Skip to main content
SECURITY · TRUST · 安全与信任

Compliant by design. Audited by default.

We built inscinstech.ai with biopharma compliance as a primary engineering constraint — not a checkbox added later.

01 — COMPLIANCE

Compliance matrix.

Certified · in progress · planned — status is fully transparent.

CertificationStatusDocument
PIPL (China)CompliantDownload privacy whitepaper →
GDPR (EU)CompliantDownload DPA template →
CCPA (California)CompliantDownload CA privacy notice →
21 CFR Part 11 (US)Ready · Q3 2026Architecture overview →
China MLPS 2.0 L3In progressExpected M5
SOC 2 Type IIIn progressExpected M8 · request status →
ISO 27001PlannedExpected M12
HIPAARoadmapAvailable on Enterprise

Anything we haven't earned yet is labeled "in progress" or "planned". We don't overclaim.

02 — DATA HANDLING

How we handle customer data.

Five principles cover isolation · training · encryption · residency · audit.

01

Customer data isolation

  • Per-tenant K8s namespace
  • Postgres row-level security
  • Milvus namespace isolation
02

No training on customer data

  • Contractually guaranteed
  • Enterprise opt-in available
03

Encryption

  • At rest: AES-256
  • In transit: TLS 1.3
  • Per-tenant KMS keys (Enterprise)
04

Data residency

  • CN data stays in China (Alibaba Cloud Shanghai)
  • EU data stays in EU (AWS Frankfurt)
  • APAC data stays in APAC (AWS Tokyo)
  • Cross-region replication is opt-in per workspace
05

Audit & retention

  • Immutable audit logs (Temporal-backed)
  • 7-year retention for Enterprise (GxP-ready)
  • Customer can export logs at any time
03 — ARCHITECTURE

Security architecture whitepaper.

7-layer architecture · multi-region deployment · LLM routing · data isolation details — full PDF whitepaper available (email registration).

Download security whitepaper
04 — INCIDENT RESPONSE

Incident response.

  • 24/7 monitoring (Sentry + Grafana + Loki)
  • SLA: 1-hour acknowledgment · 4-hour mitigation · 24-hour postmortem
  • Public status page: status.inscinstech.ai
  • Past incidents and postmortems published
05 — SUB-PROCESSORS

Vendor sub-processors (GDPR-required disclosure).

Every third-party service we use, publicly listed per GDPR. All have a DPA in place.

VendorPurposeRegionDPA
AWSHosting (global)MultiAvailable
Alibaba CloudHosting (CN)ShanghaiAvailable
AnthropicLLM inferenceMultiAvailable
DeepSeekLLM inferenceCN / GlobalAvailable
CloudflareDNS / CDN / WAFMultiAvailable
StripePayments (global)MultiAvailable
SentryError monitoringEUAvailable

Anthropic and DeepSeek are LLM backends — customer data is sent under zero-retention contracts and never enters training.

06 — RESPONSIBLE DISCLOSURE

Bug bounty · responsible disclosure.

Submit vulnerability disclosures to security@inscinstech.ai. PGP key available for sensitive reports. Rewards: $100–$5,000 depending on severity.

security@inscinstech.ai

Need deeper compliance material?

Pull the security whitepaper, request a SOC 2 report, or talk to our compliance team directly.

Download security whitepaperRequest SOC 2 reportTalk to compliance
Security & Trust · Compliant by design | inscinstech.ai