Built to Clear Your Security Review
Formulation data is the most valuable thing an R&D organization owns, which is why a platform decision usually stops at the security review. The questionnaire arrives, and the answers sit in four places: an audit report, a policy library, an architecture diagram, and someone's memory. Weeks pass while a deal that has already been won waits for a document.
Uncountable holds SOC 2 Type II certification and ISO 27001, audited annually by independent firms, alongside GxP and HIPAA alignment and GDPR compliance. Customer data is encrypted with AES-256 at rest and TLS 1.2+ in transit, and isolated at the database schema level, so no two customers share a schema and no formulation data, model, or insight is ever reused across accounts or used to train foundation models. The platform runs on AWS in US, EU and Japan regions, with multi-AZ high availability, daily snapshots replicated across regions, and the option to deploy inside your own VPC where you manage your own encryption keys.
Behind those controls is a documented information security management system of more than 50 policies, covering risk management, secure development, change management, personnel screening and training, incident response, and business continuity, reviewed on an annual cycle. Bodie runs inside your tenant under a dedicated AI security policy. Access is role-based, need-to-know internally, and every action is captured in admin and entity-level audit logs. What your security team asks for, we can hand over: the SOC 2 report, the penetration test summary, the DPA and sub-processor list, a completed CAIQ or SIG, and the GxP Validation Master Plan.
Isolated per customer. Encrypted end to end. Fully auditable.
FAQs
Yes. Uncountable holds SOC 2 Type II certification for Security and Availability, audited annually by an independent CPA firm. The full report is available on request under NDA.
Uncountable runs on AWS with deployments in the United States, the EU and Japan. Customers choose their region, and single-tenant and customer-VPC deployments are available, where you manage your own encryption keys.
No. Formulation data, models and insights are never shared between customers or used to train foundation models. Bodie runs inside your tenant under role-based access and a dedicated AI security policy.
Every customer's data sits in its own database schema, with no shared tables and no combined datasets. Isolation is confirmed as part of the SOC 2 audit and is committed to contractually.
Yes. Uncountable is a GAMP 5 Category 4 system aligned to 21 CFR Part 11 and EU GMP Annex 11, and ships a validation kit with every quarterly release so regulated teams inherit the evidence rather than repeating the effort.
