Security
How the apps handle your data
Each app is a set of static files that runs in your browser. There is no account, no app server and no database of ours behind it. This page sets out what leaves your browser, which hosts each app contacts and the headers that hold the apps to that list.
Architecture
- Static files. Pages, scripts, data files and images are built ahead of time and served by the site's host.
- No server of ours in the data path. An app's scientific requests go from your browser to the public services named on this page, as a visit to their websites would.
- No accounts and no cookies. The apps have no sign-in and set no cookies.
- No analytics and no error reporting in the apps. Nothing in an app workspace reports to an analytics or monitoring service.
- No fonts or scripts from other origins. Fonts, the Mol* viewer and the RDKit chemistry engine are served from this site.
What leaves your browser
- Anything in the address bar before the # (a search, a SMILES, an accession or a step) is sent to this site's host when a page loads or a link is opened; anything after the # is not sent.
- What you look up (a search, an accession, a condition, a name) is sent to the public service that answers it, which sees it with your IP address under its own terms.
- Projects, notes and preferences stay in this browser's storage. No project data is uploaded.
- A link you copy carries what is in the address bar, and anyone you send it to can read it. Chat and mail tools may also fetch a link to show a preview.
Hosts each app contacts
The lists below come from each app's registry entry. The browser holds every app page to its list through the Content-Security-Policy header, which is generated from the same entry.
Drybench Protein.
Static files only: no server of ours in the data path, no accounts, no cookies, no analytics, and no font or script from any other origin. The identifiers you look up go from your browser to the six public hosts listed here, and the site's host keeps standard web-server logs.
rest.uniprot.org
- Operator
- UniProt Consortium (EMBL-EBI, SIB and PIR)
- What for
- Search, and the protein's entry: names, function, location, sequence and features.
- What it receives
- your search text and UniProt accessions
- When
- on lookup
www.ebi.ac.uk
- Operator
- EMBL-EBI
- What for
- PDBe: the PDB entries mapped to the protein, the residues each one resolves, residue numbering and structure files. The EBI Proteins API: the full variant list, when you ask for it.
- What it receives
- UniProt accessions and PDB ids
- When
- on lookup
data.rcsb.org
- Operator
- RCSB PDB (United States)
- What for
- Atom counts, so that very large entries load one chain first.
- What it receives
- PDB ids
- When
- on lookup
models.rcsb.org
- Operator
- RCSB PDB (United States)
- What for
- A second source for structure files when PDBe does not answer.
- What it receives
- PDB ids
- When
- on lookup
alphafold.ebi.ac.uk
- Operator
- EMBL-EBI (AlphaFold DB)
- What for
- The predicted model, its per-residue confidence and PAE image, and AlphaMissense scores when you ask for them.
- What it receives
- UniProt accessions
- When
- on lookup
api.platform.opentargets.org
- Operator
- Open Targets
- What for
- Drugs and clinical candidates for the target, with mechanisms, stages, indications and warnings.
- What it receives
- the target's Ensembl gene id, or its UniProt accession when the entry gives no Ensembl id
- When
- on lookup
Drybench Molecule.
RDKit.js runs in a Web Worker in your browser. The only host the app contacts besides its own is pubchem.ncbi.nlm.nih.gov, to look up a name that is not in the library; no structure is sent to it.
pubchem.ncbi.nlm.nih.gov
- Operator
- NCBI, U.S. National Library of Medicine
- What for
- Looks up a structure by name when the name is not in the app's library of approved drugs.
- What it receives
- the name you typed
- When
- on lookup
Drybench Pipeline.
Searches go from your browser straight to clinicaltrials.gov and api.fda.gov, and the site's host serves only the app's files. Counting and classifying run in your browser.
clinicaltrials.gov
- Operator
- U.S. National Library of Medicine
- What for
- Trial records for the condition and filters you search, and the registry's processing date.
- What it receives
- the condition and filters you search
- When
- on lookup
api.fda.gov
- Operator
- U.S. Food and Drug Administration
- What for
- US drug labels that name the condition, with the Drugs@FDA and NDC records of their applications.
- What it receives
- the condition you search, and application and product codes taken from openFDA's own answers
- When
- on lookup
Drybench Cell.
The tour runs entirely in your browser and contacts no host but its own: no scientific service, no analytics, and no fonts or scripts from anywhere else.
