Security & Trust

Private by Design, Yours by Contract

Your sequences are among your most valuable IP. Orbion is built so they stay private, never train our models, and remain entirely yours, under an ISO/IEC 27001-certified information security management system. Every part of that is in writing for your IT and legal teams.

  • ISO/IEC 27001:2022 CertifiedCertified by Tempo Audits Ltd
  • GDPR CompliantEU processing, DPA with SCCs
Inference-Only EU-Hosted Full IP Ownership Tenant-Isolated

The promise

Three Commitments We Don't Move On

Everything below follows from these. If any one of them can't hold for your program, we'd rather tell you now.

Never Trained on Your Data

We run inference on your sequences. We don't train or fine-tune on your data, and nothing crosses between customers.

You Keep Your IP

Every prediction, construct, and result is yours. No royalties, no milestones, no claim on what you discover.

Hosted in the EU

Processed and stored on EU-based infrastructure, and removed on request or at the end of an engagement.

Follow the data

What Happens to a Sequence You Upload

One direction, four checkpoints. No step feeds your data back into our models, and every step has a safeguard your reviewers can name.

1 · You Upload

A sequence comes in over an encrypted connection.

Encrypted in Transit

2 · It's Isolated

It lands in your organization's own workspace, separated from every other customer.

Tenant-Isolated

3 · We Infer

Our models score it. It is never added to any training set.

Never Trained On

4 · You Get Results

Predictions and reports, encrypted at rest and exportable.

Yours to Keep

5 · You Can Delete

Removed on request or at the end of the engagement, with confirmation.

Deleted on Request

Encrypted In Transit And At Rest · EU Processing · Logical Tenant Isolation · Least-Privilege Internal Access

For your reviewers

Answers for the People Who Sign Off

Two teams usually gate a new vendor. Here's what each one needs — up front, before you have to ask.

For Your IT Team

Infrastructure, access, and controls

  • ISO/IEC 27001-Certified ISMS
  • Encrypted In Transit (TLS) And At Rest
  • Hosted On EU-Based Cloud Infrastructure
  • Per-Organization, Logically Isolated Workspaces
  • Least-Privilege, Logged Internal Access
  • Documented Incident Response And Breach Notification
  • Enterprise SSO (SAML / OIDC) On The Roadmap

For Your Legal Team

Contracts, data protection, and IP

  • GDPR-Compliant DPA, With SCCs Where Relevant
  • Full IP Ownership — No Royalties Or Milestones
  • Sub-Processor Register Available On Request
  • EU Data Residency
  • Retention & Deletion Terms Set Out In The DPA
  • CDA / NDA Available Before You Upload

Where we stand

Certifications

What's in place today, and what's on the roadmap. The certificate, the Statement of Applicability, and the supporting artifacts are available under NDA for your security review.

ISO/IEC 27001:2022
Tempo Audits Ltd, UKAS-Accredited · Valid To 24 August 2029
Certified
GDPR Compliance Program
Records Of Processing, DPIA Process, Data-Subject-Request Workflow
Available
Data Processing Agreement (DPA)
EU Data Protection; SCCs Where Relevant
On request
EU Data Residency
Processed And Stored On EU-Based Infrastructure
Available
Sub-Processor Register
Current List Of Infrastructure Sub-Processors
On request
Internal Audit & Management Review
Run On The ISMS Cycle Required By The Standard
Available
SOC 2
On The Roadmap After ISO 27001
Planned
Penetration Testing
Third-Party Testing Planned; Summary Shareable When Available
Planned

Certified scope

The ISMS covers the people, processes, systems, vendors, facilities and information assets used to operate, secure and support Orbion's protein engineering SaaS platform, production APIs, ML compute workflows, customer support operations and supporting business operations.

Certificate TA-01-OG-240826Issued 24 August 2026Valid until 24 August 2029Issued by Tempo Audits Ltd (UKAS 29621)Verify on UKAS CertCheck

Issued to Orbion GmbH. Statement of Applicability Version 2, dated 14 August 2026, available under NDA.

Painless Vendor Security Review

Ask for our security package under NDA: the ISO 27001 certificate and Statement of Applicability, our DPA, the sub-processor list, and a completed security questionnaire.