Security at Gimerny AI
We protect the world's most sensitive pharmaceutical research data. Security is not an afterthought; it is foundational to everything we build.
SOC 2 Type II
Annual audit by Deloitte
ISO 27001
Certified since 2023
HIPAA
BAA available
GDPR
Compliant by design
GxP
Validated workflows
21 CFR Part 11
Electronic records
Security Architecture
Encryption
- TLS 1.3 for all data in transit
- AES-256 encryption at rest
- Customer-managed encryption keys (CMEK) for Enterprise
- End-to-end encryption for federated learning gradients
- Hardware Security Modules (HSMs) for key management
Access Control
- Role-based access control (RBAC)
- Multi-factor authentication (MFA) enforced
- SSO/SAML 2.0 integration (Enterprise)
- Just-in-time privilege escalation
- Automated access reviews quarterly
Infrastructure
- Deployed on AWS (primary) and GCP (failover)
- SOC 2 Type II certified data centers
- Network segmentation and VPC isolation
- DDoS protection via AWS Shield Advanced
- 99.9% uptime SLA for Enterprise
Data Protection
- Data residency options (EU, US, APAC)
- Automated data classification and labeling
- Immutable audit logs retained for 7 years
- Data loss prevention (DLP) scanning
- Secure data deletion with cryptographic erasure
Application Security
- SAST/DAST scanning in CI/CD pipeline
- Dependency vulnerability scanning (Snyk)
- Annual penetration testing by NCC Group
- Bug bounty program via HackerOne
- OWASP Top 10 mitigations enforced
Incident Response
- 24/7 security operations center (SOC)
- Mean time to detect (MTTD): <15 minutes
- Mean time to respond (MTTR): <1 hour
- Automated incident playbooks
- Customer notification within 72 hours (GDPR)
Responsible Disclosure
We value the security research community and welcome responsible disclosure of vulnerabilities. If you discover a security issue in any Gimerny AI product or infrastructure, please report it to our security team.
Email: security@gimerny.com (PGP key available on request)
Response time: acknowledgment within 24 hours, triage within 72 hours
We will not pursue legal action against researchers acting in good faith
We offer recognition and, for qualifying vulnerabilities, monetary rewards
Please allow 90 days for remediation before public disclosure