Skip to content

Security & Data Handling

How AnnealIQ protects your research data. We believe in transparency about what we do and don't do.

Research Use Only. AnnealIQ is not intended for clinical or diagnostic purposes.

Your Ct values never leave your browser

All qPCR analysis computation — DDCt, Pfaffl, statistics, QC, reference gene stability — runs entirely in your browser using client-side JavaScript. Only experiment descriptions and result summaries are sent to the AI service for interpretation. Your raw instrument data stays on your machine.

Data flow

Your BrowserqPCR analysis runs hereTLS 1.3Hosting + API(edge functions)sessionsAI requestsDatabase(encrypted at rest)AI Service(interpretation only)

All connections use TLS 1.3 encryption in transit.

What we have

Data encryption

  • TLS 1.3 for all data in transit
  • AES-256 encryption at rest (database)
  • Admin API keys encrypted with AES-256-GCM

Access controls

  • Row-level security (RLS) on all user data tables
  • Invite-code gating for beta access
  • Admin role verification for privileged operations

Input validation & rate limiting

  • Zod schema validation on all API route inputs
  • Rate limiting: 30/hr chat, 10/hr waitlist, 5/hr request-access
  • Security headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options

AI data handling

  • Only experiment descriptions and result summaries sent to AI
  • No raw Ct values or instrument data sent to external services
  • AI responses are not used for model training (per Anthropic API terms)
  • Admin-configurable AI model and API key

What we don't have yet

We're a beta product. Here's what's not in place yet:

  • No SOC 2 or ISO 27001 certification (planned post-GA)
  • No GxP/21 CFR Part 11 compliance (not currently planned)
  • No two-factor authentication (planned)
  • No single sign-on / SSO (planned)
  • No formal audit trail for admin actions (planned)
  • No EU data residency guarantee (infrastructure is US-based)
  • No on-premises deployment option

Data deletion

You can delete individual analysis sessions from the session sidebar. Deleted sessions are permanently removed from the database within 24 hours.

For full account deletion, email hello@annealiq.ai. We'll remove all your data within 30 days and confirm by email.

Security questions?

If you have questions about our security practices or need information for your institution's review process, contact us.

hello@annealiq.ai