Compliant by design. Audited by default.
We built inscinstech.ai with biopharma compliance as a primary engineering constraint — not a checkbox added later.
Compliance matrix.
Certified · in progress · planned — status is fully transparent.
| Certification | Status | Document |
|---|---|---|
| PIPL (China) | Compliant | Download privacy whitepaper → |
| GDPR (EU) | Compliant | Download DPA template → |
| CCPA (California) | Compliant | Download CA privacy notice → |
| 21 CFR Part 11 (US) | Ready · Q3 2026 | Architecture overview → |
| China MLPS 2.0 L3 | In progress | Expected M5 |
| SOC 2 Type II | In progress | Expected M8 · request status → |
| ISO 27001 | Planned | Expected M12 |
| HIPAA | Roadmap | Available on Enterprise |
Anything we haven't earned yet is labeled "in progress" or "planned". We don't overclaim.
How we handle customer data.
Five principles cover isolation · training · encryption · residency · audit.
Customer data isolation
- Per-tenant K8s namespace
- Postgres row-level security
- Milvus namespace isolation
No training on customer data
- Contractually guaranteed
- Enterprise opt-in available
Encryption
- At rest: AES-256
- In transit: TLS 1.3
- Per-tenant KMS keys (Enterprise)
Data residency
- CN data stays in China (Alibaba Cloud Shanghai)
- EU data stays in EU (AWS Frankfurt)
- APAC data stays in APAC (AWS Tokyo)
- Cross-region replication is opt-in per workspace
Audit & retention
- Immutable audit logs (Temporal-backed)
- 7-year retention for Enterprise (GxP-ready)
- Customer can export logs at any time
Security architecture whitepaper.
7-layer architecture · multi-region deployment · LLM routing · data isolation details — full PDF whitepaper available (email registration).
Download security whitepaperIncident response.
- 24/7 monitoring (Sentry + Grafana + Loki)
- SLA: 1-hour acknowledgment · 4-hour mitigation · 24-hour postmortem
- Public status page: status.inscinstech.ai
- Past incidents and postmortems published
Vendor sub-processors (GDPR-required disclosure).
Every third-party service we use, publicly listed per GDPR. All have a DPA in place.
| Vendor | Purpose | Region | DPA |
|---|---|---|---|
| AWS | Hosting (global) | Multi | Available |
| Alibaba Cloud | Hosting (CN) | Shanghai | Available |
| Anthropic | LLM inference | Multi | Available |
| DeepSeek | LLM inference | CN / Global | Available |
| Cloudflare | DNS / CDN / WAF | Multi | Available |
| Stripe | Payments (global) | Multi | Available |
| Sentry | Error monitoring | EU | Available |
Anthropic and DeepSeek are LLM backends — customer data is sent under zero-retention contracts and never enters training.
Bug bounty · responsible disclosure.
Submit vulnerability disclosures to security@inscinstech.ai. PGP key available for sensitive reports. Rewards: $100–$5,000 depending on severity.
security@inscinstech.aiNeed deeper compliance material?
Pull the security whitepaper, request a SOC 2 report, or talk to our compliance team directly.