NakedSignal

Trust

Security and data handling

What this website collects, where an analysis runs, what we never receive, and what we do not hold. Everything here describes what exists today.

Last updated 26 September 2026

This website

  • A set of static pages served by Vercel over HTTPS, with HTTP Strict Transport Security. There is no server code, no database and no user account behind it.
  • It sets no cookies. If you choose a light or dark theme, that choice is kept in your own browser’s local storage and never sent to us.
  • The request form sends nothing. It opens a message in your own email app, and you decide whether to send it.
  • We count page views with Vercel Web Analytics, which is cookieless, runs from this site’s own address and does not identify you.
  • Pages are served with a content security policy that only allows scripts, styles, fonts and images from this site, and with headers that stop the site being framed by another.
  • The site loads no third-party fonts, embeds, advertising or tracking pixels.

In an engagement: the analysis runs where your data is

The analyser-change report is designed to run inside your laboratory, not ours.

  • The program runs on your own computer. It needs no network connection and opens none.
  • It prints checksums (sha256) of its configuration and of your input file, so you can confirm what was run on what.
  • The decisions that shape the result, such as decision limits and the re-test budget, are agreed and hashed before the data are opened.
  • Only aggregate files leave: the aggregate results, the report and a statement listing each released file with its checksum. You sign that statement.
  • Counts below the minimum cell size you set, five by default, are shown as “<5”.
  • The list of which samples crossed a limit stays on your computer, keyed by your own sample reference.

What we never receive

When the program runs on your computer, we never receive:

  • patient names, identifiers or dates of birth;
  • any row-level result, paired or not;
  • the list of samples that crossed a limit;
  • access to your laboratory information system, network or instruments.

If a laboratory prefers to send us coded pairs instead, that is agreed in writing first, the pairs carry no identifiers, and we hold no key that links them to a patient.

A laboratory may separately agree in writing to share coded per-sample instrument exports for method research; this is never needed for a report.

Optional: contributing to the Registry

Separately from any report, a laboratory may choose to contribute to the Analyser-Change Registry, a pooled record of what analyser changes do to patient results. It opts in on its order form or signs a one-page accession form, and chooses coded pairs or aggregates only for each change. Its own staff remove every identifier first; its data protection officer decides what is included; it can stop at any time. Contributing is never a condition of a report. No laboratory has contributed yet.

Data we use on this site

Only open-access, licensed public data, each deposit cited with its licence. No patient-identifiable data, no data held under a use agreement, and no customer data.

What we do not hold

  • We do not hold SOC 2 or ISO 27001 certification.
  • We have not had an outside security audit or penetration test.
  • Our reports are not regulatory clearances or ISO 15189 verifications.

We will say when any of that changes, and not before.

Reporting a vulnerability

If you find a security problem in this website or in anything we publish, email dan@careerloop.io. The same address is listed in our security.txt. Please give us a reasonable time to fix it before disclosing it.

Subprocessors for this website

ProviderWhat it does for this site
VercelHosting, request logs for security and operation, and cookieless page-view counts.
GoogleHosts the mailbox that receives email sent to our contact address.

Email you send us is held in the mailbox Google hosts for us and used only to reply to you.