How we handle your prompts, outputs and findings
Evaluation work means holding material you'd rather competitors never see: unreleased model access, system prompts, failure findings. This page states what we do with it — claiming only controls that exist. As controls mature (audits, certifications), they'll be added here with dates, not badges.
Confidential material we may hold
Under an engagement: model access credentials, system prompts, model outputs, task sets, findings and remediation notes. Everything in this category is covered by the engagement agreement and NDA before any of it is shared.
No training use
Your prompts, outputs and findings are never used to train models, build public benchmarks, or improve work for another client. Cases we author for our own benchmark are developed separately from client-confidential material.
PHI and PII
Our evaluation tasks are authored synthetic cases; we do not want and will not accept patient-identifiable data. If your product's outputs may contain PHI, we agree a de-identification and handling protocol before work starts — or we decline that material.
Human access
Access is limited to the founders and the specific physicians assigned to your engagement, each under written confidentiality obligations, each seeing only what their task requires. A per-engagement access list is available on request.
Storage and encryption
Engagement material lives in Supabase and Vercel infrastructure (TLS in transit, encryption at rest), with access logging enabled. Credentials are stored in a managed secrets vault, never in email or documents.
Retention and deletion
Client materials are returned or deleted within 30 days of an engagement ending on request, deletion confirmed in writing. We retain our own working notes only as the engagement agreement allows.
Subprocessors
Vercel (hosting), Supabase (database), Google Workspace (email), Resend (notification email). The current list with regions is available on request; we notify active clients before adding one that would touch their material.
Agreements we sign
We sign NDAs and data-processing terms; BAAs where a US engagement genuinely involves PHI. We'd rather scope PHI out than sign paper that pretends it away.
Incidents
Suspected compromise of your material: notification within 72 hours of us becoming aware, with what we know, what we've contained, and what changes. No burying.