For the complete documentation index, see llms.txt. This page is also available as Markdown.

Security and compliance

Certifications and frameworks

ItemStatusHow to obtain evidence
SOC 2 Type IImaintained, audited annuallyreport available under NDA via sales@scispace.com
GDPRDPA available on requestsales@scispace.com
ISO 27001in progress
HIPAAnot supporteddo not send PHI
PCI DSSnot applicable — we never receive card data through the API

Transport and storage

  • TLS 1.2 or later required for all API traffic; HTTP requests are rejected, not redirected

  • AES-256 at rest for documents, parsed text, and generated answers

  • Encryption keys managed in AWS KMS with annual rotation

Access control

Access is governed by API key scopes and organization roles — see teams-and-scopes. Internal access to customer content is role-restricted, logged, and reviewed quarterly.

Isolation

Documents are scoped to the organization that uploaded them. There is no cross-organization retrieval path: a Chat can only reference documents its own organization owns.

Reporting a vulnerability

Email security@scispace.com. We acknowledge within 24 hours and work to a 90-day coordinated disclosure. Please do not test against other organizations' data or run load-generating scans against production — use a test key and tell us first.

Changes to this policy

Certification changes are reflected here within 30 days and noted in the changelog.

data-privacy · teams-and-scopes · reliability · authentication

Last updated