Controls

SOC 2 Type II — preparation underway

Controls

These controls are self-attested against our published policies; our SOC 2 audit will provide independent verification.

Infrastructure security

Last reviewed: 2026-07-31
Dedicated AWS account per client and product Every client engagement and every Eigenomic product runs in its own AWS member account under AWS Organizations, so workloads are isolated from each other and from the management account.Source: Access Control Policy
SSO with MFA for AWS access Human access to AWS goes through IAM Identity Center (SSO); multi-factor authentication is required for privileged access in line with our authentication standards.Source: Access Control Policy
Least-privilege, need-to-know access Access to cloud resources, systems, and data is granted on a need-to-know and least-privilege basis, scoped by business need, role, and risk.Source: Access Control Policy
Encryption at rest Sensitive and customer data at rest is encrypted with industry-standard algorithms (AES-256), with keys managed through approved key-management services.Source: Cryptography Policy
Encryption in transit Confidential and sensitive data is encrypted with secure transport protocols (TLS) whenever it crosses public networks.Source: Cryptography Policy
Managed key lifecycle Cryptographic keys are generated, stored, rotated, and destroyed under a documented key-management matrix, with key usage logged for audit.Source: Cryptography Policy

Organizational security

Last reviewed: 2026-07-31
Code of Conduct acknowledged by all personnel Employees and contractors acknowledge the Code of Conduct, which carries confidentiality, information-security, and ethics obligations; violations carry defined consequences.Source: Code of Conduct
Confidentiality survives the engagement Confidentiality obligations for company, customer, and legal-client information continue after employment or an engagement ends, where required by agreement or law.Source: Code of Conduct
Asset inventory maintained Assets material to operations or information security are inventoried with an assigned owner, location, and status, reviewed periodically for accuracy.Source: Asset Management Policy
Secure media disposal Data and devices at end of life are sanitized with secure wiping or physical destruction, and disposal is documented.Source: Asset Management Policy
Remote work security expectations As a fully remote organization, personnel must keep a reasonably secure work environment and protect company and customer information from unauthorized viewing or access.Source: Code of Conduct

Engagement & product security

Last reviewed: 2026-07-31
Solutions run in the customer's cloud Eigenomic builds custom solutions that deploy inside each customer's own AWS, Azure, or GCP environment; engagement-specific data handling is defined per contract.Source: Data Management Policy
Customer access is scoped and logged Customers receive access only to the services and data their engagement requires; access is authenticated, authorized, logged, and periodically reviewed.Source: Access Control Policy
Source code access restricted Program source code lives in secure, access-controlled repositories; access must be justified, documented, and periodically reviewed.Source: Access Control Policy
Secure development for AI systems Secure coding practices and threat modeling are integrated into the AI development lifecycle, with models and algorithms reviewed against emerging threats.Source: AI Governance Policy

Internal security procedures

Last reviewed: 2026-07-31
BC/DR plan established A business continuity and disaster recovery plan defines roles, activation criteria, communication protocols, and recovery strategies for critical services.Source: Business Continuity & Disaster Recovery Plan
BC/DR plan tested and reviewed The BC/DR plan is subject to regular testing, review, and updates, with results documented and used to improve recovery procedures.Source: Business Continuity & Disaster Recovery Plan
Periodic access reviews User accounts and access rights are reviewed at a frequency appropriate to risk; deviations and excess privileges are corrected immediately.Source: Access Control Policy
Prompt access revocation Access rights are adjusted or removed promptly on role change, termination, or contract completion, as part of documented offboarding.Source: Access Control Policy
Privileged access monitored Privileged accounts are restricted to roles that require them, and privileged activity is logged and periodically reviewed.Source: Access Control Policy
Documented exceptions only Any exception to a security policy must be formally documented, risk-assessed, approved by the policy owner, and periodically re-reviewed.Source: Access Control Policy

Data and privacy

Last reviewed: 2026-07-31
Data classification established Data is classified as Confidential, Restricted, or Public, with handling requirements defined for each level, including encryption for confidential data.Source: Data Management Policy
Retention limited to need Data is retained only as long as business, legal, and regulatory requirements demand, with periodic review of retention schedules.Source: Data Management Policy
Secure deletion Sensitive data past its retention period is rendered unrecoverable through certified wiping or physical destruction, with disposal documented.Source: Data Management Policy
Annual data review An annual review validates data classification accuracy, retention compliance, and identifies outdated or redundant information.Source: Data Management Policy
Customer assets returned securely Customer-owned assets are managed with heightened confidentiality and returned securely at service completion, after verifying no sensitive data remains.Source: Asset Management Policy

AI governance

Last reviewed: 2026-07-31
AI governance owned by the CISO A dedicated AI Governance Policy covers LLMs, AI-enabled automation, and third-party AI services, with governance owned by the CISO.Source: AI Governance Policy
Third-party AI providers evaluated AI vendors are evaluated against the sensitivity of the data involved, and contracts must include security and data-protection clauses with breach-notification requirements.Source: AI Governance Policy
AI data segregated and access-controlled AI training, validation, and production data is segregated from other client and operational data, with access restricted and audit-logged.Source: AI Governance Policy
AI risk assessments AI systems get regular risk assessments covering vulnerabilities, data privacy, and model integrity, with mitigations that can include testing, human review, and monitoring.Source: AI Governance Policy
Change management for AI systems Modifications to AI systems and third-party integrations go through formal change management, including impact analysis and rollback procedures.Source: AI Governance Policy