Choose your research environment

Your work.
Your controls.

Private enhancements, personal AI credentials and storage choice support an environment aligned with your institution’s confidentiality and infrastructure requirements.

Private by application scope

A subsystem that belongs
to your research workflow.

Keep enhancements separate.

Private layers are scoped to their owner and research context. Another ordinary user does not inherit access to your layers. Active overlays customize permitted scientific code for your runs without changing the shared installation.

Keep decisions traceable.

Review diffs, numerical comparisons and activation records. Layer order and dependencies are preserved. You explicitly activate passing candidates and can manage or delete layers within the stack’s dependency rules.

These are application access controls, not a guarantee of absolute IP isolation. Hosting administrators and infrastructure are not cryptographically excluded. Your deployment and provider agreements determine additional confidentiality and retention protections.

BYOK / Bring Your Own Key

Choose the AI account
behind your investigation.

SaaS deployments can enable per-user credentials for all five integrations: OpenAI, operator-approved OpenAI-compatible endpoints, DeepSeek, Google Gemini and Anthropic / Claude. Standalone uses locally configured credentials.

Separate credentials and billing.

Hosted personal keys are stored in the credential vault and excluded from frontend settings responses. Missing or invalid personal credentials do not fall back to the operator’s key.

Understand what the model receives.

The configured provider receives selected evidence, source excerpts and conversation content needed for the investigation. BYOK does not make that processing zero-knowledge or override your provider’s retention policies.

BYOS / Bring Your Own Storage

Choose where bulk
research evidence lives.

Use an approved S3-compatible HTTPS destination or the outbound Linux / POSIX NAS connector. Regular PF-managed storage remains available. Changing your default destination does not silently move earlier runs.

User-owned bulk storage

  • Large inputs, outputs and evidence payloads
  • Resources pinned to their original destination
  • Recorded length and hash verification
  • Recovery and retries after transfer failures

PF-managed control records

  • Accounts, permissions and run identities
  • Conversations and continuation checkpoints
  • Layer changes, diffs and activation records
  • Trusted hashes and validation records

PF workers need readable access to files and use temporary working storage for execution. Offline or full user storage can interrupt access to uncached files. BYOS moves bulk retention costs and responsibilities; it does not remove compute, temporary disk or network costs.

Operator-managed deployment

Connect the services
around the workbench.

Configured hosted deployments can use AWS Batch for simulation jobs, managed AWS S3 for artifacts, Amazon Cognito for identity, Stripe for billing and SMTP for transactional email. These are optional operator integrations with their own account and configuration requirements.

The public website does not activate these services. An institution’s separate PF deployment determines which connections are enabled, who operates them and how research data is handled.

This public website

Public examples.
No research credentials required.

This website presents documentation and freshly generated demonstration results. It does not ask for API keys, connect to your research storage or execute private simulations. No analytics, advertising scripts, contact forms or application cookies are included in the supplied website code.

The hosting service may process ordinary request and access logs. Following an external link brings you under the destination’s practices. The separately deployed PF workbench has its own account, data-handling and operational requirements.