don't bend on
Most bots ask you to trust them. We'd rather you didn't have to — every design decision on this page comes back to one of these three.
Least privilege. We request only the permissions a feature actually needs — never Administrator, never "just in case."
Total transparency. Every action we take is logged where you can see it. There are no silent operations.
Reversible by design. Remove us in one click. There is no lingering token, session, or access of any kind.
Permissions & Access
ChevLink does not require Administrator to operate. Each module asks only for the Discord permissions it needs to function — disable a module you don't use, and its permissions go unused.
| Module | Permissions used | Why |
|---|---|---|
| Verification | Manage Roles, Manage Nicknames | Assign your verified / unverified roles and set member nicknames. |
| Anti-Nuke & Anti-Raid | View Audit Log, Ban, Kick, Manage Roles | Detect mass-destructive actions and reverse them in real time. |
| Lockdown | Manage Channels, Manage Roles | Restrict access during an active threat, then lift it. |
| Webhook protection | Manage Webhooks | Remove malicious or unknown webhooks used to nuke or spam. |
| Logging & alerts | View Channels, Send Messages, Embed Links | Post audit entries and alerts to a log channel you own. |
Role hierarchy is your hard limit. Place ChevLink's role below your owner, admin, and other protected roles. Discord's permission model then makes it physically impossible for the bot to add, remove, or modify anything above it — no matter what it's asked to do, by us or anyone else.
Everything Is Auditable
A backdoor depends on being hidden. ChevLink is the opposite — every enforcement action is recorded in two independent places you control:
- Discord's native Audit Log. Every ban, role change, and channel action shows up in your server's own audit log, attributed to ChevLink — visible to your staff, independent of us.
- A
#chevlink-logschannel you own. Verifications, enforcement, and dashboard configuration changes are mirrored to a channel in your server, in plain language, so non-technical staff can follow along too.
Instant, Total Removal
ChevLink holds no persistent access to your server. Remove the bot — or revoke a single permission — and it loses that access immediately. There is no API token left behind, no lingering session, no separate "agent." Removal stops all new data collection at once, and you can request deletion of what was stored (see Section 10).
The Backdoor Question
A fair, common concern: a deep-permission bot from an unknown developer is an attack surface. We agree — so here's the honest answer, in two parts.
Backdoors rely on opacity. ChevLink is least-privilege, fully audit-logged, and removable in one click — you can watch every action it takes and cut it off instantly. That is the structural opposite of a hidden backdoor.
The exact threat you fear is what we defend against. A rogue or compromised bot mass-banning members, deleting channels, or stripping roles is precisely what ChevLink's anti-nuke is built to detect and stop in real time — including against other bots. The thing that keeps you up at night is the thing we were built to catch.
What We Store — and What We Don't
We practice data minimization: we keep what a feature needs to function, and nothing more.
What we store
- Network ban records — user IDs and reasons, kept as limited identifiers so the dataset can't be scraped or replicated.
- Verification links — the Discord ↔ Roblox association needed to verify and re-verify members.
- Server snapshots — your server's structure (roles, channels, settings) so it can be restored after an attack.
- Reports — submitted through your private reporting form (see Section 9).
- Config & audit entries — your settings and a record of staff actions in your dashboard.
What we don't
- We do not retain bulk message history or DMs. Where a feature must act on content (e.g. scam/link detection), messages are evaluated in real time; only the minimum needed for an action or audit entry is kept.
- We do not see or store payment-card data — billing runs through Stripe.
- We do not sell or rent your community's data, ever.
Encryption
- In transit — TLS 1.3. Every connection between your server, our services, and the dashboard is encrypted. Nothing travels in the clear.
- At rest — AES-256. Sensitive data is encrypted at rest, so a snapshot of storage on its own reveals nothing usable.
- Reports are encrypted and only ever decrypt to your community's dashboard.
Role-Based Access Control
You decide who sees what. You choose which of your staff can access your dashboard, and which tabs each of them can open — access is granted per-seat and per-permission, and you can revoke it instantly. New staff start with nothing until you grant it.
Shared network intelligence (like ban records) is limited to the minimal identifiers needed to protect other communities, and is never tied to your server's private configuration.
Report Confidentiality
Each community gets a private reporting link — more confidential than a Discord ticket, where staff and bots can read everything.
Reports submitted through your link (crnsecure.com/community/…/report) are encrypted and routed only to your community's dashboard — not a shared inbox, not a public channel. Where you enable it, members can submit anonymously.
Because reports decrypt only to your dashboard, sensitive submissions — harassment, safeguarding, staff misconduct — never sit in a channel where the wrong person can scroll back and read them.
Retention & Deletion
| Action | What happens |
|---|---|
| Request export or deletion | Request an export or deletion of your community's data at any time, and we'll action it. |
| Remove ChevLink | The moment the bot leaves your server, no new data is collected from it. |
| Network bans (the one exception) | May persist in the shared threat network — as limited identifiers only — because they protect every other community, but are never linked to your server's private configuration. |
For full detail on retention windows and your rights under GDPR, UK GDPR, and US law, see the ChevLink Cyber Privacy Policy.
Who's Behind ChevLink
ChevLink is built by CRN — the Cybersecurity Response Network. We're a security-first organisation, not a general-purpose bot shop, and protection is the entire point of what we build.
We're already trusted by flagship communities, including High Rock Border Roleplay (11.9k members). We'd rather earn your trust by letting you verify than ask for it blindly — which is exactly what the read-only trial below is for.
Have Your Security Team Vet Us
We'll walk your staff through our permission model and data handling, and start read-only on a test server — so you're verifying, not trusting. No cost, removable any time. Bring your hardest questions; that scrutiny is a good thing.
This page describes our security practices and is provided for transparency. It is not a contract or a certification. For the formal legal terms, see the Privacy Policy and Terms of Use.