Last updated: August 11, 2026
In short
Curie encrypts your research in transit and at rest, isolates every account at the database layer, and never uses your documents to train AI models. This page describes the controls we operate today and the certifications we are working towards.
Researchers entrust Curie with unpublished work, interview data, and years of reading. We treat that responsibility as a design constraint rather than an afterthought: security requirements are built into how the Service is architected, developed, reviewed, and operated. This page describes those controls. For how personal data is collected and used, see our Privacy Policy.
Curie never receives or stores card numbers or banking credentials. Payments are processed by Doku, a Bank Indonesia-licensed and PCI DSS-compliant payment gateway. Card details are entered directly with the provider; we receive only the outcome of the transaction, the plan purchased, and invoice metadata. Payment callbacks are verified by signature before any subscription change is applied.
We keep our supply chain deliberately small. Providers with access to customer data are assessed for their security posture and are bound by written confidentiality and data protection terms.
| Category | Role | Access |
|---|---|---|
| Cloud hosting and database | Runs the application and stores data | Encrypted account data and Content |
| AI model providers | Generate requested output | Only the excerpts sent with a request |
| Payment gateway (Doku) | Processes subscriptions | Billing contact and transaction data |
| Email delivery | Verification codes and service notices | Email address and message content |
| Academic data services | Search and reference metadata | Search queries only |
Curie is designed to align with the principles of Indonesia's Personal Data Protection Law (UU No. 27 of 2022) and the EU General Data Protection Regulation, including data minimisation, purpose limitation, security of processing, and the data subject rights described in our Privacy Policy.
We are working towards independent certification against ISO/IEC 27001 and a SOC 2 Type II examination. We have not yet completed these audits and we do not claim to be certified. Institutions evaluating Curie can request our current security overview and sub-processor list at hello@curie.id, and we are able to sign a data processing agreement.
We welcome responsible disclosure from the security community. Report suspected vulnerabilities to hello@curie.id with sufficient detail to reproduce the issue.
We maintain an incident response process covering detection, triage, containment, eradication, recovery, and post-incident review. In the event of a personal data breach we will notify affected users and the competent supervisory authority within the periods required by applicable law — including 72 hours under the GDPR and 3 × 24 hours under Article 46 of UU PDP — and will describe the nature of the incident, the data involved, the measures taken, and the steps you should consider.
Security questions, due diligence requests, and documentation requests can be sent to hello@curie.id. See also our Privacy Policy and Terms of Service.