Security built for life sciences research
Discngine builds and operates scientific software for drug-discovery teams.
Our SaaS platform is ISO 27001:2022 certified, with controls designed for the data-handling expectations of pharma and biotech R&D.
Trusted by life-science research teams worldwide
Leading pharma Top 10 biotech AI-first discovery Translational research Academic centres
Contract research Clinical-stage biotech Big pharma R&D
DEFENCE IN DEPTH
Security at every layer of the platform
From the engineers who write the code to the EU cloud region that hosts it, every part of Discngine is governed by the same controls — independently audited and openly documented.
COMPLIANCE
Independently certified, audited annually
Our information security management system is certified against ISO/IEC 27001:2022. Customers can request the full report, Statement of Applicability and sub-processor list under NDA.
Frequently Asked Questions
Still have questions?
Reach out to us — we typically respond within one business day.
-
By default, production data is hosted on EU-based cloud infrastructure within the European Economic Area. Additional regions, and dedicated single-tenant deployments in a specific region, are available on request under contract.
-
Yes — a current copy of our ISO/IEC 27001:2022 certificate is available on request from your account contact or by emailing security@discngine.com. The Statement of Applicability is shared under NDA.
-
Audit and application logs are retained according to our internal policy; exact retention windows are shared under NDA. On request, audit logs can be exposed via secure APIs so that your SIEM can ingest them on the schedule you choose.
-
Yes — Bring Your Own Key (BYOK) is available for single-tenant subscriptions, with keys stored in a FIPS 140-2 compliant HSM-backed key vault. The default option uses provider-managed keys, also FIPS 140-2 compliant.
-
On detection of an incident affecting customer data, customers are notified immediately by any available means. A detailed incident report covering cause, impact and remediation is then provided within a contractually defined window. A specific notification window can be added to your contract on request.
-
Yes — an independent third party performs an annual external penetration test on the SaaS platform. A redacted summary is available under NDA.
-
Discngine is not SOC 2 certified at this time. We provide the ISO 27001 certificate and Statement of Applicability as an equivalent recognised standard, which is accepted by most procurement teams as security due diligence.
-
Our current list of sub-processors is shared on request under NDA. Changes are notified in line with the Data Processing Agreement, which gives customers a right to object.
WHITEPAPER
Learn more about security & trust at Discngine
A deep dive into our infrastructure, controls, and governance — written for your security and compliance teams.