Security
Built for regulated environments from day one
Argon is not a general AI tool with compliance features bolted on. Security and data governance were designed into the architecture before the first line of product code. Every decision from storage to inference is made with regulated pharma document handling in mind.
Three commitments that do not vary by tier
These apply to every Argon account on every plan, not just enterprise agreements.
Your documents never train our models
Documents you upload to Argon are used only to answer your team's queries. They are not used to improve our base models or shared with any other customer. This is a product commitment, not a marketing claim.
HIPAA controls built into the architecture
We do not claim HIPAA certification. We are an angel-stage startup. What we do claim: the architecture decisions made at the design stage implement the technical safeguards that HIPAA requires for electronic PHI, including access controls, audit logging, and transmission security.
Workspace isolation between product lines
Each knowledge collection is isolated at the data layer. An MSL working on Product A cannot access Product B's documents, and queries in one workspace do not influence results in another. Separation is enforced at the storage tier, not just the UI.
Access controls and audit infrastructure
Pharma IT procurement teams ask specific technical questions. Here are the answers.
Role-based access controls
Administrators assign users to collections and permission levels. Viewer, contributor, and admin roles map to the access patterns medical-affairs teams actually use. Changes take effect immediately with no re-login required.
Full query audit log
Every query, every answer, and every document retrieval is logged with a timestamp and user identity. Logs are exportable in CSV format for compliance review. Retention period is 24 months by default, configurable for Organization accounts.
Data in transit and at rest
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Document contents are never transmitted unencrypted between your browser, our API layer, and storage. Encryption keys are managed per-workspace.
SSO and SAML (Organization tier)
Organization accounts can connect Argon to your corporate identity provider using SAML 2.0. User provisioning and de-provisioning is handled through your existing directory, so access is revoked the moment an employee leaves without a separate Argon offboarding step.
Our approach to compliance in a regulated industry
We will not put badges on this page that we cannot substantiate. Here is what we actually do.
What we say and what we do not say
Many early-stage software vendors display compliance badges for certifications they have not yet obtained. We think that erodes trust rather than building it. Our current position:
- We implement the technical safeguards HIPAA requires. We do not claim a HIPAA certification or that we are a covered entity.
- We are pursuing SOC 2 Type II. We will display the report when we have it, not before.
- We sign Business Associate Agreements for customers handling PHI. Contact us to initiate a BAA before uploading any protected health information.
- Security questions are answered directly by technical founders, not a sales team reading a sheet.
If your IT security team needs a detailed technical brief, architecture diagram, or questionnaire completed, email [email protected] and we will respond within one business day.
Have a specific security question before you evaluate?
We answer security and compliance questions directly, without routing through a sales process. Email us or request a demo with the security team on the call.