Solution Briefs

Built to Clear Your Security Review

A security review should not become a prolonged exercise in locating evidence. It should begin with clear answers about controls, certifications, hosting, encryption, isolation, and governance.

For teams evaluating a new R&D, quality, or product-development platform, security diligence often involves multiple stakeholders with different concerns. IT needs architectural detail, security teams need control evidence, and business teams need confidence that the review will not delay an important transformation initiative.

Uncountable provides a security foundation designed for enterprise evaluation: SOC 2 Type II and ISO 27001 audits, AES-256 encryption, schema-level tenant isolation, regional and customer-VPC hosting options, and an information-security management system supported by more than 50 documented policies.

This solution brief is for security, IT, procurement, and platform-evaluation teams assessing how Uncountable protects customer data and supports enterprise security requirements.

Inside this solution brief:

  • The role of SOC 2 Type II and ISO 27001 assurance
  • How AES-256 encryption protects stored customer data
  • What schema-level tenant isolation means for customer environments
  • Regional and customer-VPC hosting options
  • The governance structure behind Uncountable’s security controls

Clear the security review with evidence that is ready when your reviewers need it.

FAQs

Is Uncountable SOC 2 certified?

Yes. Uncountable holds SOC 2 Type II certification for Security and Availability, audited annually by an independent CPA firm. The full report is available on request under NDA.

Where is Uncountable data stored?

Uncountable runs on AWS with deployments in the United States, the EU and Japan. Customers choose their region, and single-tenant and customer-VPC deployments are available, where you manage your own encryption keys.

Does Uncountable use customer data to train AI models?

No. Formulation data, models and insights are never shared between customers or used to train foundation models. Bodie runs inside your tenant under role-based access and a dedicated AI security policy.

How does Uncountable keep our data separate from other customers?

Every customer's data sits in its own database schema, with no shared tables and no combined datasets. Isolation is confirmed as part of the SOC 2 audit and is committed to contractually.

Does Uncountable support GxP validation and 21 CFR Part 11?

Yes. Uncountable is a GAMP 5 Category 4 system aligned to 21 CFR Part 11 and EU GMP Annex 11, and ships a validation kit with every quarterly release so regulated teams inherit the evidence rather than repeating the effort.

See the Platform Behind the Guide

Uncountable connects R&D, quality, and product lifecycle data in one platform. Book a personalized demo and we'll show you how it applies to your lab.