Skip to main content

How we protect your data

Your research is valuable. Here’s what we do to keep it safe.

Security at every layer

Encryption in Transit and at Rest

Every connection to Conspecta is encrypted with TLS. Everything we store is encrypted with AES-256, including your files, images, and records.

Tenant Isolation

Each project’s data is logically separated at the database level. Access policies are enforced on every query.

Role-Based Access

Assign roles to team members and manage permissions at the project level. Members only see the projects they belong to.

Automated Backups

Your data is backed up automatically with point-in-time recovery. If something goes wrong, we can restore your work.

US Data Residency

All data is stored and processed in the United States on Amazon Web Services infrastructure.

Continuous Threat Detection

Our infrastructure is monitored around the clock for malicious activity, including unusual API calls, network traffic, and storage access. High-severity findings raise an alert automatically.

Your data stays yours

  • No selling your data

    We will never sell or monetize your research data.

  • No ad sharing or profiling

    We never share your data with advertisers or use it to profile you. The only third parties involved are the vetted providers we rely on to run the service, such as cloud hosting, bound by contract to use it solely on our behalf.

  • No AI training on your data

    We don’t use your images or research data to train our models.

  • No third-party trackers

    Our website sets no advertising or analytics tracking cookies. We measure traffic from our own server logs instead.

  • Full export

    You can export your data anytime in standard, open formats.

  • Minimal collection

    We collect only what’s necessary to provide the service.

Where we stand today

  • SOC 2

    Not certified yet. Our controls are built to SOC 2 standards and we’re ready to begin the audit. If your team needs certification, tell us and we’ll prioritize it.

  • ISO 27001

    Not certified today. SOC 2 is the track we’re on, and the two share most of their controls. If ISO 27001 is what your procurement requires instead, tell us and we’ll scope it alongside.

  • HIPAA / PHI

    Our standard terms exclude PHI, and we don’t sign BAAs by default. If HIPAA is a requirement for your work, it’s an enterprise conversation. Talk to us before you upload anything covered.

  • 21 CFR Part 11 / GxP

    Regulated workflows need validation and dedicated support beyond our standard service. If that’s on your roadmap, talk to us about an enterprise engagement.

  • GDPR

    There’s no certification to hold for GDPR, but we follow it: we honor data-subject rights (access, export, correction, deletion), use Standard Contractual Clauses for EU data transfers, and don’t sell or profile your data.

  • EU / non-US data residency

    Your data is stored and processed in the US today, and we don’t offer regional residency as a standard option. If your institution requires it, talk to us about an enterprise engagement.

  • On-premises / offline use

    Conspecta is cloud-only and runs in the browser. There’s no self-hosted or on-premises install and no offline desktop mode, and that won’t change: we can’t secure, patch, or stand behind a deployment we don’t run. If your policy requires software on your own servers, we’re genuinely not your fit.

What we can send your security team

  • Security questionnaire response

    A written answer to how we handle encryption, access control, tenant isolation, and incident response. Enough for most vendor-review checklists.

  • Subprocessor list

    Every third party that touches your data, what they do, and what reaches them.

  • Breach-notification terms

    What we commit to telling you, and how fast, if your data is ever affected.

  • Evidence that our controls run

    Dated proof from our live infrastructure: threat detection, configuration monitoring, tamper-evident audit logging, and backup verification.

If your IT team needs us to fill in their own form or join a review call, that’s part of an Enterprise plan.

Need SOC 2, or a security review?

Tell us what your team requires. If certification is what’s standing between us, say so. That’s how it gets prioritized.