PepRally
v0.1.0Get Started →

Security

Security & data protection

PepRally is a research documentation tool, not a medical record system. We still treat the protocol, inventory, and dosing data you log as sensitive, and design the service accordingly.

How we protect your data

Encryption in transit and at rest

TLS 1.3 is enforced on all endpoints. Database records are encrypted at rest with AES-256, and files in object storage use server-side encryption.

Account-scoped data access

Every record in the system carries an account and tenant identifier, and queries are scoped to them by default rather than opt-in.

Data residency by region

You choose a data region — US or EU — when you create your account. Your data is stored in that region, and the region is fixed after signup.

Deployments run through CI

Application changes reach production through an automated pipeline from version control, not by hand.

What we don’t claim

PepRally holds no security certification or third-party audit attestation — no SOC 2, no ISO 27001 — and it is not a HIPAA-covered service. It is a research record-keeping tool, not an electronic medical record system, and it should not be used to store protected health information on anyone’s behalf. The controls above describe how the service is built; they are not a substitute for a formal audit, and we’d rather say so here than imply otherwise.

Your data rights

You can request a full export of your data or deletion of your account at any time. Details on format and timing are in our Privacy Policy.

Reporting a security issue

If you believe you’ve found a security vulnerability in PepRally, email security@nesting.llc. Please include steps to reproduce and avoid accessing data that isn’t yours. We aim to respond promptly and will follow up as we investigate.