Security & Compliance
Your manuscript is unpublished work, and we treat it that way. It is encrypted in transit and at rest, processed with purpose-limited access, retained only as the review workflow requires, and never used to train any AI model. Here is exactly how that works.
Encryption
Manuscript uploads use encrypted HTTPS connections, and stored files use the cloud provider's encryption at rest. Manuscripts are processed with isolated workflow controls and time-bounded retention.
Data Handling
Manuscript content is used only to provide the requested review and is not used to train Manusights or model-provider models. Source files are scheduled for deletion seven days after the review lifecycle settles. Standard individual-review artifacts are scheduled for deletion after 30 days. Active Lab Plan workspaces retain report history for revision tracking; their artifacts are scheduled for deletion 30 days after the plan ends. Limited operational and billing records may be kept longer where needed for security, support, accounting, and legal obligations.
Infrastructure
Persistent application data and manuscript storage use Supabase in AWS us-west-2. Core review services run on Google Cloud Run in us-east1. The public application is served through Vercel's network. Access uses least-privilege service credentials and is limited to the workflow components and authorized operators needed to provide and support the service.
Compliance
Manusights uses third-party infrastructure and model providers only to operate the service; the full list and the data each provider handles are published in the Trust Center. Model-provider API content is not used for model training. Standard provider retention may still apply, including up to 30 days for abuse monitoring unless stricter account-level terms are in place.
Manusights is not SOC 2 or ISO 27001 certified. We do not describe certification as pending or imply that a vendor's certification transfers to Manusights. For institutional review, we can provide a current control summary, architecture and data-flow answers, subprocessor disclosures, and a DPA discussion.
Manusights is not currently a HIPAA service, does not offer a Business Associate Agreement, and must not be used with protected health information (PHI), a HIPAA limited data set, or directly identifiable patient information. Authors should de-identify manuscripts through their institution's approved process before upload, or not upload them.
Institutional reviewers can see our full subprocessor list and trust posture, read the manuscript data-handling brief, review the institutional review brief, or request a DPA and vendor-review materials at the Trust Center (or email team@manusights.com).