Security and compliance

    Security at Desearch

    Desearch has a SOC 2 Type II report and handles personal data under the GDPR. A Data Processing Agreement and zero data retention are available, and our controls are aligned with the HIPAA Security Rule. This page explains each one, how to request documents, and how to report a vulnerability.

    Last updated

    At a glance

    StandardStatusDocuments
    SOC 2 Type IIIndependently auditedReport shared under NDA
    GDPRPersonal data handled under the GDPRPrivacy policy, data requests by email
    Data Processing AgreementAvailableRequested by email
    Zero data retentionAvailableEnabled for your workload on request
    HIPAAControls aligned with the HIPAA Security RuleReview with our team before sending PHI
    Enterprise agreementsCustom terms, service levels, and invoicingAgreed for your workload

    Is Desearch SOC 2 compliant?

    Yes. Desearch has a SOC 2 Type II report from an independent audit of its security controls. The report is confidential. Email support@desearch.ai to request it, and we share it under NDA.

    Is Desearch GDPR compliant?

    Yes. Desearch processes personal data in line with the GDPR. The privacy policy explains what we collect, including account, usage, technical, and payment data, how we use it, and how long we keep it. To access, correct, or delete your data, or to object to its processing, email privacy@desearch.ai. A Data Processing Agreement (DPA) is available on request at support@desearch.ai.

    Does Desearch store my queries and results?

    Zero data retention is available. With it enabled, Desearch doesn't store your queries or results and doesn't use them for training. Without it, the privacy policy lists API calls and queries among the usage data Desearch may collect. Talk to our team to enable zero data retention for your workload.

    Can I use Desearch with healthcare data?

    Desearch's controls are aligned with the HIPAA Security Rule. If your workload involves protected health information (PHI), talk to our team before you send it so we can review your requirements together.

    How is access to the API protected?

    Every request authenticates with your API key over HTTPS. Keep the key on your server and connect your agents from there. Desearch Console shows request costs and usage by API key and service.

    Does Desearch offer enterprise agreements?

    Yes. Talk to us when you need higher volume, custom limits, invoicing, or specific support and data requirements. Pricing, capacity, and service levels are agreed for your workload, and a DPA and zero data retention are available.

    How do I report a security vulnerability?

    Email support@desearch.ai and start the subject line with [Security]. Include the affected system, steps to reproduce, and the impact you observed. Use only your own account and data, don't disrupt the service, and give us time to fix the issue before you disclose it publicly. In scope: www.desearch.ai, api.desearch.ai, console.desearch.ai, the desearch-py and desearch-js SDKs, and the Desearch MCP server.