Security
Drug discovery data security starts and ends with your structures
For a chemistry team the security conversation is usually one sentence long: what happens to my structures. The answer is that they answer your screen and nothing else. Everything below is the longer version.
Never used for training
Structures you submit are not used to train, fine tune or evaluate any model. Not ours, not a third party's. This is a term of the contract, not a preference you have to find and switch off.
Never shared
Your submissions are not visible to other customers and are not pooled into any shared dataset. A screen is answered and the result belongs to you.
Deletable on request
Ask and your submitted structures and results are deleted. On Program and Enterprise the deletion is recorded in the audit log so you can show it happened.
Controls
What is available, and on which plan
| Control | Detail | Available on |
|---|---|---|
| Transport encryption | TLS on every connection, HSTS enabled | All plans |
| Encryption at rest | Storage encrypted at rest | All plans |
| No training on your data | Contractual, applies to every submission | All plans |
| Deletion on request | Structures and results removed | All plans |
| Roles and permissions | Per seat access control inside a workspace | Discovery and above |
| API keys | Scoped keys, revocable individually | Discovery and above |
| SSO | SAML 2.0 and OIDC against your identity provider | Program and Enterprise |
| Audit log | Who ran what, when, and what was exported or deleted | Program and Enterprise |
| SLA | 99.9% uptime commitment | Program and Enterprise |
| DPA | Signed data processing agreement | Program and Enterprise |
| Invoicing and PO | Purchase order workflow, annual invoicing | Program and Enterprise |
| Data residency | Choose the region your data sits in | Enterprise |
| Private or VPC deployment | Runs inside your own environment | Enterprise |
| Named contact | A person, with an escalation path | Enterprise |
Scope of use
Research use only, and why that matters here
This product touches a medical adjacent subject. A predicted susceptibility read-out looks superficially like an antibiogram, and it is not one. It is a computational prediction built from published activity data, for the purpose of deciding what to put on a plate.
It must not be used for diagnosis, for treatment selection, for infection control decisions, or for anything else that reaches a patient. The label sits on the read-out, in the exports and in the terms, deliberately, in all three places.
Reporting a vulnerability
Email security@antibacterial.ai with enough detail to reproduce the issue. We will acknowledge the report, keep you updated while it is being fixed, and credit you if you want the credit. Please do not run automated scanning that degrades the service for other users.
General questions, procurement paperwork and DPA requests go to hello@antibacterial.ai.
Send the DPA request with your first screen
Create an account and reply to the confirmation email with what procurement needs. We answer paperwork by email, from a person.
What you are agreeing to
- Your compounds stay yours
- Never used for model training
- Deletable on request
- No card required to run a screen