Trust Center · trust.eigenomic.com
Controls
These controls are self-attested against our published policies; our SOC 2 audit will provide independent verification.
Infrastructure security
| Dedicated AWS account per client and product | Every client engagement and every Eigenomic product runs in its own AWS member account under AWS Organizations, so workloads are isolated from each other and from the management account.Source: Access Control Policy | |
| SSO with MFA for AWS access | Human access to AWS goes through IAM Identity Center (SSO); multi-factor authentication is required for privileged access in line with our authentication standards.Source: Access Control Policy | |
| Least-privilege, need-to-know access | Access to cloud resources, systems, and data is granted on a need-to-know and least-privilege basis, scoped by business need, role, and risk.Source: Access Control Policy | |
| Encryption at rest | Sensitive and customer data at rest is encrypted with industry-standard algorithms (AES-256), with keys managed through approved key-management services.Source: Cryptography Policy | |
| Encryption in transit | Confidential and sensitive data is encrypted with secure transport protocols (TLS) whenever it crosses public networks.Source: Cryptography Policy | |
| Managed key lifecycle | Cryptographic keys are generated, stored, rotated, and destroyed under a documented key-management matrix, with key usage logged for audit.Source: Cryptography Policy |
Organizational security
| Code of Conduct acknowledged by all personnel | Employees and contractors acknowledge the Code of Conduct, which carries confidentiality, information-security, and ethics obligations; violations carry defined consequences.Source: Code of Conduct | |
| Confidentiality survives the engagement | Confidentiality obligations for company, customer, and legal-client information continue after employment or an engagement ends, where required by agreement or law.Source: Code of Conduct | |
| Asset inventory maintained | Assets material to operations or information security are inventoried with an assigned owner, location, and status, reviewed periodically for accuracy.Source: Asset Management Policy | |
| Secure media disposal | Data and devices at end of life are sanitized with secure wiping or physical destruction, and disposal is documented.Source: Asset Management Policy | |
| Remote work security expectations | As a fully remote organization, personnel must keep a reasonably secure work environment and protect company and customer information from unauthorized viewing or access.Source: Code of Conduct |
Engagement & product security
| Solutions run in the customer's cloud | Eigenomic builds custom solutions that deploy inside each customer's own AWS, Azure, or GCP environment; engagement-specific data handling is defined per contract.Source: Data Management Policy | |
| Customer access is scoped and logged | Customers receive access only to the services and data their engagement requires; access is authenticated, authorized, logged, and periodically reviewed.Source: Access Control Policy | |
| Source code access restricted | Program source code lives in secure, access-controlled repositories; access must be justified, documented, and periodically reviewed.Source: Access Control Policy | |
| Secure development for AI systems | Secure coding practices and threat modeling are integrated into the AI development lifecycle, with models and algorithms reviewed against emerging threats.Source: AI Governance Policy |
Internal security procedures
| BC/DR plan established | A business continuity and disaster recovery plan defines roles, activation criteria, communication protocols, and recovery strategies for critical services.Source: Business Continuity & Disaster Recovery Plan | |
| BC/DR plan tested and reviewed | The BC/DR plan is subject to regular testing, review, and updates, with results documented and used to improve recovery procedures.Source: Business Continuity & Disaster Recovery Plan | |
| Periodic access reviews | User accounts and access rights are reviewed at a frequency appropriate to risk; deviations and excess privileges are corrected immediately.Source: Access Control Policy | |
| Prompt access revocation | Access rights are adjusted or removed promptly on role change, termination, or contract completion, as part of documented offboarding.Source: Access Control Policy | |
| Privileged access monitored | Privileged accounts are restricted to roles that require them, and privileged activity is logged and periodically reviewed.Source: Access Control Policy | |
| Documented exceptions only | Any exception to a security policy must be formally documented, risk-assessed, approved by the policy owner, and periodically re-reviewed.Source: Access Control Policy |
Data and privacy
| Data classification established | Data is classified as Confidential, Restricted, or Public, with handling requirements defined for each level, including encryption for confidential data.Source: Data Management Policy | |
| Retention limited to need | Data is retained only as long as business, legal, and regulatory requirements demand, with periodic review of retention schedules.Source: Data Management Policy | |
| Secure deletion | Sensitive data past its retention period is rendered unrecoverable through certified wiping or physical destruction, with disposal documented.Source: Data Management Policy | |
| Annual data review | An annual review validates data classification accuracy, retention compliance, and identifies outdated or redundant information.Source: Data Management Policy | |
| Customer assets returned securely | Customer-owned assets are managed with heightened confidentiality and returned securely at service completion, after verifying no sensitive data remains.Source: Asset Management Policy |
AI governance
| AI governance owned by the CISO | A dedicated AI Governance Policy covers LLMs, AI-enabled automation, and third-party AI services, with governance owned by the CISO.Source: AI Governance Policy | |
| Third-party AI providers evaluated | AI vendors are evaluated against the sensitivity of the data involved, and contracts must include security and data-protection clauses with breach-notification requirements.Source: AI Governance Policy | |
| AI data segregated and access-controlled | AI training, validation, and production data is segregated from other client and operational data, with access restricted and audit-logged.Source: AI Governance Policy | |
| AI risk assessments | AI systems get regular risk assessments covering vulnerabilities, data privacy, and model integrity, with mitigations that can include testing, human review, and monitoring.Source: AI Governance Policy | |
| Change management for AI systems | Modifications to AI systems and third-party integrations go through formal change management, including impact analysis and rollback procedures.Source: AI Governance Policy |