Trust & compliance
Built to be audited.
Public sources in, cited and tamper-evident verdicts out. Here's exactly how we handle your data, our compliance posture, and the proof behind it.
Part 11 hash-chained audit trail on every run.
Compliance posture
Honest about status
What is implemented today, what is a stated design posture, and what is still in progress. We never imply a certification is complete.
- Implemented
21 CFR Part 11
Tamper-evident, hash-chained audit trail on every run.
Every feasibility run writes an append-only, hash-chained audit record (electronic records & signatures). Each entry references the cryptographic hash of the prior entry, so any retroactive edit breaks the chain and is detectable. Citations, inputs, scorer versions, and outputs are all captured in the chain.
How the audit chain works → - Posture
HIPAA
No PHI required — engine runs on public data and de-identified protocol inputs.
The feasibility engine is designed to operate on public data sources and protocol-level (non-patient) inputs, so Protected Health Information is not required to produce a verdict. Where customers choose to transmit regulated data, transport is encrypted (TLS) and storage is encrypted at rest (AES-256). This is a stated posture, not a third-party HIPAA attestation.
- Posture
GDPR
Data-minimisation by design; EU data-handling alignment.
We follow data-minimisation principles: only the protocol inputs needed to run scorers are processed, and outputs cite public sources. Data-subject and processing terms are addressed contractually. This reflects our design posture and DPA commitments, not a supervisory-authority certification.
- In progress
SOC 2 Type II
Audit underway — report not yet issued.
We are actively pursuing a SOC 2 Type II examination. Controls are being implemented and evidenced; the independent report has not yet been issued. We will publish the report status here when available. We do not claim SOC 2 compliance today.
- Implementedthe control exists and is verifiable in-product today
- Posturea stated design posture, not an external audit
- In progresswork underway, not yet attained
Data handling
Your protocol stays yours
Three commitments that govern how your inputs are processed.
We never train on your data
Protocols you submit are not used to train or fine-tune any model.
Open models, EU inference
Extraction runs on open-weight models (Qwen / Gemma) hosted for us in the EU; your protocol is never sent to a consumer or general-purpose model API such as OpenAI, Anthropic, or Google.
Per-tenant isolation
Your runs, citations, and audit chain are isolated to your tenant.
Provenance & audit
Every number is a citation. Every verdict is hash-chained.
Each feasibility verdict cites the public source behind every figure, then is hashed into a 21 CFR Part 11 tamper-evident chain you can export and replay.
Cited
Every figure carries the public source, the query behind it, and the snapshot date it was read on.
Hashed
Citations, inputs, scorer versions, and outputs are written to an append-only record; each entry references the cryptographic hash of the entry before it.
Replayable
Export the chain and replay the run. Any retroactive edit breaks the chain and is detectable.
ENDO-2b · Endometriosis Phase 2b
Feasibility verdict · every number cited
- [1] Open Targets
- [2] AACT
- [3] ClinicalTrials.gov
- [4] PubMed 30295701
Click any figure to inspect the source, the query, and the snapshot date behind it.
Data sources
Powered by public data
Every cited number traces back to one of these public, stewarded sources — no proprietary black boxes.
- ClinicalTrials.govU.S. National Library of Medicine
- PubMedNCBI / U.S. National Library of Medicine
- FDAU.S. Food & Drug Administration
- EMAEuropean Medicines Agency
- Open TargetsOpen Targets Consortium
- AACTClinical Trials Transformation Initiative (CTTI)
- ChEMBLEMBL-EBI
These 7 backbone registries are part of ~50 live connectors feeding the engine.