Trust Center · trust.eigenomic.com
Security FAQ
Answers are drawn from our published policies. If your question isn't here, email security@eigenomic.com.
Where is our data stored and processed?
Eigenomic builds custom solutions that run inside your own cloud environment — AWS, Azure, or GCP. There is no shared Eigenomic production environment holding customer data; engagement-specific data handling is defined in each contract.
Is data encrypted?
Yes. Our Cryptography Policy requires sensitive and customer data to be encrypted in transit and at rest using industry-standard methods where technically applicable — AES-256 for data at rest and TLS for data crossing public networks — with keys managed through approved key-management services and a documented rotation schedule.
Do you enforce multi-factor authentication?
Yes. Multi-factor authentication is required for privileged access and other systems per our Access Control Policy. Human access to our AWS organization goes through IAM Identity Center (SSO).
How is access to client data controlled?
Access is granted on a need-to-know, least-privilege basis, scoped by role and business need. Privileged activity is logged, access rights are reviewed periodically, and access is revoked promptly on role change or engagement end.
How do you use AI with client data?
Our AI Governance Policy governs every AI system and third-party AI service we use. Third-party AI providers are evaluated against the sensitivity of the data involved, contracts must include security and data-protection clauses, and AI data is segregated from other client and operational data with access restricted and logged.
Do you have a business continuity and disaster recovery plan?
Yes. Our BC/DR Plan defines roles, activation criteria, communication protocols, and recovery strategies for critical services, and is subject to regular testing and review. As a fully remote, cloud-based organization, recovery leans on AWS backup and restoration capabilities.
How long do you retain data?
Only as long as business, legal, and regulatory requirements demand. Our Data Management Policy defines retention by classification, requires secure archival or disposal past retention, and mandates an annual data review.
What happens to our data when the engagement ends?
Customer-owned assets are returned securely after verification that no sensitive data remains, per our Asset Management Policy. Confidentiality obligations on our personnel survive the end of the engagement where required by agreement or law.
Are you SOC 2 certified?
SOC 2 Type II preparation is underway. Our security policies are written against SOC 2 security objectives, and this page will be updated when the audit completes.
Do contractors have the same obligations as employees?
Yes. Our policies apply to employees, contractors, and third parties working on Eigenomic's behalf. Contractors must acknowledge the Code of Conduct requirements applicable to them, including confidentiality and information-security obligations.
How do I report a security concern?
Email security@eigenomic.com. Suspected security incidents are handled through our established incident reporting procedures.