Security & Compliance

Built for regulated biotech R&D.

Consolidate is architected so your research data stays yours: permission-aware, default-deny, and designed to run entirely inside your own cloud. Consolidate is early / pre-launch, so this is a straight account of how it's built, how it deploys, and what's still on the roadmap.

How your data is protected

Properties of how the product is built and deployed, not marketing.

deployment

Runs in your own cloud

Designed to run entirely inside your environment, so your data stays in your cloud. With in-tenant inference, the models run there too. No copy of your data sits on our infrastructure.

permissions

Permission-aware, default-deny

Access is enforced per-fact against your source systems' own permissions, applied before the model reads anything, and defaulting to deny.

fidelity

Follows your tools' own permissions

Access mirrors each connected system, down to channel membership and sensitivity class, rather than a coarse, all-or-nothing role.

access

Read-only & never trained on

Read-only connectors. We never modify your systems, and your data is never used to train a model.

provenance

Every answer cited to source

Each claim traces back to the exact record it came from, so every answer is verifiable against its sources.

integrity

Abstains rather than guess

When the evidence isn't there, Consolidate says so. It won't fabricate. An unverified answer is worse than none.

sub-processors

Designed for zero data sub-processors

In the own-cloud deployment with in-tenant inference, no third-party model provider receives your data. (Current previews use an external model provider, one of the first things the own-cloud deployment removes.)

encryption

Encrypted in transit; credentials at rest

TLS in transit; stored source credentials sealed with AES-256. Research data at rest is protected by your own cloud's disk encryption.

Controls & roadmap

Where each control stands. Available = real in the product today. By design = an architectural property, not yet deployed for a customer. Planned = on the roadmap, not built. We mark nothing higher than it is.

ControlStatus
Permission-aware, default-deny accessAvailable
Native source-permission fidelity + sensitivity classesAvailable
Read-only connectors · no training on your dataAvailable
Source-cited, verifiable answersAvailable
Encryption in transit (TLS) · AES-256 stored credentialsAvailable
Single-tenant, own-cloud deployment modelBy design
In-tenant inference (removes the model sub-processor)Planned
SSO / SAML & SCIM provisioningPlanned
Immutable, exportable audit logsPlanned
Customer-managed keys (BYOK / KMS)Planned
21 CFR Part 11 electronic signaturesPlanned
SOC 2 Type IIPlanned
ISO 27001Planned
Third-party penetration testPlanned

By design, deploying in your own cloud answers much of a typical vendor security review through architecture: your data stays in your environment, so there's no shared tenant to breach and, once in-tenant inference is enabled, effectively no data sub-processors to vet.

Security review?

We're happy to walk your security team through the architecture and complete your questionnaire.

Talk to us ← Back to consolidate.bio