Data ProtectionHeura Lab Platform

How We Protect Your Data

As more organizations trust Heura Lab with sensitive research and simulation work, we've heard a consistent question: how exactly do you protect our data?

This article is our answer — a transparent, living look at the security controls we have in place today, the capabilities we're actively building, and the standards we're working toward. We'll keep updating it as our products and approach evolve.

Security Today

The following capabilities are available now, in our standard managed cloud deployment:

  • Google Sign-In: Users authenticate through Google (OAuth). HeuraLab does not store separate account passwords.
  • Role-based access within organizations: Admins manage membership and invites, and simulations can be shared securely within an organization.
  • Encryption in transit: All traffic between your browser and HeuraLab is encrypted (HTTPS/TLS).
  • Encryption at rest: Customer data is stored using our cloud provider's managed, encrypted storage (Google Cloud / Cloud SQL).
  • Controlled, auditable deployments: Code changes reach production through an automated pipeline using short-lived cloud credentials rather than long-lived deploy passwords.
  • Cloud infrastructure: HeuraLab runs on Google Cloud Platform, a provider that maintains its own extensive independent security and compliance program.
  • Session security hardening: Login sessions use hardened cookie protections (HttpOnly, Secure, SameSite) to reduce the risk of session hijacking or unauthorized account access.

How We Handle Your Data

When you use HeuraLab's simulation and generation features, the relevant content and prompts are processed by leading commercial AI model providers that power the product. We work only with reputable providers under vendor agreements, and we do not sell personal information.

You control your own content: individual simulations can be deleted from your account today. Full-account data deletion and self-service data export tools are actively in development (see roadmap below).

HeuraLab is built for synthetic research, not as a system of record for protected health information (PHI), human resource (HR) data, or credit information. Please don't submit PHI or other regulated data into the standard product. We offer a separate healthcare track for qualifying enterprise engagements; contact us to discuss.

Roadmap

This is a living document updated as capabilities ship. It is not a compliance attestation. We're publishing it because we'd rather be transparent about what's still being built than imply capabilities we don't yet have. Items move from this table into “Security Today” above as they ship.

#Focus AreaStatusWhat This Means For You
1Automated abuse & traffic protection (rate limiting)PlannedAn added layer of automated defense against abusive, automated, or malicious traffic patterns.
2Secrets & credential management upgradePlannedMoving internal credentials to a centralized, rotating store to reduce the impact of any single system compromise.
3Enterprise SSO (SAML / OIDC)PlannedSign in with your existing identity provider instead of individual Google accounts.
4Customer-facing audit logsPlannedDetailed, exportable activity logs for your own compliance and security review.
5Self-service data export & deletionIn ProgressExport or fully delete your organization's data without waiting on manual support.
6Security monitoring & alertingIn ProgressExpanding internal visibility into account activity so we can detect and respond to unusual behavior faster.
7Incident response & notification processPlannedFormalizing how we respond to, and communicate about, security incidents.
8SCIM user provisioningPlannedAutomatically provision and deprovision user access as your team changes.
9Customer-managed encryption keys (CMK)PlannedBring and control your own encryption keys rather than relying solely on provider-managed keys.
10SOC 2 Type I / IIPlannedIndependent third-party audit of our security controls.
11Private / dedicated data environmentsPlannedIsolated, non-shared environments for organizations that require it.
12Contractual data residencyPlannedChoose or confirm the region where your data is processed and stored, as a contractual term.
13ISO 27001PlannedIndependent certification against the international information security standard.
14HIPAA / BAA supportAvailable on requestThis is not part of the standard product but we have a separate track for qualifying enterprise healthcare engagements.

Note: this list reflects current build priorities and is provided for informational purposes only. It is not a contractual commitment or a delivery guarantee. For contractual commitments regarding specific capabilities or timelines, please contact us directly.

Our Approach to Ongoing Security

  • Least privilege: People and systems get only the access they need for their role or task.
  • Defense in depth: We layer authentication, authorization, encryption, and controlled deployment practices rather than relying on any single control.
  • Secure by default: New features are built to require authentication and access control from day one, not bolted on afterward.
  • Transparency: We'd rather tell you what's not built yet than let a gap in our security program surprise you later.

Questions or Enterprise Due Diligence

Enterprise customers and prospects can request our detailed technical security documentation and completed security questionnaires under an NDA. For enterprise due diligence, data processing agreements (DPAs), or any security-related question not answered here, reach out to info@heuralab.ai.

Published: 7/26