Current-state procurement facts. No certification or assurance badge is implied.
ProductsTrustPrivacyTermsStart review
Security and procurement

The facts a buyer should see before a call.

This page consolidates service scope, data handling, providers, retention, support, and assurance status. Contract-specific answers still require a written review.

Service boundary

Provotics is an invite-only research and educational service, not a medical device. It accepts authorized gene-expression values only. PHI, names, patient or sample identifiers, medical record numbers, clinical notes, clinical diagnosis, and treatment-selection workflows are prohibited. The limited identifier-field screen does not certify de-identification under HIPAA or another law.

Data flow

  • Public readiness checks run in the browser.
  • A model profile leaves the browser only after an entitled user confirms the data boundary and chooses Run.
  • Raw profiles are not intentionally written to account storage or browser project history.
  • Query audit records store fingerprints, the attestation version, security events, and watermarks, not expression values.

Service providers

  • Cloudflare: hosting, network security, serverless processing, account storage.
  • Resend: transactional email.
  • Google/GitHub: only if that provider is enabled and selected.
  • Stripe: only if billing is enabled and a transaction is initiated.

Retention

  • Application and account records: while access is managed; no automatic expiry today.
  • Agreement receipts: contract/legal-claims evidence; final expiry schedule pending approval.
  • Query and administrative audit records: no more than 12 months.
  • General contact messages: no more than 12 months.
  • Privacy-request records: 24 months where required.
  • Update subscriptions: until opt-out or verified deletion.
  • Local project history: until the user clears it.

Support and incidents

Named enterprise support and an SLA are contract-specific and not active by default. Security issues are accepted through the published security contact. General support normally responds within two business days.

Continuity and encryption

Model-gateway resilience and documented recovery procedures exist. Provider-managed storage encryption is active. The separate application-layer field-encryption key, scheduled secondary application backup, restore evidence, buyer-facing historical uptime report, contractual recovery objectives, and independent disaster-recovery assurance are not active or available today.

Assurance register

Current status

AreaStatusWhat remains
GDPR / CCPAProgram buildingApplicability records, processor contracts, transfer mechanisms, and operating evidence.
HIPAANo PHI accepted; no BAABusiness-associate program and signed BAA before any PHI workflow.
ISO/IEC 27001Not certifiedComplete ISMS and accredited certification audit.
SOC 2 / SOC 3No reportIndependent CPA examination and issued report.
AccessibilitySelf-reviewed, not independently certifiedFormal WCAG audit and remediation record.
Available review material

Start with the public evidence

Contract

The public Access Agreement remains marked for attorney review. Do not treat it as a negotiated enterprise agreement.

Start a procurement review

Include expected seats, annual model volume, jurisdiction, deployment requirements, security questionnaire, and desired timeline.