Describe it. We set up everything.It runs in the AWS account you already own.
Kronos talks with the people who will use the tool, writes the spec, builds the app, and deploys it into your cloud. Sign-in, audit logs, encryption and backups are in place before the first user logs in.
- +vpc / private subnets ×2yours
- +postgres · encrypted at restyours
- +row-level security · 3 rolesyours
- +s3 · claim-photos · KMSyours
- +sso · your identity provideryours
- +cloudtrail · audit log onyours
- +nightly backups · 35 daysyours
- +claims.yourco.com · TLSyours
From a sentence to a tool your team uses
Most app builders stop at a prototype. Kronos keeps going until the software is running in your cloud, owned by you, with someone watching it.
Describe the problem
Tell Kronos what the tool is for. It interviews each stakeholder and asks about the things people forget: who can see what, what gets audited, what happens when someone leaves.
Approve the spec
You get a plain-language spec and a clickable preview in a sandbox. Nothing touches your cloud until you sign off.
Deploy to your account
One narrowly scoped role in your AWS account. Kronos provisions the app there, on your domain, with your sign-in.
Keep it running
Backups, monitoring and change requests continue after launch. Every change is reviewed and logged before it ships.
We build. You own what runs.
The build happens on our side. The finished app, its data and its logs live on yours. Remove the role and it keeps running without us.
The workshop
- Stakeholder interviews and the spec
- Sandboxed builds and previews
- Tests that run before every release
- Release artifacts, signed and versioned
The building
- The running app and its database
- Your customer and employee data
- Audit logs, backups and keys
- Your domain, your sign-in, your bill
No AWS account yet? We can create one for you in a managed organization and hand it over whenever you want it.
The defaults an auditor asks about
Access rules are enforced by the platform, not left to generated code. Each control ships with the evidence to show it is on.
ACCESSRow-level security by role
People see only the records their role allows, checked in the database on every query.
IDENTITYYour single sign-on
Okta, Microsoft Entra or Google Workspace. Offboarding in your directory removes access to the app.
AUDITEvery change on the record
CloudTrail and app-level logs of who viewed and changed what, kept in your account.
DATAEncrypted with your keys
Storage and databases encrypted at rest with keys you control in AWS KMS.
RECOVERYBackups you can restore
Nightly point-in-time backups, with a restore drill before launch.
CHANGEReviewed releases
Changes go through a staging copy and your approval before they reach production.
Teams that can't send data to someone else's cloud
Insurance
Claims intake, agent CRMs and policy servicing tools, with the access controls your carriers expect.
Legal and nonprofit
Searchable document libraries, case tracking and intake forms for organizations that handle sensitive records.
Healthcare operations
Internal tools that stay inside your AWS environment and under your agreement with AWS.
Tell us what you need built
A demo is a 30-minute call where we walk through a build like yours. Early access puts your team on the list for the next onboarding group. Either way, a person reads every request.