Your data

What we hold, where, and for how long

What the platform stores, where it is processed, what it is never used for, and how long it is kept — in plain terms, with the legal detail linked.

The engine is designed to run on public data and protocol-level inputs. Protected Health Information is not required to produce a verdict, which removes an entire category of risk from the conversation before it starts.

This page is a plain-language summary. The privacy notice, terms and data processing addendum are the binding versions.

What we hold#

  • The study definitions you create — indication, intervention, phase, endpoints, eligibility criteria and any other inputs you state.
  • Documents you upload, and the indexed representation used to retrieve passages from them within your workspace.
  • The assessments produced, their citations, and the public records they were pinned to.
  • Deliverables drafted in role workspaces, their revision history, and the audit chain including signatures.
  • Account and workspace membership data needed to run the service.

Protected Health Information is not required. Where a customer chooses to transmit regulated data anyway, it is encrypted in transit and at rest — but the design intent is that you never need to.

What it is never used for#

Never used to train a model
Protocols and documents you submit are not used to train or fine-tune any model, ours or anyone else’s.
Never sent to a general-purpose model API
Document reading and drafting run on open-weight models hosted for us in the EU. Your protocol is not sent to a consumer or general-purpose model API.
Never mixed with another tenant
Runs, citations and the audit chain are isolated per tenant.

Where it is processed#

The platform is hosted in the European Union and personal data is processed there by default. Where personal data is transferred outside the EEA or UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum.

A US or dedicated deployment region can be arranged for enterprise customers on request. Data in transit is encrypted with TLS; data at rest is encrypted with AES-256.

How long it is kept#

Data is kept for as long as your account is active, and thereafter as required to meet legal, audit and regulatory obligations — including Part 11 audit retention — after which it is deleted or anonymised.

Audit retention is the reason a blanket "delete everything immediately" is not on offer: a tamper-evident record you can erase on request is not a tamper-evident record. Deletion and data-subject requests are handled under the privacy notice, and enterprise retention terms can be agreed in the DPA.

Compliance status, stated honestly#

Compliance posture. Status wording is deliberately not upgraded.
FrameworkStatusWhat that means
21 CFR Part 11ImplementedHash-chained, append-only audit trail with electronic signatures, in the product today.
HIPAADesign postureNo PHI is required to run the engine. A stated posture, not a third-party attestation.
GDPRDesign postureData-minimisation by design, EU processing by default, terms addressed contractually. Not a supervisory-authority certification.
SOC 2 Type IIIn progressExamination underway. The independent report has not yet been issued, and we do not claim SOC 2 compliance today.

See a verdict you can actually check.

Send us a protocol — or just a molecule and an indication. We'll return a fully cited feasibility assessment you can trace, line by line, back to public data — yours to defend in a bid, take to your board or investment committee, or hand to a regulator.