Security at Gimerny AI

We protect the world's most sensitive pharmaceutical research data. Security is not an afterthought; it is foundational to everything we build.

SOC 2 Type II
Annual audit by Deloitte
ISO 27001
Certified since 2023
HIPAA
BAA available
GDPR
Compliant by design
GxP
Validated workflows
21 CFR Part 11
Electronic records

Security Architecture

Encryption

  • TLS 1.3 for all data in transit
  • AES-256 encryption at rest
  • Customer-managed encryption keys (CMEK) for Enterprise
  • End-to-end encryption for federated learning gradients
  • Hardware Security Modules (HSMs) for key management

Access Control

  • Role-based access control (RBAC)
  • Multi-factor authentication (MFA) enforced
  • SSO/SAML 2.0 integration (Enterprise)
  • Just-in-time privilege escalation
  • Automated access reviews quarterly

Infrastructure

  • Deployed on AWS (primary) and GCP (failover)
  • SOC 2 Type II certified data centers
  • Network segmentation and VPC isolation
  • DDoS protection via AWS Shield Advanced
  • 99.9% uptime SLA for Enterprise

Data Protection

  • Data residency options (EU, US, APAC)
  • Automated data classification and labeling
  • Immutable audit logs retained for 7 years
  • Data loss prevention (DLP) scanning
  • Secure data deletion with cryptographic erasure

Application Security

  • SAST/DAST scanning in CI/CD pipeline
  • Dependency vulnerability scanning (Snyk)
  • Annual penetration testing by NCC Group
  • Bug bounty program via HackerOne
  • OWASP Top 10 mitigations enforced

Incident Response

  • 24/7 security operations center (SOC)
  • Mean time to detect (MTTD): <15 minutes
  • Mean time to respond (MTTR): <1 hour
  • Automated incident playbooks
  • Customer notification within 72 hours (GDPR)

Responsible Disclosure

We value the security research community and welcome responsible disclosure of vulnerabilities. If you discover a security issue in any Gimerny AI product or infrastructure, please report it to our security team.

Email: security@gimerny.com (PGP key available on request)
Response time: acknowledgment within 24 hours, triage within 72 hours
We will not pursue legal action against researchers acting in good faith
We offer recognition and, for qualifying vulnerabilities, monetary rewards
Please allow 90 days for remediation before public disclosure
Contact Security Team