Trust & security

Security posture, without inflated claims.

GaiaLab is a research-use platform. This page describes controls that are implemented or explicitly staged, and separates them from certifications or regulatory claims GaiaLab does not currently make.

Research use onlyNo SOC 2 claimNo HIPAA claimNo GxP / 21 CFR Part 11 claim

Implemented engineering controls

Current enterprise boundary

GaiaLab is suitable today for public or non-confidential research exploration and bounded validation pilots. Until authenticated organizational identity and database-level tenant isolation are fully deployed and verified, customers should not submit PHI, patient-identifiable data, trade-secret datasets, or other confidential regulated information unless a written agreement explicitly defines the approved workflow and controls.

Tenant isolation

GaiaLab has implemented workspace-scoped database transaction support and has designed row-level-security policies. Database-level RLS remains a staged control and is not represented here as fully deployed across every workspace path. Enterprise confidential-data use will not be marketed as ready until that rollout is complete and tested.

Authentication and auditability

Public research exploration intentionally supports low-friction access. Paid institutional workflows require a stronger identity and audit model. Durable authenticated identity, team-level access boundaries, and user-attributed audit events are part of the pharma-readiness gate.

Vulnerability reporting

Security reports may be sent to security@gailabai.com. Please provide enough detail to reproduce the issue and allow reasonable time for investigation before public disclosure.

What GaiaLab does not claim