Security and privacy
Confidential product data is treated as crown-jewel IP
Controls are designed against SOC 2 Type II and ISO 27001 objectives from inception. These are the control targets the platform is built toward; they are not certifications currently held.
Commitments
Ten commitments that govern your data
Each commitment is enforced in the platform rather than described in a policy document alone.
Role-based and attribute-based access
Access is decided by role and by attributes including tenant, project, purpose, jurisdiction, consent state, conflict status, and data class. Unauthorized requests fail closed.
Encryption in transit and at rest
TLS protects data in transit and envelope encryption protects data at rest, with per-tenant or per-project keys and customer-managed keys available on enterprise terms.
Project isolation
Isolation is enforced across application, database, search, graph, object storage, and cache layers, so one project's material cannot leak into another's analysis.
Data minimization
Only the material needed for the decision at hand is collected, retained, and exposed to any given role.
Consent management
Purpose, data rights, and retention terms are accepted before processing, recorded, and re-checked whenever the purpose changes.
Retention controls
Retention, deletion, export, legal hold, and data-residency handling are configurable and enforced per contract.
Immutable audit evidence
Access, analysis, approval, override, and disclosure events are written to an append-only audit trail with signed approvals.
Versioned policies and models
Policy packs and models are versioned artifacts, and every decision records the versions that produced it, so nothing is silently rewritten.
Human authorization
Binding conclusions require a named approver with the relevant authority, and privileged actions are logged and reviewable.
Revocable sharing
Every disclosure to an investor, expert, or partner is scoped, time-boxed where required, logged, and revocable by the project owner.
Training
No cross-client training without explicit authorization
Your project material is not used to train models for other customers. Any cross-project learning requires explicit consent, appropriate de-identification, and contractual authorization, and remains auditable after the fact.
Control baseline
Controls by group
Isolation and access
- Tenant isolation enforced in the application, database, search, graph, object, and cache layers
- RBAC plus ABAC using tenant, project, role, purpose, jurisdiction, consent, conflict, and data class
- SSO, MFA, SCIM, short-lived tokens, service identities, and least privilege
Encryption and key management
- TLS in transit and envelope encryption at rest
- Per-tenant or per-project keys for enterprise tiers
- Customer-managed keys and regional storage where contracted
- Secrets management, rotation, hardware-backed keys, and break-glass controls
Content and model safety
- Malware scanning, sandboxed parsing, and content disarm on ingestion
- Data-loss prevention and prompt-injection filtering
- Model and policy versioning with deterministic evidence snapshots
Assurance and lifecycle
- Immutable audit trail and signed approvals
- Retention, deletion, export, legal hold, and residency handling
- Backup, restoration testing, incident response, and vendor-risk review
Privacy
Applicability is assessed, not assumed
- HIPAA applicability depends on entity, role, data, and activity; it is not triggered automatically by every medical-product project. Where ePHI is processed for a covered entity or business associate, administrative, physical, and technical safeguards and a risk analysis apply.
- Personal data and PHI trigger restricted processing paths and narrower retention.
- Privileged actions are logged, and high-risk exports, model changes, and cross-project analytics require explicit approval.
Request the security overview
We share the control matrix, data-flow map, and the assurance work still in progress.