Authenticated access
Personal resources are scoped to an authenticated account. Shared project resources use team and workspace authorization rather than becoming public links.
Pipette combines controlled access, managed analysis, and durable project records. We explain how research data is handled and work directly with labs and organizations that have security, privacy, or contractual requirements.
Pipette limits access through account and team permissions and uses service providers to deliver the analysis, storage, billing, and reliability functions users request.
For teams with formal requirements, we can work through security questionnaires, data-handling expectations, and a data processing agreement. SOC 2 Type II is on our roadmap; contact us for current status and documentation.
The controls below are described at the level supported by Pipette's current product and operating documentation.
Personal resources are scoped to an authenticated account. Shared project resources use team and workspace authorization rather than becoming public links.
Analysis workloads run in managed compute environments. Inputs are staged for execution and outputs are returned to durable project storage.
Projects preserve the relationship between inputs, methods, parameters, code, software versions, intermediate artifacts, figures, reports, and final outputs.
Access follows account and team permissions. When support, security, or service operation requires additional access, it is limited to authorized personnel and the information needed for that task.
Research content includes queries, files, conversation history, generated code, intermediate files, results, and reports.
Uploaded files and generated outputs are stored in the Data Bucket so analyses can be resumed, reviewed, and downloaded. Active team-workspace allocations are working capacity, not a promise of permanent archival storage.
Required inputs are staged into a managed analysis workspace. The requested tools produce code, logs, intermediate artifacts, figures, tables, and reports.
Query text and conversation history are sent to an LLM provider to perform the requested analysis. Portions of files that the agent inspects—such as column names, sampled rows, or computed observations—may be included in inference prompts.
Project files remain available for continuity until they are deleted or the applicable service lifecycle ends. Users can delete individual files in the Data Bucket and can request account deletion by email.
Account deletion removes or anonymizes account content. Limited billing, tax, security, or legal records may be retained where required.
Pipette uses submitted content to authenticate users, run analyses, preserve project continuity, return results, provide support, investigate incidents, and operate the platform.
Read the current Privacy PolicyPipette shares the minimum information needed with providers used to deliver the service. Teams can request current provider information as part of a security or DPA review.
| Provider category | Purpose | Information involved |
|---|---|---|
| Cloud infrastructure | Application hosting, databases, object storage, and analysis compute | Account, project, uploaded, generated, and operational data |
| LLM inference | Interpret requests, plan work, and reason over analysis observations | Queries, conversation history, and limited inspected-file content |
| Payment processing | Purchases and billing records | Transaction metadata; card numbers do not pass through Pipette servers |
| Analytics and error reporting | Service reliability, abuse prevention, and product diagnostics | Technical, usage, and pseudonymous diagnostic information |
Need provider details, processing locations, retention information, or contractual terms? Include them in your security review or DPA request.
We can work with labs, cores, biotech teams, and research organizations on security questionnaires, data-handling requirements, provider information, and data processing agreements.
Share your questionnaire, data type, retention or residency requirements, and DPA needs. We will respond with the relevant information and discuss the terms appropriate to your proposed use.
No. Pipette does not use customer queries, uploaded files, or results to train its own or third-party AI models. Relevant context may be processed by AI service providers solely to perform the analysis a user requests.
If your project has HIPAA, protected health information, or other regulated health-data requirements, contact us before uploading anything. We will review the proposed use, required safeguards, and appropriate agreement with your team.
Access follows account and team permissions. When support, security, or service operation requires additional access, it is limited to authorized personnel and the information needed for that task.
Delete individual files from the in-app Data Bucket. To request account deletion, email info@pipette.bio. Limited billing, legal, tax, or security records may be retained where required.
SOC 2 Type II is on our roadmap. Contact us for the current status, security questionnaires, provider information, data-handling discussions, and DPA requirements.
Yes. Contact us to discuss your organization's DPA requirements and the terms appropriate to the proposed use.
Email a concise description, affected URL or component, reproduction steps, and expected impact. Do not access another user's data, disrupt production, or disclose a potential issue publicly before Pipette has had a reasonable opportunity to investigate.