Security at Forefront

Your research deserves to be protected.

Forefront is built to help researchers explore, organise and understand scientific knowledge. That means protecting more than an account: it means protecting the research activity, saved work and information entrusted to the platform.

Security is built into how Forefront authenticates users, controls access to data, develops software and operates its infrastructure.

We continue to test and strengthen those protections as the platform grows.

01

Security by design

Security is part of Forefront’s architecture, not a layer added at the end.

We use secure defaults, explicit access controls and automated checks to reduce unnecessary exposure across the application.

Our API is being systematically classified by the identity and access requirements of each route, with automated checks designed to detect unclassified routes and discrepancies between documented policy and implementation.

Security-sensitive areas are reviewed with particular attention to authentication, authorisation, data ownership and unintended information exposure.

02

Accounts and access

Forefront distinguishes between public scientific information and research activity belonging to individual users.

Access to private account data is tied to a verified application identity. Authorisation controls determine what that identity is permitted to read or change.

Where Forefront supports guest functionality, guest identity is established using cryptographically signed credentials rather than trusting an identity supplied by the browser.

Permissions are enforced on the server rather than relying on what is visible or hidden in the interface.

03

Protecting your research

Public scientific knowledge and private user activity are treated differently.

Papers, trials and other scientific sources may be public information. Your saved research, projects, preferences and other account-specific activity are not made public simply because the underlying scientific material is.

Access to private data is restricted through application and data-access controls, and sensitive credentials and infrastructure secrets are kept outside application source code.

Data is encrypted in transit using HTTPS.

04

Application & infrastructure security

Forefront runs on established managed cloud infrastructure rather than operating its own physical servers.

Security is reinforced throughout development and production through controls including:

  • Authentication and server-side authorisation
  • Automated testing of security-sensitive behaviour
  • Dependency and vulnerability monitoring
  • Controlled handling of secrets and credentials
  • Validation at application boundaries
  • Restricted database access
  • Production error and security monitoring
  • Code review for security-sensitive changes

We also review the application for unnecessary exposure, insecure defaults and discrepancies between intended security policy and actual behaviour.

05

AI and your research

Your research shouldn’t become someone else’s answer.

Forefront uses AI to provide capabilities such as research synthesis, analysis and other research-intelligence features.

AI requests are constructed by Forefront and sent to external model providers where those capabilities require them. We minimise the context sent to those services to what is needed to perform the requested operation.

Forefront currently uses OpenAI as its sole AI provider, for both language models and text embeddings. Our OpenAI account is configured not to share API inputs and outputs, evaluation and fine-tuning data, or model feedback with OpenAI for model improvement. Content submitted through the API is therefore not used to train OpenAI's models. OpenAI may retain API inputs and outputs for up to 30 days for service operation and abuse monitoring, subject to its applicable data-retention policies and exceptions.

We want researchers to be able to understand what happens to their information when AI is involved rather than having to guess.

06

Privacy & responsible disclosure

Security protects the systems that hold your information. Privacy governs how that information is collected, used and retained.

Our Privacy Policy explains what personal information Forefront processes, why it is processed, the services involved and the rights available to users.

Read our Privacy Policy

Found something that doesn’t look right?

If you believe you’ve discovered a security vulnerability in Forefront, please report it privately so we can investigate.

Report a security issue

Please don’t publicly disclose a suspected vulnerability until we’ve had a reasonable opportunity to investigate and address it.

07

Security as we grow

Forefront’s security programme will develop alongside the platform.

As Forefront expands from individual researchers to larger research teams and organisations, we expect our security programme to include additional organisational controls, documentation and independent assurance.

We won’t claim certifications or compliance standards before we’ve earned them.

When we introduce formal certifications or independent security assessments, we’ll document them here.

Questions about security?

If you’re evaluating Forefront for your organisation and need more detail about our infrastructure, data handling, AI providers or security practices, talk to us.