Robust security
Data encrypted in transit and at rest to protect your research from unauthorized access.
Industry standards
GDPR-ready platform with Data Processing Agreements available for institutional users.
Transparency
Clear, accessible information about our data handling practices and policies.
In depth
Security practices
Explore our security measures across product, data, infrastructure, and corporate domains.
Server-side scientific jobs execute in isolated cloud containers. Results are returned to the submitting workspace and stored through the same authenticated file and job services described in our privacy policy.
Job inputs, results, and files remain available until you delete them or delete the workspace. Traffic is served over HTTPS, and managed database and object-storage providers supply encryption at rest. Our Data Processing Agreement documents backup retention and data locations.
Your sequences, structures, and research data are never used for AI training or shared with third parties. We collect only what is necessary to provide our services — account information, job inputs, and usage analytics.
Workspace data is available to you and authorized members of your workspace. Administrative access is limited to support, security, and service operation needs. Authentication is handled through Clerk.
The platform undergoes regular security reviews and dependency updates. Input validation is enforced at multiple layers. Route handlers use consistent error handling patterns with Zod schema validation.
Hosted on Vercel with Cloudflare R2 object storage and managed PostgreSQL. All cloud providers maintain industry-standard physical security, network security, and compliance certifications.
Traffic is served over HTTPS. Protected API endpoints use authentication checks, and sensitive mutation routes are subject to origin validation and rate limits where configured. Compute jobs run in isolated Modal containers.
Access to production systems is limited to essential personnel on a need-to-know basis. Subprocessors and their purposes are disclosed in the Data Processing Agreement, and security reports can be sent directly to our security contact.
Legal
Legal documents
Our policies and agreements that govern how we handle your data and your use of our platform.
Security researchers can also use our machine-readable security.txt. We do not claim a security certification unless it is listed here with a current verification link.