Trust & security

Your experiments are yours alone

Experimental data is proprietary before it is scientific. The platform is built so that your datasets, models and results are isolated to your account, never pooled, and never used to train anything shared.

Model

How the platform protects you

What the platform actually does today — each pillar names the backend mechanism that backs it.

01

Authentication

Passwords are stored as salted Argon2id hashes — the server never keeps plaintext. Legacy accounts hashed with an older scheme keep verifying, and new hashes use Argon2id library defaults (backend/models/tables/users.py). You can also sign in with Google through the server-side OpenID Connect (OIDC) flow, in which case the platform only ever receives the identity you choose to disclose.

Every session is tracked server-side with IP and user-agent (backend/users/users.py). Settings → Security shows every active session with device, IP and last activity, and lets you revoke any of them with one click — including the current device (utils/auth_utils.py).

02

Data isolation

Uploaded and generated files are stored on the server filesystem scoped to your account, and every served path is validated against your own storage directory with a canonical-path check (backend/core/paths.py) — another user's request cannot reach your files.

Job directories resolve ownership before any read or write (backend/core/jobs.py), and account and job metadata live in the application database with per-account filtering at the request boundary.

03

Your data is never used to train shared models

Every model the platform trains for you — predictor, synthesis generator, optimizer surrogate — is trained on your data alone, for your account alone. Nothing is merged into a global or shared model.

This is a policy statement backed by the architecture: model artifacts are per-job and per-account, and the governed model registry scopes every entry to its owner (backend/routes/model_registry_routes.py).

04

Abuse protection

Account creation and public forms are protected by Cloudflare Turnstile bot detection when the deployment configures it (backend/utils/auth_utils.py; without a secret key the check is skipped, and the platform logs that).

Per-tier rate limits on jobs per hour, concurrent jobs, upload size and storage keep the platform responsive for everyone (backend/core/constants.py USER_TIERS, enforced in backend/core/runtime.py). Repeated deliberate abuse can be throttled or suspended, as described in the Terms of use.

Accounts are created immediately; where card verification is enabled, work creation unlocks after a $0 verification within the grace period, and administrators can suspend, restrict or unapprove an account at any time.

05

API keys

Programmatic access uses per-user API keys issued from Settings → API Keys. Keys are stored as SHA-256 hashes — the raw key is shown once — and can be created, rotated and revoked at any time without touching your session (backend/core/api_auth.py).

Each request is rate-limited against your tier the same way the web app is.

06

Transport & security headers

Every response carries baseline security headers — X-Frame-Options, X-Content-Type-Options, Referrer-Policy and a Permissions-Policy — with HSTS added in production (backend/app.py). The deployment edge config mirrors the same values so they cannot disagree between proxy and application.

07

Audit & transparency

The audit trail is a hash-chained, tamper-evident log: each entry includes the previous entry's hash, and writes are serialized per process so the chain cannot fork. The digest is keyed with HMAC-SHA256 when the deployment sets an audit-chain key (plain SHA-256 otherwise), so tampering is detectable by re-hashing the chain (backend/core/audit.py).

Login sessions record IP and user-agent so you can audit your own account history, and run configuration and results are stored per job, making every model run reproducible from the platform's own records (backend/core/provenance.py).

What happens to your data — retention, deletion, third-party processors — is spelled out in the Privacy policy, not buried in fine print.

Honest status

What we do not claim: certifications

Compliance statements are only useful if they distinguish a certificate from its groundwork.

No SOC 2 or ISO certification is claimed.The repository contains SOC 2 evidence scaffolding — append-only audit export, optional authenticated access logging, security-header configuration, dependency-scan helpers and read-only readiness flags for MFA and IP allowlisting (backend/core/soc2.py). Those helpers are controls-in-place, not a certified audit. MFA and IP allowlisting are reported as configured/not-configured per deployment and are not enforced by default.
Record-integrity certificates are draft scope.The ELN generates hash-chained, HMAC-signed record-integrity certificates for experiment sign-off. Their own text states they are not a certificate of ISO-17025, GLP, 21 CFR Part 11 or any other regulatory standard (backend/services/eln_compliance_service.py). Treat them as tamper-evidence, not accreditation.
All output is screening-grade until validated.Security controls protect the data; they do not upgrade a prediction into a measurement. Every scientific result carries an evidence class and an engine card so the provenance is visible.
Habits

What you can do to stay secure

Small habits that matter more than any feature.

  • Use a strong, unique password — the platform enforces a minimum length at registration and change.
  • Sign in with Google if your institution uses it — you get their account security for free.
  • Review the active sessions list occasionally and revoke anything you do not recognize.
  • Use dedicated API keys per integration, and rotate them when a script or notebook changes hands.
  • Never paste proprietary data into the AI assistant that you would not want to leave the platform — assistant messages are processed by a third-party LLM API (see Privacy).
  • If you leave an institution, request account deletion from Settings → Data & account so your data leaves with you (backend/core/user_purge.py; the operations team actions the permanent purge — see Privacy).

Questions about how your data is handled?

The privacy policy has the full details, and the team answers directly — no ticket roulette.