Before you paste a sequence into any tool, you ask the quiet question: where does this go, and who can see it? For a protein engineer that is not paranoia. Your constructs, your assay results, and your target identities are often the most valuable thing your program owns. We built Orbion to handle exactly that kind of data, so we held ourselves to a standard an outside auditor could check. Orbion is now certified to ISO/IEC 27001:2022, the international standard for information security management.
Key Takeaways
- Orbion GmbH is certified to ISO/IEC 27001:2022, the recognized international standard for managing information security.
- The independent Stage 2 audit returned zero nonconformities. For a first-time certification, that is a strong result.
- The audit was independent. Tempo Audits ran the certification audit. Kantis provided the compliance platform and support, and did not audit us.
- Your data sits in our most protected tier. Customer sequences, structures, experimental data, and target identities are classified and handled at the highest level in our security management system.
An Independent Result
Certification audits run in two stages. Stage 1 checks that the security management system is documented and ready. Stage 2 tests whether the controls actually work. A nonconformity is a finding where the auditor judges that you fall short of a requirement. Our Stage 2 audit, conducted by Tempo Audits, returned zero.
As Aniruddh Goteti, Co-Founder and MD at Orbion, put it:
"Protecting our customers' data is a responsibility we take seriously. Working with Kantis, we achieved ISO/IEC 27001 certification with zero nonconformities in our independent Stage 2 audit, conducted by Tempo Audits."
The separation of roles is what makes the result credible. Kantis gave us the platform and support to move quickly, but Kantis did not grade the exam. The people who helped us prepare were not the people who signed off.
Why It Matters For Protein Work
When you run a sequence through Orbion, you hand over information that can reveal a program's direction long before anything is published: a target identity, a set of stabilizing mutations, a developability profile on a lead. Some of it is pre-patent, where a leak can cost a filing.
So we classify customer-submitted material at the most restricted tier in our system, with the handling rules that tier requires. Orbion is fully computational, which keeps the scope clean. There is no wet lab and no physical custody of your material. The only question is how your data is stored, accessed, and protected inside the platform, and that is exactly what the certification addresses.
Certification is not a one-time checkbox. ISO 27001 requires ongoing risk assessment, internal audit, and surveillance audits in the years that follow, so the standard has to hold over time, not just on audit day.
Bottom Line
If you are deciding whether to trust a computational platform with sensitive protein data, ISO 27001 answers a question an independent party already asked on your behalf. Zero nonconformities, an independent auditor, and your data handled at the most protected tier we have.
If your diligence, procurement, or security team needs documentation, our security page links to our certificate and to how we handle data. Reach out from there and we will get you what you need.



