Curie
FeaturesPricingInstitutionsAboutBlogFAQ
Log inStart writing

Security

Last updated: August 11, 2026

In short

Curie encrypts your research in transit and at rest, isolates every account at the database layer, and never uses your documents to train AI models. This page describes the controls we operate today and the certifications we are working towards.

1. Our approach

Researchers entrust Curie with unpublished work, interview data, and years of reading. We treat that responsibility as a design constraint rather than an afterthought: security requirements are built into how the Service is architected, developed, reviewed, and operated. This page describes those controls. For how personal data is collected and used, see our Privacy Policy.

2. Encryption

  • In transit — all traffic between your browser and Curie is encrypted with TLS 1.2 or above using modern cipher suites. Plaintext HTTP connections are redirected and never served application data.
  • At rest — documents, uploaded files, library data, and account records are stored on encrypted volumes using AES-256.
  • Internal traffic — connections to our database, storage, AI providers, and other upstream services are authenticated and encrypted.
  • Secrets — third-party API credentials are held in a managed secret store, injected only into server-side execution contexts, and are never exposed to the browser or embedded in client code.

3. Authentication and account protection

  • Passwords are hashed with a modern, salted, computationally expensive algorithm. We cannot read or recover your plaintext password.
  • Sign in with Google (OAuth 2.0) is supported, allowing you to inherit your Google account's protections including two-factor authentication and hardware keys.
  • New registrations are verified by a one-time code sent to your email address before the account is activated.
  • Sessions use short-lived, signed tokens; signing out invalidates the session, and password resets use single-use, time-limited tokens.
  • Repeated failed authentication attempts and anomalous request patterns are rate-limited.

4. Tenant isolation and access control

  • Every record in Curie carries an owner. Row-level security rules are enforced by the platform on every read and write, so one account's documents, library, chats, and comments cannot be reached by another — including through the API.
  • Shared workspaces expose data only to members you explicitly invite, at the role you assign.
  • Internal access to production systems is restricted to the minimum number of personnel required to operate and support the Service, granted on a least-privilege basis, and protected by strong authentication.
  • Administrative operations are separated from ordinary application logic and require elevated, logged permissions.

5. AI processing safeguards

  • Only the excerpts and instructions necessary to fulfil the specific request you make are transmitted to an AI provider — never your account, your library, or documents you did not involve.
  • Your Content is never used to train Curie models; we operate no training pipeline of our own.
  • We use enterprise API tiers whose contractual terms exclude customer inputs and outputs from provider model training.
  • AI providers are accessed over authenticated, encrypted channels using server-side credentials; no model credential is ever present in the browser.
  • Requests to public academic infrastructure (OpenAlex, Crossref, DOAJ, CORE, Semantic Scholar) carry search terms only, not your identity or your documents.

6. Application security

  • Authentication and authorisation are validated server-side on every backend operation; the client is never trusted to enforce access.
  • Input validation, output encoding, and parameterised data access protect against injection and cross-site scripting.
  • Features that fetch remote documents apply allow-listing and SSRF protections so they cannot be redirected against internal infrastructure.
  • Uploads are size- and type-restricted, stored outside the application's execution path, and served through signed, expiring URLs where private.
  • Dependencies are monitored and patched on a continuous basis, and changes are reviewed before reaching production.

7. Infrastructure, availability, and backups

  • Curie runs on managed, audited cloud infrastructure with physical security, redundancy, and network controls maintained by the provider.
  • Data is backed up on an automated schedule; backups are encrypted and access-controlled, and restoration procedures are tested.
  • Backup copies of deleted content are purged within 30 days of deletion.
  • Application, access, and security events are logged and monitored for anomalies.

8. Payment security

Curie never receives or stores card numbers or banking credentials. Payments are processed by Doku, a Bank Indonesia-licensed and PCI DSS-compliant payment gateway. Card details are entered directly with the provider; we receive only the outcome of the transaction, the plan purchased, and invoice metadata. Payment callbacks are verified by signature before any subscription change is applied.

9. Sub-processors and vendor review

We keep our supply chain deliberately small. Providers with access to customer data are assessed for their security posture and are bound by written confidentiality and data protection terms.

CategoryRoleAccess
Cloud hosting and databaseRuns the application and stores dataEncrypted account data and Content
AI model providersGenerate requested outputOnly the excerpts sent with a request
Payment gateway (Doku)Processes subscriptionsBilling contact and transaction data
Email deliveryVerification codes and service noticesEmail address and message content
Academic data servicesSearch and reference metadataSearch queries only

10. Compliance and certification roadmap

Curie is designed to align with the principles of Indonesia's Personal Data Protection Law (UU No. 27 of 2022) and the EU General Data Protection Regulation, including data minimisation, purpose limitation, security of processing, and the data subject rights described in our Privacy Policy.

We are working towards independent certification against ISO/IEC 27001 and a SOC 2 Type II examination. We have not yet completed these audits and we do not claim to be certified. Institutions evaluating Curie can request our current security overview and sub-processor list at hello@curie.id, and we are able to sign a data processing agreement.

11. Your part in keeping data safe

  • Use a strong, unique password, or sign in with Google using two-factor authentication.
  • Invite collaborators to workspaces deliberately, and remove access when a project ends.
  • Sign out on shared or public devices.
  • Apply your institution's ethics and data handling rules before uploading sensitive or identifiable research data.
  • Contact us immediately if you suspect unauthorised access to your account.

12. Vulnerability disclosure

We welcome responsible disclosure from the security community. Report suspected vulnerabilities to hello@curie.id with sufficient detail to reproduce the issue.

What we ask

  • Do not access, modify, or delete data belonging to other users; use only accounts you control.
  • Do not perform denial-of-service testing, spam, or social engineering against our users or staff.
  • Give us a reasonable period to remediate before any public disclosure.

What we commit to

  • Acknowledge your report within 3 business days.
  • Provide an initial assessment within 10 business days and keep you updated until resolution.
  • Credit you for the finding if you wish, and take no legal action in respect of good-faith research conducted within these guidelines.

13. Incident response

We maintain an incident response process covering detection, triage, containment, eradication, recovery, and post-incident review. In the event of a personal data breach we will notify affected users and the competent supervisory authority within the periods required by applicable law — including 72 hours under the GDPR and 3 × 24 hours under Article 46 of UU PDP — and will describe the nature of the incident, the data involved, the measures taken, and the steps you should consider.

14. Contact

Security questions, due diligence requests, and documentation requests can be sent to hello@curie.id. See also our Privacy Policy and Terms of Service.

Curie

Meet your intelligent research assistant

PT Hanya Planet Bumi ("Curie")
South Tangerang, Indonesia

Start writingCurie AI - The AI workspace for papers, citations & literature reviews. | Product Hunt
Product
  • Pricing
  • Features
  • FAQ
  • Curie for MS Word
  • Institutions
  • Refer & earn
  • About
  • Blog
  • Changelog
  • Careers
  • Contact
Account
  • Log in
  • Sign up
  • Workspace
Legal
  • Privacy Policy
  • Terms of Service
  • Billing & Payments
  • Refund Policy
  • Security
Zero data training — your work is never used to train AI modelsDesigned to align with UU PDP (Law No. 27/2022) and GDPR principles
© 2026 Curie. All rights reserved.PrivacyTerms