Current-state procurement facts. No certification or assurance badge is implied.
ProductsTrustPrivacyTermsStart review
Security and procurement

The facts a buyer should see before a call.

This page consolidates service scope, data handling, providers, retention, support, and assurance status. Contract-specific answers still require a written review.

Service boundary

Provotics is an invite-only research and educational service, not a medical device. It accepts de-identified gene-expression values. PHI, direct identifiers, clinical diagnosis, and treatment-selection workflows are prohibited.

Data flow

  • Public readiness checks run in the browser.
  • A model profile leaves the browser only after an entitled user chooses Run.
  • Raw profiles are not stored in browser project history.
  • Query audit records store fingerprints and watermarks, not expression values.

Service providers

  • Cloudflare: hosting, network security, serverless processing, account storage.
  • Resend: transactional email.
  • Google/GitHub: only if that provider is enabled and selected.
  • Stripe: only if billing is enabled and a transaction is initiated.

Retention

  • Query and administrative audit records: no more than 12 months.
  • General contact messages: no more than 12 months.
  • Privacy-request records: 24 months where required.
  • Local project history: until the user clears it.

Support and incidents

Named enterprise support and an SLA are contract-specific and not active by default. Security issues are accepted through the published security contact. General support normally responds within two business days.

Continuity

Model-gateway resilience and documented recovery procedures exist. A buyer-facing historical uptime report, contractual recovery objectives, and independent disaster-recovery assurance are not yet available.

Assurance register

Current status

AreaStatusWhat remains
GDPR / CCPAProgram buildingApplicability records, processor contracts, transfer mechanisms, and operating evidence.
HIPAANo PHI accepted; no BAABusiness-associate program and signed BAA before any PHI workflow.
ISO/IEC 27001Not certifiedComplete ISMS and accredited certification audit.
SOC 2 / SOC 3No reportIndependent CPA examination and issued report.
AccessibilitySelf-reviewed, not independently certifiedFormal WCAG audit and remediation record.
Available review material

Start with the public evidence

Contract

The public Access Agreement remains marked for attorney review. Do not treat it as a negotiated enterprise agreement.

Start a procurement review

Include expected seats, annual model volume, jurisdiction, deployment requirements, security questionnaire, and desired timeline.