TRUST CENTER

Security, privacy, and compliance at DNACHAIN.

This page is maintained by DNACHAIN to answer common security and privacy questions about the platform. It describes the technical controls we operate today, the sub-processors we rely on, and where the compliance responsibility is shared with you as the customer. It is not an independent certification.

Shared responsibility. DNACHAIN provides platform controls. Regulatory compliance (HIPAA, 21 CFR Part 11, GxP, GDPR, CLIA/CAP) always requires customer SOPs, training, and — where applicable — a signed BAA or DPA. We do not attest to your organization's compliance on your behalf.

Compliance posture

21 CFR Part 11

Controls

Technical controls for electronic records: immutable audit trail, per-actor attribution, Ed25519-signed exports. Customer is responsible for SOP and validation.

HIPAA

Controls

Technical safeguards: encryption at rest and in transit, RLS-enforced access, audit logging. BAA available on Professional and Enterprise.

GDPR

Controls

Consent versioning, DB-enforced withdrawal cascade, data export and erasure workflows. Sub-processors listed on the Trust page.

SOC 2 Type II

Controls

Trust-services criteria controls implemented (access, change management, monitoring). Independent SOC 2 Type II audit not yet completed.

GxP / GCP

Controls

Hash-chained custody events with two-party sender/recipient attribution, designed to support GxP / GCP evidence. Formal computer-system validation and Part 11-compliant e-signatures are the customer's responsibility.

CLIA / CAP

Controls

Per-action actor attribution supports CLIA/CAP evidence. DNACHAIN is not itself CLIA/CAP accredited — the lab holds the accreditation.

An independent SOC 2 Type II report is in progress and not yet available. DNACHAIN itself is not CLIA, CAP, ISO 27001, or FedRAMP certified.

Security controls in place

Encryption

TLS 1.2+ in transit. AES-256 at rest via managed cloud storage. Secrets stored in a hardened secret manager, never in application code.

Access control

Row-Level Security enforced at the database on every table containing customer data. Role-based access (Owner, Manager, Researcher, Auditor) with least-privilege defaults.

Tamper-evident audit trail

Every custody event is SHA-256 hashed and cryptographically chained. Audit PDF exports are signed with per-organization Ed25519 keys and independently verifiable at /verify.

Authentication

Password + email verification, single active session per user, sign-up fingerprinting to deter multi-account abuse. SSO (SAML) available on Enterprise.

Data isolation

Multi-tenant with per-organization scoping enforced in the database, not just the application. No cross-tenant reads are possible under RLS.

Personnel

Access to production data is limited and audited. No routine access to customer sample data by DNACHAIN staff.

Data handling

What we store. Sample metadata, custody events, consent records, and audit logs that you create in the platform. We process this on your behalf as a data processor.

What we don't store in the hash chain. No PII, donor identifiers, or specimen sequence data is ever exposed in the hash chain itself — only one-way SHA-256 digests used to prove integrity.

Retention & deletion. Customer data is retained for the life of your account plus a defined recovery window. You can export your complete workspace or request deletion at any time.

Training. We do not use customer data to train machine-learning models. We do not sell personal data.

Sub-processors

ProviderPurposeRegion
Supabase / AWSApplication hosting, Postgres database, object storageUS
CloudflareEdge network, DDoS protection, TLS terminationGlobal
StripePayment processing and subscription billingUS / Global
PauboxHIPAA-compliant transactional and lifecycle email delivery (BAA in place)US
Lovable AI GatewayAI chatbot inference (public marketing chat only)US

We notify customers of material sub-processor changes. Contact support@dnachain.bio for the latest list.

Legal & contact

Documents

Security contact

Report a vulnerability or security concern to support@dnachain.bio. We acknowledge reports within 2 business days.

This page is maintained by DNACHAIN and reflects the current state of the platform. Nothing on this page constitutes a warranty of regulatory compliance or a substitute for your own legal review.