21 CFR Part 11 · EU GMP Annex 11 · GAMP 5 · ALCOA+
We follow the guidelines of SOC 2 Type II · ISO 27001 · EU AI Act
Security & Trust

The controls auditors actually look for.

Security and regulatory compliance are not features — they are how we build. Validated against the regulations that matter, with a downloadable procurement pack.

01 — Certifications

Aligned to the controls auditors look for. Documentation shareable under MNDA.

SOC 2

Aligned with SOC 2 Type II control objectives

We are building our security, availability, processing integrity, confidentiality and privacy practices toward the SOC 2 Type II framework. We have not yet engaged an auditor; formal certification is on our roadmap, and a sample report structure is shareable under MNDA.

Certification planned
ISO 27001

Aligned with ISO 27001 control objectives

We are aligning our information security practices with ISO 27001:2022 and building the ISMS, control catalogue and risk register the standard requires. We have not yet engaged a certification body; a formal certification audit is planned.

Certification audit planned
GDPR

GDPR-aligned data protection

Processing practices designed around GDPR principles, with a redlined DPA template available pre-contract and a publicly maintained sub-processor list. Data separation is logical today — see Data residency below.

DPA template available
EU AI Act

High-risk system practices

RAG-grounded generation and human-in-the-loop signing are live today. Model cards and structured data-lineage documentation are planned as part of our EU AI Act alignment work.

Compliance statement available
02 — Regulatory alignment

Built against the regulations validation teams actually defend.

21 CFR 11

FDA Part 11 ready

Validated electronic records and electronic signatures. Two-component identification per §11.200, computer-generated time-stamped audit trails per §11.10(e), signed records bound to e-signatures per §11.50.

EU GMP

Annex 11 aligned

Risk-based validation, signature linking, periodic review, supplier qualification and incident management aligned to EU GMP Annex 11. Pre-built Annex 11 control matrix included.

GAMP 5

GAMP 5 (2nd ed.) v-model

Lifecycle phases — Concept, Project, Operation, Retirement — modelled in the platform. ISPE GAMP 5 categorisation (1, 3, 4, 5) drives default validation depth.

ALCOA+

Data integrity by default

Attributable, Legible, Contemporaneous, Original, Accurate — plus Complete, Consistent, Enduring, Available. Built into the audit data model.

03 — Controls

Six categories, twenty-four controls — some live today, others on our roadmap.

Encryption

  • Data at restNot encrypted per-tenant today; AES-256 per-tenant encryption at rest and customer-managed keys (BYOK) are on our roadmap.
  • Data in transitTLS 1.3 and HSTS on all endpoints
  • BackupsRegular on-host backups today; separate KMS-managed encryption and geo-redundant storage are planned.
  • SecretsNo long-lived credentials in code paths; secrets provided via environment configuration

Identity

  • AuthenticationJWT-backed sessions with Argon2id password hashing
  • MFATOTP available; enforcement is an account-wide toggle, not limited to privileged roles
  • SessionsConfigurable timeout and idle lock
  • Account modelAccount ▸ Tenant scoping; user lifecycle managed in-app

Access control

  • RBACTenant-scoped roles with least-privilege defaults
  • Separation of DutiesEnforced at workflow layer — author ≠ approver
  • Privileged accessAccount/system admin bypass access exists today; reason-code logging for that access is being rolled out.
  • Customer supportPrivileged admin access exists today — it is not zero-standing; we are bringing it under reason-code audit logging.

Monitoring

  • Audit logAppend-only event capture across all GxP entities
  • Tamper-evidenceHash-anchored audit entries with periodic verification
  • Inspector exportsOn-demand audit bundle export (DOCX / PDF / JSON)
  • Status pagePublic status page not yet available; planned.

Resilience

  • Uptime SLANo contractual uptime SLA today; reliability targets are on our roadmap.
  • RPO / RTONo formal RPO/RTO commitments today; disaster-recovery targets are in development.
  • DR drillsNot yet formalized; planned as part of our resilience roadmap.
  • BackupsDeploy-triggered on-host backups, retained ~10 most recent; longer retention and off-site copies are planned.

AppSec

  • SDLCCode review before merge, automated dependency auditing and secret scanning in CI; SAST/DAST automation is planned.
  • Pen testsInternal security review checklist today; independent third-party penetration testing is planned. No bug bounty program.
  • DependenciesAutomated dependency vulnerability scanning in CI; SBOM publication and a formal CVE response SLA are planned.
  • Secret hygieneNo long-lived credentials in code paths
04 — Data residency

Logical data separation, not physical regions.

At provisioning time, each tenant is assigned a logical region tag (US or EU) that determines which database and storage path serves its data. Today this is application-level, logical separation on shared infrastructure — not a guarantee that your data is physically located in a dedicated regional data center.

RegionSeparationWhat this means today
US (logical)Logical DB/storage partitionLogically separated by database and storage path. No physically dedicated US data center today.
EU (logical)Logical DB/storage partitionLogically separated by database and storage path. Data is not currently held in a physically distinct EU data center — ask us about our physical-residency roadmap.
05 — Procurement pack

The paperwork your CFO and InfoSec lead will ask for.

DPA, MSA and the business case template are downloadable today; SOC 2, ISO 27001 and EU AI Act control documentation is available under NDA on request.

Vendor qualification

Bring your security questionnaire. We'll fill it in.

We can provide responses to the major life-sciences security questionnaires — CAIQ, SIG Lite, GxP-VAL, HECVAT — on request under NDA.