Security and regulatory compliance are not features — they are how we build. Validated against the regulations that matter, with a downloadable procurement pack.
We are building our security, availability, processing integrity, confidentiality and privacy practices toward the SOC 2 Type II framework. We have not yet engaged an auditor; formal certification is on our roadmap, and a sample report structure is shareable under MNDA.
Certification plannedWe are aligning our information security practices with ISO 27001:2022 and building the ISMS, control catalogue and risk register the standard requires. We have not yet engaged a certification body; a formal certification audit is planned.
Certification audit plannedProcessing practices designed around GDPR principles, with a redlined DPA template available pre-contract and a publicly maintained sub-processor list. Data separation is logical today — see Data residency below.
DPA template availableRAG-grounded generation and human-in-the-loop signing are live today. Model cards and structured data-lineage documentation are planned as part of our EU AI Act alignment work.
Compliance statement availableValidated electronic records and electronic signatures. Two-component identification per §11.200, computer-generated time-stamped audit trails per §11.10(e), signed records bound to e-signatures per §11.50.
Risk-based validation, signature linking, periodic review, supplier qualification and incident management aligned to EU GMP Annex 11. Pre-built Annex 11 control matrix included.
Lifecycle phases — Concept, Project, Operation, Retirement — modelled in the platform. ISPE GAMP 5 categorisation (1, 3, 4, 5) drives default validation depth.
Attributable, Legible, Contemporaneous, Original, Accurate — plus Complete, Consistent, Enduring, Available. Built into the audit data model.
At provisioning time, each tenant is assigned a logical region tag (US or EU) that determines which database and storage path serves its data. Today this is application-level, logical separation on shared infrastructure — not a guarantee that your data is physically located in a dedicated regional data center.
DPA, MSA and the business case template are downloadable today; SOC 2, ISO 27001 and EU AI Act control documentation is available under NDA on request.
GDPR Art. 28 processor agreement with sub-processor list, EU SCC references and customer instructions schedule.
Standard commercial terms — order form, term, fees, liability, termination — for procurement review.
Structured business case for procurement and validation leadership: scope, benefits, risks, total cost of ownership.
We can provide responses to the major life-sciences security questionnaires — CAIQ, SIG Lite, GxP-VAL, HECVAT — on request under NDA.