Security

Your Life’s Work Deserves 
More Than “Trust Us”

QED Science protects every research input you share, from manuscripts and grants to queries and data, 
with controls an independent auditor has tested and you can verify yourself.

Research-Grade Protection

Purpose-Built Security

QED Science's security program spans infrastructure, application, and operations. The platform runs on AWS in a private, segmented environment behind a web application firewall, with least-privilege access, encryption in transit and at rest, logging with monthly review, and semi-annual access reviews.

Data 
Control

You retain control over your work. Decide what to upload, who can see it, and when it is deleted. Uploads are visible only to you and the people you share them with, separation between accounts is verified in independent testing, and customer data is disposed of according to our commitments to you.

Your Work 
Stays Yours

Research inputs you upload, whether a manuscript, a grant, a query, or a dataset, are not used to train or fine-tune language models. Your work is used to deliver the review you asked for.

Independently Tested

QED Science partners with top-tier firms for external validation. Our SOC 2 Type II audit is performed by EY across Security, Availability, and Confidentiality, and our application is penetration-tested annually by an independent security firm. Vulnerability scanning runs between tests, and findings are tracked to closure.

Enforceable Commitments

Our agreements set out binding terms on confidentiality, data protection, customer notification, and support response times, with a Data Processing Agreement available to academic institutions, enterprises, and pharma partners. Our controls are aligned with SOC 2 and ISO 27001 and are audited, not asserted.

Every Control, Category by Category

The specific controls behind the summary above, grouped the way our auditors group them.

Access Control

  • SSO and Multi-Factor Authentication
  • Least Privilege and Need-to-Know
  • Semi-Annual Access Reviews

Availability

  • Multi-Availability-Zone Deployment
  • Continuous Database Backups
  • Annual DR and Restore Testing

Application Security

  • Annual Independent Penetration Testing
  • Continuous Vulnerability Scanning
  • Code Review and Change Control

Data Privacy

  • Information Classification
  • Customer Data Disposal per Agreement
  • Vendor Confidentiality Agreements

Data Security

  • Encryption at Rest and in Transit
  • Logging with Monthly Log Review
  • Restricted Access to Backups

Corporate Security

  • Annual Risk Assessment
  • Annual Security Awareness Training
  • Laptop Encryption and Antivirus

Network Security

  • Web Application Firewall and Security Groups
  • Private AWS Cloud, Isolated Production Environment
  • TLS-Encrypted Connections to Production

Policies

  • Information Security Policy
  • Access Control Procedure
  • Acceptable Use Policy
  • Incident Response Procedure

Reports

  • SOC 2 Type II Report
  • Penetration Test Attestation
  • Business Continuity and DR Plan

How Your Work 
Is Used

People hand QED Science unpublished manuscripts, grant strategy, and ideas that haven't seen daylight yet. We treat that as a responsibility.

Research inputs you upload are not used to train or fine-tune language models. Your work is used to produce the review you asked for. We measure and improve the accuracy of our reviews using the feedback you give us.

Full details on how your data is handled are in our Privacy Policy.

Free access for academic researchers

Create your free QED account to validate your research, strengthen grant proposals, and uncover scientific insights.
We've sent you an access link.
Please check your inbox.

Didn't get your email? Check your spam folder or reach out to info@qedscience.com

Oops! Something went wrong while submitting the form.
Looking for QED for pharma, biotech or life science organizations?
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.