Your data security
Your research is never used to train AI, every analysis runs in its own isolated container, and everything in transit and at rest is encrypted. Here is exactly how that works.
Security at a glance
Never used to train AI
Your research data and conversations are never used to train any model. Not ours, not anyone else’s.
Isolated compute per analysis
Every run executes in its own single-use container that is destroyed when the job ends. Nothing is shared between customers.
Viewers run in your browser
Signed out, the bioSTUDIO file viewers parse your file locally. It never reaches our servers. Check the network tab.
Encrypted in transit and at rest
TLS 1.3 on every public endpoint, AES-256 for stored files, and storage configured to block public access.
Your data and AI
Your prompts never reach a model vendor
Your research is never used to train any model, by us or by anyone else. Inference runs on managed infrastructure in the United States, under terms that prohibit retaining your inputs or training on them, so your prompts are never sent to a model vendor's own API.
One thing worth knowing: if you reach us through an external assistant such as ChatGPT or Claude using our MCP server, that assistant's own data terms apply to whatever passes through it.
How your files are handled
Analyses run in isolation
Every tool run and pipeline step executes in its own isolated, single-use container, created for that one job and destroyed when it ends. Containers cannot see other customers' files, nothing persists between runs, and the image is chosen server-side: your input selects parameters, never what runs.
Viewing happens on your machine
The standalone bioSTUDIO viewers for FASTA, BAM, VCF, PDB and CSV parse your file in your browser, so viewing a file never sends it to us. Running an analysis on it does, so the job has something to work on.
Access control
Who can reach what
- Role-based access control is enforced server-side at the data layer, not in the interface. Organization and workspace boundaries are checked on every request, including requests that name a file directly.
- API keys are stored only as hashes, shown to you once, scoped and revocable. The CLI, editor extensions and MCP server use OAuth 2.0 with PKCE, with refresh tokens hashed and rotated.
- Databases are not reachable from the public internet, deployments authenticate with short-lived federated credentials rather than long-lived cloud keys, and a failing tenant-isolation test blocks a release instead of reaching production.
- Databases are backed up continuously, with point-in-time recovery across a seven-day window.
Your data
Exporting or deleting your data
- Export. Request your data in machine-readable form: JSON, CSV, or your original files.
- Delete. Deleting a conversation removes it from our live database outright, not archived or hidden. Closing your account erases your stored files and immediately revokes your API keys and every connected tool.
- Logging. Neither your query text nor your file contents are written to our application logs, which are kept for 30 days.
Our Privacy Policy lists every subprocessor that may handle your data and what each receives. A Data Processing Agreement is available on request.
Talk to us
Security questionnaires
If your institution needs a security review completed before you can use Smarts.bio, we will answer it honestly, including the parts where the answer is no.
sales@smarts.bioReport a vulnerability
Tell us what you found, how to reproduce it, and how to reach you. We aim to acknowledge within two business days, and we will not pursue researchers acting in good faith who give us time to fix things and do not touch other people's data.
security@smarts.bioLast reviewed . We update this page when what it describes changes.