Security & trust
What we won't do with your data.
Celeus is built for research statistics on sensitive datasets. The design starts from what the model is never allowed to see, not from what it's convenient to send.
No PII/PHI to the AI
One chokepoint, and nothing else touches the model.
A single function stands between your data and the AI. It accepts only a whitelisted metadata structure - variable names, types, summary statistics - never a data frame, never a row value, never free text. There is no second path from data to model. This isn't a policy; it's the shape of the code.
Deterministic, always
Every result ships with its own proof.
Every analysis is seeded and runs on pinned package versions. The output is a reproducible package: the plan, the exact R script, the seed, full session info, and an append-only audit log. Re-run it and you get the same numbers, bit for bit.
Workspace data ownership
The workspace owns the data. People own the actions.
On a Team plan, the workspace - not any individual - owns everything in it. Every member can see everything the lab has done, admins manage membership and billing, and the audit trail attributes every action to the person who took it. If a member leaves, their work stays with the lab, the way research data already works under a PI.
Research statistics, not clinical decision support
Celeus answers research questions, not patient questions.
Celeus interprets statistical results for research datasets - it does not produce patient-specific diagnosis or treatment recommendations, and it isn't positioned or marketed as clinical decision support software.
Enterprise
Deployment options on request.
Enterprise runs on the same managed platform as everyone else, with the org-level layer on top: SAML/SCIM SSO, project-level access control, an org-wide audit view, invoice/PO billing, and custom seats and quotas. For organizations of 25+ seats - contact us to talk through deployment options.