Privacy, by design

Built for teams that take research data seriously

PerfectPaper gives labs, departments, and institutions the security, access controls, and integrations they need — without getting in the way of the work.

Your content stays yours

We protect your manuscripts with strong access controls and encrypted storage, in transit and at rest.

Privacy policy

Never used to train AI

Your papers are yours. Nothing you upload is ever used as training data.

How we handle your data

A compliance roadmap

We're pursuing SOC 2 and ISO 27001. Our data handling and subprocessors are documented for your IT team.

See compliance

Everything in Enterprise

Every capability below ships today — nothing on this list is a roadmap item.

Deep Microsoft integration

If your institution runs on Microsoft, PerfectPaper plugs in everywhere — identity, provisioning, and the place your team already talks.

Talk to us about your tenant
  • Microsoft Entra single sign-on — SAML 2.0 and OIDC
  • SCIM provisioning and group sync straight from Entra
  • A Microsoft Teams bot: review updates as Adaptive Cards
  • Account linking via Entra ID — no second identity
  • Organization-enforced MFA honored at every sign-in

Security

Your manuscripts are encrypted in transit and at rest and are never used to train models.

Read the full security page
  • Encryption in transit and at rest
  • Content never used for model training
  • Input sanitization on every upload

Teams & organizations

Bring your lab or department together with shared organizations, roles, and credits.

  • Organizations with owner, admin, and member roles
  • Groups and per-project access
  • A shared credit pool with per-member allocation
  • Seat-based contracts with high-water billing and internal invoicing

Access & identity

Sign in the way your institution already does, and control exactly who sees what.

  • Single sign-on — SAML 2.0 and OIDC (Entra, Okta, and any standard IdP)
  • SCIM 2.0 provisioning; deprovisioning ends sessions immediately
  • Domain routing with just-in-time provisioning
  • Organization-enforced multi-factor authentication
  • Granular, scoped access grants

Developer platform

Automate reviews and stream events into your own systems.

API docs
  • API keys and a REST API — full OpenAPI reference
  • Organization-scoped webhooks, HMAC-signed, at-least-once
  • Delivery log with one-click replay
  • Domain events and metrics endpoints for your observability stack

Compliance & data

Clear data handling and a compliance roadmap you can share with your IT team.

  • Append-only audit logs of role, access, and authentication events
  • Encryption at rest for secrets and sensitive fields
  • EU data residency available
  • Documented subprocessors and data handling
  • Pursuing SOC 2 and ISO 27001 certification

Support & SLAs

Dedicated support, onboarding help, and service-level agreements are available on enterprise plans.

Talk to sales
  • Dedicated support contact
  • Onboarding and IT help-desk resources
  • Service-level agreements (SLAs)

From first call to full rollout

1

Talk to us

Tell us about your lab, department, or institution. We'll scope seats, data residency, and your identity setup on the first call.

2

Security review & pilot

Your IT team gets our documentation — subprocessors, data handling, DPA — while a pilot group reviews real manuscripts.

3

Roll out with your directory

SAML SSO and SCIM go live, roles sync from your groups, and the Teams bot follows your researchers into their channels.

Talk to us about your team.

Tell us about your lab, department, or institution and we'll help you get set up — including security review, onboarding, and SLAs.