Security · retention · research-use only
Trust Center
Short, honest posture for labs evaluating CandleAI. Computational research tool only — not a medical device,
not SOC 2 marketing fluff until certified.
Data handling
- Research sequences only — no PHI without a signed BAA
- No training on customer sequences by default
- Free-run path uses public MSA API unless local MSA is provisioned
- 90-day default retention; deletion on written request
Access control
- Staff dashboard: email allowlist + shared passcode
- Session cookies HMAC-signed when staff auth is configured
- Production secrets stay in Azure secrets — not git
- Pilot email send remains human-approved only
Transport & storage
- HTTPS on public site (ACA managed cert + custom domain)
- Compute on dedicated DGX Spark for active folds
- Hub jobs and pilot intake stored as operational logs for queue/SLA
- QC gates before paid invoice (QC-F)
What we do not claim
- Not HIPAA-certified by default (HIPAA-ready practices + BAA path)
- Not SOC 2 Type II until listed here with audit date
- Not a diagnostic or clinical decision system
- Not a 250-model marketplace
Questions for enterprise: use paid pilot and ask for security follow-up.
Legal terms: research-use disclaimer.