Trust Center

Built to be examined.

Our customers review vendors for a living. This page is written for your security office, your counsel, and your procurement team — and we would rather over-answer than gloss.

Data handling

Institutional data is logically isolated per tenant. Encryption in transit and at rest. Institution-controlled retention. Researcher data is processed for compliance verification on your instruction — we are a processor acting for the institution, not a data broker.

We do not sell, share, or pool your data, and we never use your data to train AI models.

AI governance

AI is used to accelerate document review and evidence reconciliation. Findings are graded, sourced, and presented to your officers for decision — the platform does not auto-adjudicate. AI-assisted determinations are logged for auditability: the input factors, the resulting score, and the model-version metadata are captured with each determination so a reviewer can reconstruct what was decided and by which model.

Our full AI governance statement is available on request during security review. A public summary will be published here as our first institutional deployments complete.

Audit & evidence

Every certification captures an immutable evidence snapshot — what was checked, what it showed, who decided what, and when. Designed for IG inquiries, sponsor audits, and litigation defense.

Our security posture — verifiable today

  • Tenant isolation by design — each institution's data is scoped per tenant on every query, and that scoping is verified automatically in the build pipeline (see the access-control bullet below).
  • Append-only audit trail — every consequential action is recorded immutably, with retention configurable to your institution's policy (3–10+ years).
  • Access-control enforcement is verified automatically in our build pipeline — organizational data scoping is checked on every change, not just in code review.
  • No third-party runtime calls in the browser — all fonts and assets are self-hosted; your users' browsers talk only to the platform. Server-side, where subprocessors are required (hosting, AI model providers, transactional email), they are invoked under contractual data-protection controls — see Subprocessors below.
  • We verify — we never transmit. The platform reads your institutional systems to verify disclosures. It never submits to federal systems (SciENcv and Research.gov remain the systems of record) and never authors researcher adverse-event records.

Certifications & assessments

  • SOC 2 — on our roadmap; we have not yet begun a formal audit engagement, and we'll say so plainly until we have. Design partners receive our security architecture documentation and direct access to our team for security review.
  • HECVAT — we will complete your institution's HECVAT (Lite or Full) as part of your procurement security review.
  • Single sign-on — SAML 2.0 / OIDC SSO is a requirement of every institutional deployment; no pilot goes live without it.

Subprocessors & hosting

We maintain a short list of subprocessors — cloud hosting, AI model providers under no-training commitments, and transactional email. The current list is provided to institutions during security review, and will be published here as our first institutional deployments complete.

Security documentation

Request our security documentation.

Security architecture documentation, subprocessor list, AI governance statement, and — for institutions under procurement review — HECVAT completion by our team. Routed to the founder.