Security and trust

Security for serious research workflows

Pipette combines controlled access, managed analysis, and durable project records. We explain how research data is handled and work directly with labs and organizations that have security, privacy, or contractual requirements.

Security approach

Practical controls and clear answers

Pipette limits access through account and team permissions and uses service providers to deliver the analysis, storage, billing, and reliability functions users request.

For teams with formal requirements, we can work through security questionnaires, data-handling expectations, and a data processing agreement. SOC 2 Type II is on our roadmap; contact us for current status and documentation.

Product controls

How access, execution, and project records are separated

The controls below are described at the level supported by Pipette's current product and operating documentation.

01

Authenticated access

Personal resources are scoped to an authenticated account. Shared project resources use team and workspace authorization rather than becoming public links.

02

Managed analysis environments

Analysis workloads run in managed compute environments. Inputs are staged for execution and outputs are returned to durable project storage.

03

Durable provenance

Projects preserve the relationship between inputs, methods, parameters, code, software versions, intermediate artifacts, figures, reports, and final outputs.

04

Limited operational access

Access follows account and team permissions. When support, security, or service operation requires additional access, it is limited to authorized personnel and the information needed for that task.

Data lifecycle

What happens from upload to deletion

Research content includes queries, files, conversation history, generated code, intermediate files, results, and reports.

  1. 01

    Upload and project storage

    Uploaded files and generated outputs are stored in the Data Bucket so analyses can be resumed, reviewed, and downloaded. Active team-workspace allocations are working capacity, not a promise of permanent archival storage.

  2. 02

    Analysis execution

    Required inputs are staged into a managed analysis workspace. The requested tools produce code, logs, intermediate artifacts, figures, tables, and reports.

  3. 03

    AI inference

    Query text and conversation history are sent to an LLM provider to perform the requested analysis. Portions of files that the agent inspects—such as column names, sampled rows, or computed observations—may be included in inference prompts.

  4. 04

    Retention and user deletion

    Project files remain available for continuity until they are deleted or the applicable service lifecycle ends. Users can delete individual files in the Data Bucket and can request account deletion by email.

  5. 05

    Account deletion and required records

    Account deletion removes or anonymizes account content. Limited billing, tax, security, or legal records may be retained where required.

Data use

Research content is used to provide the service

Pipette uses submitted content to authenticate users, run analyses, preserve project continuity, return results, provide support, investigate incidents, and operate the platform.

Read the current Privacy Policy
  • No model trainingQueries, uploaded files, and results are not used to train Pipette's or third-party AI models.
  • No sale of personal dataPipette does not sell personal data.
  • Inference processingRelevant prompt context and limited file observations may be processed by the LLM provider to answer the request.
  • User-owned workUsers retain ownership of their uploaded content and analysis outputs, subject to the Terms of Service.
Service providers

Systems that may process account or research information

Pipette shares the minimum information needed with providers used to deliver the service. Teams can request current provider information as part of a security or DPA review.

Provider categoryPurposeInformation involved
Cloud infrastructureApplication hosting, databases, object storage, and analysis computeAccount, project, uploaded, generated, and operational data
LLM inferenceInterpret requests, plan work, and reason over analysis observationsQueries, conversation history, and limited inspected-file content
Payment processingPurchases and billing recordsTransaction metadata; card numbers do not pass through Pipette servers
Analytics and error reportingService reliability, abuse prevention, and product diagnosticsTechnical, usage, and pseudonymous diagnostic information

Need provider details, processing locations, retention information, or contractual terms? Include them in your security review or DPA request.

For teams and organizations

Security documentation for your team

We can work with labs, cores, biotech teams, and research organizations on security questionnaires, data-handling requirements, provider information, and data processing agreements.

Tell us what your team needs

Share your questionnaire, data type, retention or residency requirements, and DPA needs. We will respond with the relevant information and discuss the terms appropriate to your proposed use.

Common questions

Security and data-handling FAQ

No. Pipette does not use customer queries, uploaded files, or results to train its own or third-party AI models. Relevant context may be processed by AI service providers solely to perform the analysis a user requests.

If your project has HIPAA, protected health information, or other regulated health-data requirements, contact us before uploading anything. We will review the proposed use, required safeguards, and appropriate agreement with your team.

Access follows account and team permissions. When support, security, or service operation requires additional access, it is limited to authorized personnel and the information needed for that task.

Delete individual files from the in-app Data Bucket. To request account deletion, email info@pipette.bio. Limited billing, legal, tax, or security records may be retained where required.

SOC 2 Type II is on our roadmap. Contact us for the current status, security questionnaires, provider information, data-handling discussions, and DPA requirements.

Yes. Contact us to discuss your organization's DPA requirements and the terms appropriate to the proposed use.

Responsible disclosure

Report a potential vulnerability privately

Email a concise description, affected URL or component, reproduction steps, and expected impact. Do not access another user's data, disrupt production, or disclose a potential issue publicly before Pipette has had a reasonable opportunity to investigate.

Report a Security Issue