Security and compliance
Security at Desearch
Desearch has a SOC 2 Type II report and handles personal data under the GDPR. A Data Processing Agreement and zero data retention are available, and our controls are aligned with the HIPAA Security Rule. This page explains each one, how to request documents, and how to report a vulnerability.
Last updated
At a glance
| Standard | Status | Documents |
|---|---|---|
| SOC 2 Type II | Independently audited | Report shared under NDA |
| GDPR | Personal data handled under the GDPR | Privacy policy, data requests by email |
| Data Processing Agreement | Available | Requested by email |
| Zero data retention | Available | Enabled for your workload on request |
| HIPAA | Controls aligned with the HIPAA Security Rule | Review with our team before sending PHI |
| Enterprise agreements | Custom terms, service levels, and invoicing | Agreed for your workload |
Is Desearch SOC 2 compliant?
Yes. Desearch has a SOC 2 Type II report from an independent audit of its security controls. The report is confidential. Email support@desearch.ai to request it, and we share it under NDA.
Is Desearch GDPR compliant?
Yes. Desearch processes personal data in line with the GDPR. The privacy policy explains what we collect, including account, usage, technical, and payment data, how we use it, and how long we keep it. To access, correct, or delete your data, or to object to its processing, email privacy@desearch.ai. A Data Processing Agreement (DPA) is available on request at support@desearch.ai.
Does Desearch store my queries and results?
Zero data retention is available. With it enabled, Desearch doesn't store your queries or results and doesn't use them for training. Without it, the privacy policy lists API calls and queries among the usage data Desearch may collect. Talk to our team to enable zero data retention for your workload.
Can I use Desearch with healthcare data?
Desearch's controls are aligned with the HIPAA Security Rule. If your workload involves protected health information (PHI), talk to our team before you send it so we can review your requirements together.
How is access to the API protected?
Every request authenticates with your API key over HTTPS. Keep the key on your server and connect your agents from there. Desearch Console shows request costs and usage by API key and service.
Does Desearch offer enterprise agreements?
Yes. Talk to us when you need higher volume, custom limits, invoicing, or specific support and data requirements. Pricing, capacity, and service levels are agreed for your workload, and a DPA and zero data retention are available.
How do I report a security vulnerability?
Email support@desearch.ai and start the subject line with [Security]. Include the affected system, steps to reproduce, and the impact you observed. Use only your own account and data, don't disrupt the service, and give us time to fix the issue before you disclose it publicly. In scope: www.desearch.ai, api.desearch.ai, console.desearch.ai, the desearch-py and desearch-js SDKs, and the Desearch MCP server.