How We Protect Your Data
As more organizations trust Heura Lab with sensitive research and simulation work, we've heard a consistent question: how exactly do you protect our data?
This article is our answer — a transparent, living look at the security controls we have in place today, the capabilities we're actively building, and the standards we're working toward. We'll keep updating it as our products and approach evolve.
Security Today
The following capabilities are available now, in our standard managed cloud deployment:
- Google Sign-In: Users authenticate through Google (OAuth). HeuraLab does not store separate account passwords.
- Role-based access within organizations: Admins manage membership and invites, and simulations can be shared securely within an organization.
- Encryption in transit: All traffic between your browser and HeuraLab is encrypted (HTTPS/TLS).
- Encryption at rest: Customer data is stored using our cloud provider's managed, encrypted storage (Google Cloud / Cloud SQL).
- Controlled, auditable deployments: Code changes reach production through an automated pipeline using short-lived cloud credentials rather than long-lived deploy passwords.
- Cloud infrastructure: HeuraLab runs on Google Cloud Platform, a provider that maintains its own extensive independent security and compliance program.
- Session security hardening: Login sessions use hardened cookie protections (HttpOnly, Secure, SameSite) to reduce the risk of session hijacking or unauthorized account access.
How We Handle Your Data
When you use HeuraLab's simulation and generation features, the relevant content and prompts are processed by leading commercial AI model providers that power the product. We work only with reputable providers under vendor agreements, and we do not sell personal information.
You control your own content: individual simulations can be deleted from your account today. Full-account data deletion and self-service data export tools are actively in development (see roadmap below).
HeuraLab is built for synthetic research, not as a system of record for protected health information (PHI), human resource (HR) data, or credit information. Please don't submit PHI or other regulated data into the standard product. We offer a separate healthcare track for qualifying enterprise engagements; contact us to discuss.
Roadmap
This is a living document updated as capabilities ship. It is not a compliance attestation. We're publishing it because we'd rather be transparent about what's still being built than imply capabilities we don't yet have. Items move from this table into “Security Today” above as they ship.
| # | Focus Area | Status | What This Means For You |
|---|---|---|---|
| 1 | Automated abuse & traffic protection (rate limiting) | Planned | An added layer of automated defense against abusive, automated, or malicious traffic patterns. |
| 2 | Secrets & credential management upgrade | Planned | Moving internal credentials to a centralized, rotating store to reduce the impact of any single system compromise. |
| 3 | Enterprise SSO (SAML / OIDC) | Planned | Sign in with your existing identity provider instead of individual Google accounts. |
| 4 | Customer-facing audit logs | Planned | Detailed, exportable activity logs for your own compliance and security review. |
| 5 | Self-service data export & deletion | In Progress | Export or fully delete your organization's data without waiting on manual support. |
| 6 | Security monitoring & alerting | In Progress | Expanding internal visibility into account activity so we can detect and respond to unusual behavior faster. |
| 7 | Incident response & notification process | Planned | Formalizing how we respond to, and communicate about, security incidents. |
| 8 | SCIM user provisioning | Planned | Automatically provision and deprovision user access as your team changes. |
| 9 | Customer-managed encryption keys (CMK) | Planned | Bring and control your own encryption keys rather than relying solely on provider-managed keys. |
| 10 | SOC 2 Type I / II | Planned | Independent third-party audit of our security controls. |
| 11 | Private / dedicated data environments | Planned | Isolated, non-shared environments for organizations that require it. |
| 12 | Contractual data residency | Planned | Choose or confirm the region where your data is processed and stored, as a contractual term. |
| 13 | ISO 27001 | Planned | Independent certification against the international information security standard. |
| 14 | HIPAA / BAA support | Available on request | This is not part of the standard product but we have a separate track for qualifying enterprise healthcare engagements. |
Note: this list reflects current build priorities and is provided for informational purposes only. It is not a contractual commitment or a delivery guarantee. For contractual commitments regarding specific capabilities or timelines, please contact us directly.
Our Approach to Ongoing Security
- Least privilege: People and systems get only the access they need for their role or task.
- Defense in depth: We layer authentication, authorization, encryption, and controlled deployment practices rather than relying on any single control.
- Secure by default: New features are built to require authentication and access control from day one, not bolted on afterward.
- Transparency: We'd rather tell you what's not built yet than let a gap in our security program surprise you later.
Questions or Enterprise Due Diligence
Enterprise customers and prospects can request our detailed technical security documentation and completed security questionnaires under an NDA. For enterprise due diligence, data processing agreements (DPAs), or any security-related question not answered here, reach out to info@heuralab.ai.
Published: 7/26