Security at EdGeneAI
Your sequencing data is sensitive. Here's a plain-language overview of how we protect Platform data — and why Skills carry a fundamentally different data-exposure profile.
A Note on Skills vs. Platform Security
Everything below describes Platform security, because that's where EdGeneAI actually handles your data. A licensed Skill runs entirely on your own infrastructure — your data never reaches EdGeneAI's systems at all, so the relevant security posture is your own, not ours. If you need us to review your own Skill deployment security, we're happy to advise.
Infrastructure Security (Platform)
Platform infrastructure runs on AWS and/or Google Cloud Platform, both ISO 27001 and SOC 2 Type II certified. By default, Platform data is processed in the Asia Pacific (Mumbai) region; Enterprise customers can request EU or US hosting.
Data Encryption
- In transit: TLS 1.2+ enforced for all API and web traffic
- At rest: AES-256 encryption for all stored Customer Data
- Key management: AWS KMS / GCP Cloud KMS with automatic annual rotation
Access Controls
- Least-privilege access for all EdGeneAI staff
- Multi-factor authentication required for all employee accounts
- No employee can access raw Platform customer data except in documented, logged, consent-based support scenarios
- All access events immutably logged and retained for 12 months
Application Security
- Code review required for all changes; automated vulnerability scanning in CI/CD
- Annual third-party penetration test
- All uploads type-checked, size-limited, and scanned before pipeline ingestion
Data Isolation
Each Platform customer's data is logically isolated at storage, compute, and database layers. Pipeline jobs run in isolated containers with no cross-customer network access.
Incident Response
Incidents are triaged within 2 hours of detection. Affected Platform customers are notified within 72 hours of confirmation, with a post-incident report within 14 days of resolution.
Certifications Roadmap
| Certification | Status | Target |
|---|---|---|
| ISO 27001 | In preparation | Q4 2027 |
| SOC 2 Type I | In preparation | Q2 2027 |
| DPDPA (India) Registration | In progress | Q3 2026 |
Vulnerability Disclosure
Found a potential issue? Email security@edgeneai.com with a description, reproduction steps, and your contact details. We acknowledge within 48 hours and won't pursue legal action against good-faith researchers.
Contact
Security enquiries: security@edgeneai.com