Institutional due diligence
Manusights institutional review brief
This page answers the questions a university, lab, library, or security office usually asks before approving a manuscript-review pilot. It states current controls and current limitations, including where Manusights is not certified.
Current as of September 5, 2026.
Non-PHI service boundary
Manusights is not currently a HIPAA service, does not offer a Business Associate Agreement, and must not receive protected health information (PHI), a HIPAA limited data set, or directly identifiable patient information.
If a manuscript contains patient information, de-identify it under the institution's approved process before using Manusights, or do not upload it. A name, medical-record number, exact date, image, rare-case description, or combination of details may still identify a patient even when obvious identifiers have been removed.
Manuscript data flow
1. Upload
The author uploads a manuscript over HTTPS. The browser sends the file through a short-lived signed upload session to private Supabase Storage in AWS us-west-2.
2. Review processing
The review API and workers run on Google Cloud Run in us-east1. They retrieve the file for the requested review and send only the task context needed to Anthropic or OpenAI when that model path is used.
3. Delivery
The system stores job state and generated artifacts long enough to deliver the report and support the customer. Transactional email is delivered through Resend.
4. Deletion
Source files are scheduled for deletion 7 days after the review lifecycle settles. Standard individual-review artifacts are scheduled for deletion after 30 days. Active Lab Plan workspaces retain report history for revision tracking and schedule those artifacts for deletion 30 days after the plan ends. Earlier deletion can be requested by email.
Automated Full Reviews and Dossiers do not use a live human reader. Authorized operators may access limited records when needed to investigate a customer-authorized support request, security issue, or failed workflow. A separately purchased Expert Review uses a human reviewer under a separate engagement and confidentiality process.
Providers and locations
Manuscript processing therefore leaves the customer's institution and may cross state or national borders. Model-provider processing follows the provider account and service terms; Manusights does not promise single-region model processing unless that control is separately contracted and verified.
Retention and deletion
- Source manuscript: scheduled for deletion 7 days after the review lifecycle settles.
- Generated report artifacts: standard individual-review artifacts are scheduled for deletion 30 days after the review lifecycle settles. Active Lab Plan workspaces retain report history for revision tracking; those artifacts are scheduled for deletion 30 days after the plan ends.
- Model-provider processing: not used for training by default. Standard provider retention may be up to 30 days unless stricter account-level controls are confirmed.
- Operational records: limited job, security, billing, and support records may be retained longer for fraud prevention, accounting, legal obligations, and service reliability.
- Early deletion: email team@manusights.com from the address used for the review and include the job ID. Manusights verifies ownership before deleting customer data.
Review quality and model governance
Evidence boundary
The review rubric was developed from work with 35+ experienced reviewers and senior scientists and is tested with internal evaluation sets. This is internal product-development evidence, not an independent published validation study and not proof that the calibration sample represents every target journal.
Hallucination controls
Outputs distinguish manuscript-grounded observations from external claims, use structured contracts and provenance checks, and apply hard-failure gates for fabricated facts or citations. Authors should still verify every factual statement and citation before acting on the report.
Production changes
Model and prompt changes are evaluated before promotion using hard-failure checks, blind quality comparisons, and cost and latency limits. Routine improvements are not individually announced to every customer. Material changes to privacy, subprocessors, or the service boundary are posted in the Trust Center and reflected in the policy date.
Current assurance status
Manusights is not SOC 2 or ISO 27001 certified. We can provide this control summary, answer a security questionnaire, discuss a DPA, and scope a non-PHI pilot. We will not present a cloud vendor's certification as Manusights' certification.
An institution that requires a current SOC 2 report or a BAA as a non-negotiable condition should not approve Manusights under the current service boundary. A department may still be able to approve a non-PHI pilot through its lower-risk vendor-review path.
Primary policy references
- HHS guidance on HIPAA and cloud computing explains why a service handling ePHI for a covered entity generally needs a BAA.
- Anthropic's commercial data-retention policy describes its standard API retention period and separately contracted zero-data-retention option.
- OpenAI API data controls describe training defaults, abuse-monitoring retention, and optional stricter controls.
- Google Cloud Run locations identifies us-east1 as South Carolina.