Research and educational use only. Provotics is not a medical device and does not provide clinical diagnoses.
PlatformResearchValidationSafetyTrustRequest access
Trust center

Current state, controls, and known limits.

One place for service reachability, model identity, data handling, security practices, scientific limitations, and incident reporting.

Live check

System reachability

These checks confirm that the public gateway responds. They are not a synthetic model prediction or a performance guarantee.

Public websiteReachable

This page and its static resources loaded successfully.

Account gatewayChecking…

Testing the same-origin account route without changing account state.

Model gatewayChecking…

Reading the public version and configuration route; no profile is submitted.

Model identity

What is being served

Display model
Provenance-2
Scope
RNA-seq site-of-origin research across 25 anatomical sites
Coverage
In-distribution calibration and conformal guarantees only
Gateway version
Checking live route…
Agreement
Checking live route…
Read the full model card →
Data handling

What leaves your browser

  • Readiness checker: nothing. Analysis is browser-local and the input is not retained.
  • Model runner: the parsed gene-expression profile is submitted only after an entitled user confirms the required data boundary and chooses Run analysis.
  • Project history: report outputs and an input fingerprint for matching runs are stored on the current device; raw profiles are not saved to history.
  • Application storage: raw expression values are not intentionally written to account storage or query audits. Query fingerprints and audit records may be kept for up to 12 months; account-level security flags follow account retention.
  • Identifiable data: names, patient or sample identifiers, medical record numbers, dates of birth, contact details, clinical notes, and PHI are prohibited. The limited field screen does not certify legal de-identification.
Read the privacy policy →
Known limitations

Limits are part of the product.

These are not footnotes to be discovered after a result.

01

Mesothelioma is out of validated scope

Real mesothelioma is not reliably recognized. Pleura and Mediastinum outputs must not be relied upon.

02

Platform shift changes performance

Calibration and 90% conformal coverage do not transfer to arbitrary assays or processing pipelines.

03

Rare sites remain data-limited

Some rare classes are underpowered and can be overconfident despite calibration of the overall model.

04

Retrospective research only

No prospective clinical validation, independent clinical-site study, or completed demographic subgroup-equity audit.

Security controls

Layered access

  • Current-version signed research agreement before model access.
  • Account, organization, IP, daily, and weekly usage controls.
  • Revocable API keys and account-bound output watermarking.
  • Bounded requests, identifier-style field rejection, origin isolation, and model gateway resilience controls.
  • No-store API responses, security headers, and a public vulnerability-disclosure contact.
  • Current gap: provider-managed storage encryption is active, but the optional application-layer field-encryption key and scheduled secondary backup are not active.
Security contact and policy →
Report a problem

Security or service incident

If you find a vulnerability, a service interruption, or a result that appears scientifically unsafe, send the relevant time, page, and non-sensitive reproduction details. Do not email patient data.

Email the trust contact

For ordinary account or billing help, use the support center.

Compliance and assurance

Current status, without badges we have not earned.

Security controls, legal obligations, independent assurance, and certification are different things. This register states the current posture and the remaining gate.

GDPR and CCPA

Program building

Data minimization, a published notice, access controls, limited retention rules, and a privacy-rights intake path are implemented. Applicability assessments, legal review, processor contracts, transfer mechanisms, automated retention evidence, and the complete operating record remain in progress.

Exercise a privacy right

HIPAA

No PHI accepted

Provotics is not currently a covered entity or business associate, has no BAA in force, and prohibits PHI. It is not available for a PHI-handling workflow. A signed BAA and a completed HIPAA business-associate program are required before that changes.

Read the health-data boundary

ISO/IEC 27001

Not certified

An ISMS scope, risk process, Statement of Applicability, internal audit, management review, and accredited certification audit are required. Provotics does not currently hold an ISO/IEC 27001 certificate.

SOC 2

No report

Provotics has not completed a SOC 2 examination and does not have a SOC 2 Type I or Type II report. A licensed independent CPA firm must perform the examination.

SOC 3

No report

Provotics has not completed a SOC 3 examination and has no general-use SOC 3 report. This cannot be self-attested.

Status reviewed 20 July 2026. Contact the trust owner for a security or procurement review.

Procurement packet

Buyer-facing service facts

The procurement page consolidates service scope, data flow, providers, retention, continuity, support, and the current assurance register. Contract-specific DPA, SLA, residency, and security-questionnaire answers require written review.

Open security and procurement →
Accessibility

Self-reviewed, not certified

Keyboard access, motion controls, responsive layout, and dark/beige themes are implemented. No independent WCAG audit, VPAT, or accessibility conformance report has been issued.

Read the accessibility statement →
Service history

What the status check does not prove

The live cards above show current gateway reachability only. Provotics does not yet publish historical uptime, contractual availability, incident history, recovery-time performance, or independent disaster-recovery assurance. The scheduled secondary application backup is not active, so no restore performance is represented. Those artifacts must exist before an enterprise SLA or tested backup control is described as operational.