Security & privacy

Built to be trusted with the manuscript.

Provenote handles unpublished work, author identity, and decisions that can affect careers. Security and privacy are not a page we bolted on, they are a launch gate.

DATA

Manuscripts & identity

Documents and author data are minimized, encrypted in transit and at rest, tenant-isolated, and deleted on a defined retention schedule. Content is kept out of logs.

THIRD PARTIES

Bring-your-own detectors

When you connect a detector, the request goes to your vendor under your terms and key. Outbound calls are allowlisted and require consent, we don’t quietly fan your manuscript out.

COMPLIANCE

EU AI Act · Art. 50

Provenote is a compliance-supporting tool for the Article 50 transparency duties, in force since 2 August 2026, including the machine-readable marking duty, whose grace period for systems already on the market runs to December 2026. We align to C2PA and provider watermark standards rather than inventing our own.

ASSURANCE

Independent review

A pre-launch penetration test and a tiered security standard gate real-user onboarding. We report findings honestly and won’t launch past an unresolved critical issue.

Responsible disclosure

Found a vulnerability? Tell us at security@provenote.us. We’ll acknowledge, investigate, and credit good-faith reports.

Status: Provenote is in private beta; some controls above are in build. This page tracks what is live versus in progress, honestly, as we approach launch.