What we won't do with your data.
Celeus is built for research on confidential data, from patient records to survey responses. The design starts from what the model is never allowed to see, not from what it's convenient to send.
No data rows, ever.
Every path from your data to the AI model passes a guard that refuses data tables. The model works from a de-identified profile of your dataset - column names and types, summary statistics, and category names with small counts suppressed - and from the aggregate results of analyses. Summary statistics include each numeric column's minimum and maximum, and variable labels stored in your file are sent too. This isn't a policy; it's the shape of the code.
Columns flagged as identifiers, free text or dates are excluded from the AI by default when you upload. A column excluded from AI is left out of the profile the assistant works from. If you include one, or run an analysis on it, the AI sees its summaries or its name and category labels in the results it interprets, not its data rows.
Text you write is sent as you wrote it: chat messages, your research question, project and dataset notes, and codebook labels and descriptions. Keep identifiers out of those.
Scanned before anything else happens.
Every upload is checked against the HIPAA Safe Harbor identifier categories, by column name, by value pattern and with a free-text scan. You decide what happens to each flagged column: drop it, pseudonymize it, reduce dates to the year or shift them, cap ages over 89, or truncate ZIP codes. The result is saved as a new version of the dataset.
A workspace owner can choose to store identified data instead. That takes a second factor and accepting an attestation, and it stays off unless the owner turns it on.
A second factor where it counts.
You sign in with Google. On top of that, you can enroll an authenticator app or a passkey or security key as a second factor. Deleting data, projects or accounts, inviting or removing team members, changing roles, sharing a project flagged as containing identifiers, and turning on identified-data storage all require it, re-confirmed within the last few minutes.
Every result ships with its own proof.
Every analysis is seeded and runs on pinned package versions. The output is a reproducible package: the plan, the exact R script, the seed, full session info, and an append-only audit log. Re-run it on the same pinned engine and you get the same numbers -read the validation report.
The workspace owns the data. People own the actions.
On a Team plan, the workspace - not any individual - owns everything in it. Every member can see everything the lab has done, admins manage membership and billing, and the audit trail attributes every action to the person who took it. If a member leaves, their work stays with the lab, the way research data already works under a PI.
Research questions, not decisions about individual patients.
Celeus interprets statistical results for research datasets - it does not produce diagnosis or treatment recommendations for individual patients, and it isn't positioned or marketed as clinical decision support software.
More than 25 seats, or custom terms.
Enterprise runs on the same managed platform as every other plan.Contact us about more than 25 seats or custom terms.
Last updated September 27, 2026.