Security & compliance

Built with your documents and your employees’ data protected as a first requirement.

PubDaily stores the documents you upload and the results your employees generate. Here's how we approach protecting both.

How we handle your data.

Encryption

Encrypted in transit and at rest

Uploaded documents and employee results are encrypted in transit and at rest.

Access

Role-based access controls

Access to results is limited by role, so a manager sees their own team and nothing else, and every access is logged.

Review

A review queue before questions go live

Generated questions can be held for a subject-matter expert to approve before employees ever see them.

Retention

Data retention scoped to purpose

Documents and results are retained only as long as needed to run the programme, per the terms agreed with each customer.

HIPAA, for healthcare customers.

For healthcare customers, PubDaily is built with HIPAA in mind, and we sign a Business Associate Agreement (BAA) where one is required. One caveat worth knowing: HIPAA has no official certification, so "HIPAA compliant" is never one company's claim alone — it depends on how you configure and use the platform too. Outside healthcare, the same secure infrastructure applies, just without the BAA paperwork.

What PubDaily does not do.

Not medical advice

Training, not clinical advice

PubDaily generates training questions from the documents an organisation uploads. It does not provide medical advice or make clinical determinations.

Not automatic submission

Nothing ships without a review option

Every generated question can be held for review before it reaches an employee, if you choose to use the queue.

Have a specific security question?

For questions about our data handling practices, BAA terms, or a security review as part of your procurement process, reach out directly.

Contact our team →