Last updated: June 16, 2026
GHSLogic handles sensitive formulation data, including confidential business information (CBI) and trade-secret compositions. Security and confidentiality are designed into the product. This page describes the controls we have in place. If you have a security question or need documentation for a vendor review, email security@ghslogic.com.
GHSLogic runs entirely on managed, independently audited cloud infrastructure. We do not operate our own servers.
Google Cloud, Vercel, and Supabase each maintain their own SOC 2 Type II attestations; their reports are available from those providers under NDA. GHSLogic itself is not yet SOC 2 certified — see Compliance status below.
CBI and trade-secret handling is a core part of the product, not an afterthought:
GHSLogic uses Anthropic's Claude API to extract structured data from uploaded SDSs and to draft translations. Deterministic regulatory classification never relies on the AI model — the model assists with data extraction and drafting only, and every output is flagged as a draft requiring professional review. Data sent to the API is processed under Anthropic's commercial terms and is not used to train models.
We rely on the following subprocessors to deliver the service:
| Provider | Purpose |
|---|---|
| Google Cloud | Application hosting (Cloud Run) |
| Vercel | Frontend hosting / CDN |
| Supabase | Database & file storage |
| Anthropic | AI extraction & translation (Claude API) |
| Stripe | Payment processing |
| Resend | Transactional email |
| Cloudflare | DNS |
| Sentry | Error monitoring |
GHSLogic is built on SOC 2 Type II–certified infrastructure (Google Cloud, Vercel, Supabase) and follows the security practices described on this page. GHSLogic does not currently hold its own SOC 2 attestation. If your procurement process requires one, contact us at security@ghslogic.com — we're happy to discuss your requirements and timeline.
If you believe you've found a security vulnerability, please email security@ghslogic.com with details. We appreciate responsible disclosure and will work with you to confirm and address the issue. Please do not publicly disclose an issue before we've had a chance to respond.
Independent of security: every classification, label, and SDS GHSLogic produces is a draft decision-support document. It must be reviewed and signed off by a qualified SDS/GHS/regulatory professional before use, distribution, or submission to any authority.