The app contacts no host but its own.
Headers
Every app workspace is served with the headers below.
- Connections, workers, images, frames, plug-ins and form targets are limited to the app's own origin and its declared hosts.
- The script policy allows inline scripts, because the pages are pre-rendered and carry the framework's own start-up scripts; a hash or nonce policy would mean rendering every app page on request. A stricter script policy is recorded as a later step.
- WebAssembly compilation is allowed only where an app runs a WebAssembly engine (the RDKit chemistry engine).
- Apps that use the Mol* viewer also allow script evaluation and a data: connection, for the reason given beside their headers; no other app does.
- Web Worker scripts, such as the chemistry engine's, are served from the site's shared static folder without a Content-Security-Policy header, because one header there could not name each app's hosts. The browser therefore does not hold a worker to its app's list; the app's own network code does, and refuses any host its entry does not declare.
Drybench Protein.
These are the exact header values, generated from the app's registry entry.
- Content-Security-Policy
- default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; worker-src 'self' blob:; connect-src 'self' https://rest.uniprot.org https://www.ebi.ac.uk https://data.rcsb.org https://models.rcsb.org https://alphafold.ebi.ac.uk https://api.platform.opentargets.org blob: data:; img-src 'self' data: blob: https://alphafold.ebi.ac.uk; style-src 'self' 'unsafe-inline'; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'
- Referrer-Policy
- no-referrer
- Permissions-Policy
- camera=(), microphone=(), geolocation=(), payment=(), usb=()
- X-Content-Type-Options
- nosniff
- Cross-Origin-Opener-Policy
- same-origin
Drybench Molecule.
These are the exact header values, generated from the app's registry entry.
- Content-Security-Policy
- default-src 'self'; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval'; worker-src 'self' blob:; connect-src 'self' https://pubchem.ncbi.nlm.nih.gov blob:; img-src 'self' data: blob:; style-src 'self' 'unsafe-inline'; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'
- Referrer-Policy
- no-referrer
- Permissions-Policy
- camera=(), microphone=(), geolocation=(), payment=(), usb=()
- X-Content-Type-Options
- nosniff
- Cross-Origin-Opener-Policy
- same-origin
Drybench Pipeline.
These are the exact header values, generated from the app's registry entry.
- Content-Security-Policy
- default-src 'self'; script-src 'self' 'unsafe-inline'; worker-src 'self' blob:; connect-src 'self' https://clinicaltrials.gov https://api.fda.gov blob:; img-src 'self' data: blob:; style-src 'self' 'unsafe-inline'; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'
- Referrer-Policy
- no-referrer
- Permissions-Policy
- camera=(), microphone=(), geolocation=(), payment=(), usb=()
- X-Content-Type-Options
- nosniff
- Cross-Origin-Opener-Policy
- same-origin
Drybench Cell.
These are the exact header values, generated from the app's registry entry.
- Content-Security-Policy
- default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; worker-src 'self' blob:; connect-src 'self' blob: data:; img-src 'self' data: blob:; style-src 'self' 'unsafe-inline'; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'
- Referrer-Policy
- no-referrer
- Permissions-Policy
- camera=(), microphone=(), geolocation=(), payment=(), usb=()
- X-Content-Type-Options
- nosniff
- Cross-Origin-Opener-Policy
- same-origin
Storage on your device
- Projects, notes and settings are kept in this browser's storage (IndexedDB and local storage) on this device.
- Browser storage is not backed up. Clearing site data, a private window, a company policy or the browser's own clean-up can remove it, so export anything you want to keep.
Hosting and logs
- The site is hosted by Vercel. Like any web host, it records requests to the site: IP address, browser, requested address and time.
- The apps' requests to public scientific services go directly from your browser and do not pass through the site's host.
Certifications and questionnaires
- We do not currently hold a formal security certification.
- We do not currently have a formal security questionnaire; we answer supplier questions by email and say plainly which do not apply to browser-only software.
Reporting a security issue
- Email m.beale@me.com with what you found and how to reproduce it. Please leave out personal data and anything confidential.
Next step
Need an app like this built?
These apps were designed and built by Mat Beale. If your team needs a browser tool built on its own data, or one of these tuned to it, get in touch.
Available from September 2026 for full-time roles and selected freelance projects.