CandleAI Trust
Security · retention · research-use only

Trust Center

Short, honest posture for labs evaluating CandleAI. Computational research tool only — not a medical device, not SOC 2 marketing fluff until certified.

Data handling

  • Research sequences only — no PHI without a signed BAA
  • No training on customer sequences by default
  • Free-run path uses public MSA API unless local MSA is provisioned
  • 90-day default retention; deletion on written request

Access control

  • Staff dashboard: email allowlist + shared passcode
  • Session cookies HMAC-signed when staff auth is configured
  • Production secrets stay in Azure secrets — not git
  • Pilot email send remains human-approved only

Transport & storage

  • HTTPS on public site (ACA managed cert + custom domain)
  • Compute on dedicated DGX Spark for active folds
  • Hub jobs and pilot intake stored as operational logs for queue/SLA
  • QC gates before paid invoice (QC-F)

What we do not claim

  • Not HIPAA-certified by default (HIPAA-ready practices + BAA path)
  • Not SOC 2 Type II until listed here with audit date
  • Not a diagnostic or clinical decision system
  • Not a 250-model marketplace

Questions for enterprise: use paid pilot and ask for security follow-up. Legal terms: research-use disclaimer.

Computational research tool only. Not a medical device.