TRUST CENTER
Security, privacy, and compliance at DNACHAIN.
This page is maintained by DNACHAIN to answer common security and privacy questions about the platform. It describes the technical controls we operate today, the sub-processors we rely on, and where the compliance responsibility is shared with you as the customer. It is not an independent certification.
Shared responsibility. DNACHAIN provides platform controls. Regulatory compliance (HIPAA, 21 CFR Part 11, GxP, GDPR, CLIA/CAP) always requires customer SOPs, training, and — where applicable — a signed BAA or DPA. We do not attest to your organization's compliance on your behalf.
Compliance posture
21 CFR Part 11
ControlsTechnical controls for electronic records: immutable audit trail, per-actor attribution, Ed25519-signed exports. Customer is responsible for SOP and validation.
HIPAA
ControlsTechnical safeguards: encryption at rest and in transit, RLS-enforced access, audit logging. BAA available on Professional and Enterprise.
GDPR
ControlsConsent versioning, DB-enforced withdrawal cascade, data export and erasure workflows. Sub-processors listed on the Trust page.
SOC 2 Type II
ControlsTrust-services criteria controls implemented (access, change management, monitoring). Independent SOC 2 Type II audit not yet completed.
GxP / GCP
ControlsHash-chained custody events with two-party sender/recipient attribution, designed to support GxP / GCP evidence. Formal computer-system validation and Part 11-compliant e-signatures are the customer's responsibility.
CLIA / CAP
ControlsPer-action actor attribution supports CLIA/CAP evidence. DNACHAIN is not itself CLIA/CAP accredited — the lab holds the accreditation.
An independent SOC 2 Type II report is in progress and not yet available. DNACHAIN itself is not CLIA, CAP, ISO 27001, or FedRAMP certified.
Security controls in place
Encryption
TLS 1.2+ in transit. AES-256 at rest via managed cloud storage. Secrets stored in a hardened secret manager, never in application code.
Access control
Row-Level Security enforced at the database on every table containing customer data. Role-based access (Owner, Manager, Researcher, Auditor) with least-privilege defaults.
Tamper-evident audit trail
Every custody event is SHA-256 hashed and cryptographically chained. Audit PDF exports are signed with per-organization Ed25519 keys and independently verifiable at /verify.
Authentication
Password + email verification, single active session per user, sign-up fingerprinting to deter multi-account abuse. SSO (SAML) available on Enterprise.
Data isolation
Multi-tenant with per-organization scoping enforced in the database, not just the application. No cross-tenant reads are possible under RLS.
Personnel
Access to production data is limited and audited. No routine access to customer sample data by DNACHAIN staff.
Data handling
What we store. Sample metadata, custody events, consent records, and audit logs that you create in the platform. We process this on your behalf as a data processor.
What we don't store in the hash chain. No PII, donor identifiers, or specimen sequence data is ever exposed in the hash chain itself — only one-way SHA-256 digests used to prove integrity.
Retention & deletion. Customer data is retained for the life of your account plus a defined recovery window. You can export your complete workspace or request deletion at any time.
Training. We do not use customer data to train machine-learning models. We do not sell personal data.
Sub-processors
| Provider | Purpose | Region |
|---|---|---|
| Supabase / AWS | Application hosting, Postgres database, object storage | US |
| Cloudflare | Edge network, DDoS protection, TLS termination | Global |
| Stripe | Payment processing and subscription billing | US / Global |
| Paubox | HIPAA-compliant transactional and lifecycle email delivery (BAA in place) | US |
| Lovable AI Gateway | AI chatbot inference (public marketing chat only) | US |
We notify customers of material sub-processor changes. Contact support@dnachain.bio for the latest list.
Legal & contact
Documents
- Privacy Policy
- Terms of Service
- DPA / BAA — available on request at support@dnachain.bio
Security contact
Report a vulnerability or security concern to support@dnachain.bio. We acknowledge reports within 2 business days.
This page is maintained by DNACHAIN and reflects the current state of the platform. Nothing on this page constitutes a warranty of regulatory compliance or a substitute for your own legal review.
