Your experiments are yours alone
Experimental data is proprietary before it is scientific. The platform is built so that your datasets, models and results are isolated to your account, never pooled, and never used to train anything shared.
How the platform protects you
What the platform actually does today — each pillar names the backend mechanism that backs it.
Authentication
Passwords are stored as salted Argon2id hashes — the server never keeps plaintext. Legacy accounts hashed with an older scheme keep verifying, and new hashes use Argon2id library defaults (backend/models/tables/users.py). You can also sign in with Google through the server-side OpenID Connect (OIDC) flow, in which case the platform only ever receives the identity you choose to disclose.
Every session is tracked server-side with IP and user-agent (backend/users/users.py). Settings → Security shows every active session with device, IP and last activity, and lets you revoke any of them with one click — including the current device (utils/auth_utils.py).
Data isolation
Uploaded and generated files are stored on the server filesystem scoped to your account, and every served path is validated against your own storage directory with a canonical-path check (backend/core/paths.py) — another user's request cannot reach your files.
Job directories resolve ownership before any read or write (backend/core/jobs.py), and account and job metadata live in the application database with per-account filtering at the request boundary.
Your data is never used to train shared models
Every model the platform trains for you — predictor, synthesis generator, optimizer surrogate — is trained on your data alone, for your account alone. Nothing is merged into a global or shared model.
This is a policy statement backed by the architecture: model artifacts are per-job and per-account, and the governed model registry scopes every entry to its owner (backend/routes/model_registry_routes.py).
Abuse protection
Account creation and public forms are protected by Cloudflare Turnstile bot detection when the deployment configures it (backend/utils/auth_utils.py; without a secret key the check is skipped, and the platform logs that).
Per-tier rate limits on jobs per hour, concurrent jobs, upload size and storage keep the platform responsive for everyone (backend/core/constants.py USER_TIERS, enforced in backend/core/runtime.py). Repeated deliberate abuse can be throttled or suspended, as described in the Terms of use.
Accounts are created immediately; where card verification is enabled, work creation unlocks after a $0 verification within the grace period, and administrators can suspend, restrict or unapprove an account at any time.
API keys
Programmatic access uses per-user API keys issued from Settings → API Keys. Keys are stored as SHA-256 hashes — the raw key is shown once — and can be created, rotated and revoked at any time without touching your session (backend/core/api_auth.py).
Each request is rate-limited against your tier the same way the web app is.
Transport & security headers
Every response carries baseline security headers — X-Frame-Options, X-Content-Type-Options, Referrer-Policy and a Permissions-Policy — with HSTS added in production (backend/app.py). The deployment edge config mirrors the same values so they cannot disagree between proxy and application.
Audit & transparency
The audit trail is a hash-chained, tamper-evident log: each entry includes the previous entry's hash, and writes are serialized per process so the chain cannot fork. The digest is keyed with HMAC-SHA256 when the deployment sets an audit-chain key (plain SHA-256 otherwise), so tampering is detectable by re-hashing the chain (backend/core/audit.py).
Login sessions record IP and user-agent so you can audit your own account history, and run configuration and results are stored per job, making every model run reproducible from the platform's own records (backend/core/provenance.py).
What happens to your data — retention, deletion, third-party processors — is spelled out in the Privacy policy, not buried in fine print.
What we do not claim: certifications
Compliance statements are only useful if they distinguish a certificate from its groundwork.
What you can do to stay secure
Small habits that matter more than any feature.
- Use a strong, unique password — the platform enforces a minimum length at registration and change.
- Sign in with Google if your institution uses it — you get their account security for free.
- Review the active sessions list occasionally and revoke anything you do not recognize.
- Use dedicated API keys per integration, and rotate them when a script or notebook changes hands.
- Never paste proprietary data into the AI assistant that you would not want to leave the platform — assistant messages are processed by a third-party LLM API (see Privacy).
- If you leave an institution, request account deletion from Settings → Data & account so your data leaves with you (backend/core/user_purge.py; the operations team actions the permanent purge — see Privacy).
Questions about how your data is handled?
The privacy policy has the full details, and the team answers directly — no ticket roulette.