This page and its static resources loaded successfully.
Current state, controls, and known limits.
One place for service reachability, model identity, data handling, security practices, scientific limitations, and incident reporting.
System reachability
These checks confirm that the public gateway responds. They are not a synthetic model prediction or a performance guarantee.
Testing the same-origin account route without changing account state.
Reading the public version and configuration route; no profile is submitted.
What is being served
- Display model
- Provenance-2
- Scope
- RNA-seq site-of-origin research across 25 anatomical sites
- Coverage
- In-distribution calibration and conformal guarantees only
- Gateway version
- Checking live route…
- Agreement
- Checking live route…
What leaves your browser
- Readiness checker: nothing. Analysis is browser-local and the input is not retained.
- Model runner: the parsed gene-expression profile is submitted only after an entitled user confirms the required data boundary and chooses Run analysis.
- Project history: report outputs and an input fingerprint for matching runs are stored on the current device; raw profiles are not saved to history.
- Application storage: raw expression values are not intentionally written to account storage or query audits. Query fingerprints and audit records may be kept for up to 12 months; account-level security flags follow account retention.
- Identifiable data: names, patient or sample identifiers, medical record numbers, dates of birth, contact details, clinical notes, and PHI are prohibited. The limited field screen does not certify legal de-identification.
Limits are part of the product.
These are not footnotes to be discovered after a result.
Mesothelioma is out of validated scope
Real mesothelioma is not reliably recognized. Pleura and Mediastinum outputs must not be relied upon.
Platform shift changes performance
Calibration and 90% conformal coverage do not transfer to arbitrary assays or processing pipelines.
Rare sites remain data-limited
Some rare classes are underpowered and can be overconfident despite calibration of the overall model.
Retrospective research only
No prospective clinical validation, independent clinical-site study, or completed demographic subgroup-equity audit.
Layered access
- Current-version signed research agreement before model access.
- Account, organization, IP, daily, and weekly usage controls.
- Revocable API keys and account-bound output watermarking.
- Bounded requests, identifier-style field rejection, origin isolation, and model gateway resilience controls.
- No-store API responses, security headers, and a public vulnerability-disclosure contact.
- Current gap: provider-managed storage encryption is active, but the optional application-layer field-encryption key and scheduled secondary backup are not active.
Security or service incident
If you find a vulnerability, a service interruption, or a result that appears scientifically unsafe, send the relevant time, page, and non-sensitive reproduction details. Do not email patient data.
Email the trust contactFor ordinary account or billing help, use the support center.
Current status, without badges we have not earned.
Security controls, legal obligations, independent assurance, and certification are different things. This register states the current posture and the remaining gate.
GDPR and CCPA
Program buildingData minimization, a published notice, access controls, limited retention rules, and a privacy-rights intake path are implemented. Applicability assessments, legal review, processor contracts, transfer mechanisms, automated retention evidence, and the complete operating record remain in progress.
Exercise a privacy rightHIPAA
No PHI acceptedProvotics is not currently a covered entity or business associate, has no BAA in force, and prohibits PHI. It is not available for a PHI-handling workflow. A signed BAA and a completed HIPAA business-associate program are required before that changes.
Read the health-data boundaryISO/IEC 27001
Not certifiedAn ISMS scope, risk process, Statement of Applicability, internal audit, management review, and accredited certification audit are required. Provotics does not currently hold an ISO/IEC 27001 certificate.
SOC 2
No reportProvotics has not completed a SOC 2 examination and does not have a SOC 2 Type I or Type II report. A licensed independent CPA firm must perform the examination.
SOC 3
No reportProvotics has not completed a SOC 3 examination and has no general-use SOC 3 report. This cannot be self-attested.
Status reviewed 20 July 2026. Contact the trust owner for a security or procurement review.
Buyer-facing service facts
The procurement page consolidates service scope, data flow, providers, retention, continuity, support, and the current assurance register. Contract-specific DPA, SLA, residency, and security-questionnaire answers require written review.
Open security and procurement →Self-reviewed, not certified
Keyboard access, motion controls, responsive layout, and dark/beige themes are implemented. No independent WCAG audit, VPAT, or accessibility conformance report has been issued.
Read the accessibility statement →