Security
Confidentiality and security is crucial in chemistry, and we take protecting our users' data very seriously. Here's what we do to protect the confidentiality of your data:
- All data is encrypted in transit using TLS/SSL and at rest using LUKS AES-XTS-plain64. Database backups are also encrypted, and our database and servers are in secure datacenters protected from physical access.
- Passwords are additionally encrypted via salting and hashing, ensuring that nobody (even us) can figure out your password. Similarly, API keys are hashed before storage.
- Credit card information never even touches our servers; instead, we use Stripe as our payments processor. Stripe also processes payments for companies you may have heard of—like Slack, OpenAI, Shopify, Google, and Amazon—so they're pretty trustworthy.
- Email verification is required to reset passwords, and users are notified upon any password change.
- Internal users don't have any special access to our website. So if you send us a calculation that didn't work, please make sure it's shared first or we won't be able to see it!
- And, of course, users maintain full control of all intellectual property. Uploading a structure to Rowan doesn't give us any claim to your IP, just like making a presentation in PowerPoint doesn't give Microsoft any claim to your IP. (Our terms and conditions state this clearly.)
You Own Your Data
We will never use your data to train an ML model without your permission. We're not trying to harvest data from our customers to make our own internal technology better.
We care about doing a good job here and are always open to being corrected. If you have an idea for how we could improve our security, let us know at contact@rowansci.com!