Compliance & Security

Validated for regulatory submissions.

Clinical trial data requires a compliance framework that goes beyond standard SaaS security. Metamorphic AI is built to satisfy the requirements of global regulatory agencies, independent auditors, and your internal QA teams.

  • SOC 2 TYPE IIActive
  • ISO 27001Active
  • GDPRCompliant
  • FDA 21 CFR PART 11Compliant
  • ALCOA+Enforced
Overview

Five frameworks. One coherent posture.

Each certification addresses a distinct layer of the compliance requirement for pharmaceutical AI platforms — from information security management through to data integrity and regulatory submissions.

SOC 2 TYPE II

Security, Availability & Confidentiality

Independently audited controls verified over time, not just at a point in time. Continuous assurance that Metamorphic AI's controls for security, availability, and confidentiality operate as described.

ISO 27001

Information Security Management

Systematically managed, continuously monitored, and independently certified information security controls across the organisation and platform.

GDPR

EU Data Protection

Full compliance with EU data protection regulation, including data subject rights, purpose limitation, and documented Data Processing Agreements provided as standard.

FDA 21 CFR PART 11

Electronic records and signatures regulation satisfied throughout the document lifecycle.

No separate validation exercise required from the customer. The platform is validated per FDA Computer Software Validation guidance, with IQ/OQ/PQ documentation available on request.

ALCOA+

Data Integrity by Architecture

Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, Available. Enforced by architecture — not by process.

Security architecture

Defence-in-depth across every layer.

Controls operate at every layer of the stack — from network perimeter through to individual document actions. No single control failure exposes customer data.

INFRASTRUCTURE

Network & perimeter

Network segmentation, firewall hardening, intrusion detection, and encrypted remote access with MFA enforced at all entry points.

IDENTITY & ACCESS

Least-privilege by role

Role-based access control aligned to document workflow roles. Quarterly access reviews. Access revoked within SLA on termination.

DATA PROTECTION

Isolated and encrypted

Encryption at rest and in transit. Per-company data isolation at the database level. Your study data never shared across tenants or used to train models. Formal retention and deletion procedures.

AUDIT & MONITORING

Always-on visibility

24/7 incident response. Continuous monitoring. Annual independent penetration testing. Complete, validated audit trails across all document activity.

Controls

43 controls. All passing.

All controls are continuously monitored. Status reflects the current verified state.

Infrastructure Security

16 CONTROLS · ALL PASSING
  • Encryption key access restricted
    Privileged access to encryption keys is restricted to authorised users with a documented business need.
    Passing
  • Access control procedures established
    Formal procedures govern adding, modifying, and removing user access across all system components.
    Passing
  • Production database access restricted
    Privileged access to production databases is limited to authorised personnel with a documented need.
    Passing
  • Firewall access restricted
    Firewall administration access is controlled and limited to authorised users.
    Passing
  • Production OS access restricted
    Operating system access in the production environment is restricted to authorised users.
    Passing
  • Production network access restricted
    Production network access is limited to authorised personnel only.
    Passing
  • Access revoked upon termination
    Termination checklists ensure access is revoked for departing employees within defined SLAs.
    Passing
  • Unique network authentication enforced
    Production network authentication requires unique usernames/passwords or authorised SSH keys.
    Passing
  • Remote access MFA enforced
    All remote access to production systems requires multi-factor authentication.
    Passing
  • Remote access encrypted
    Remote access to production systems is permitted only via approved encrypted connections.
    Passing
  • Intrusion detection system utilised
    Continuous network monitoring detects and alerts on potential security breaches in real time.
    Passing
  • Infrastructure performance monitored
    Monitoring tools track system performance and generate automated alerts at predefined thresholds.
    Passing
  • Network segmentation implemented
    Network segmentation prevents lateral movement and unauthorised access to customer data.
    Passing
  • Network firewalls reviewed
    Firewall rulesets are reviewed at least annually; required changes are tracked to completion.
    Passing
  • Network firewalls utilised
    Firewalls are configured to prevent unauthorised access to all system components.
    Passing
  • Network and system hardening maintained
    Hardening standards are documented, based on industry best practices, and reviewed at least annually.
    Passing
Regulatory

Built for GxP. Not retrofitted to it.

General-purpose platforms carry security certifications. Very few are built to operate inside the regulatory framework governing pharmaceutical clinical data. Metamorphic AI is designed from the ground up for GxP environments — with the documentation, controls, and validation artefacts inspection teams expect.

VALIDATED AUDIT TRAIL

A complete record. From source data to final approval.

Every element of a generated document is recorded at each stage of the workflow. The record is append-only — no retrospective modification is permitted by any user, including administrators.

An auditor can trace any content decision back to its source without relying on individual memory or reconstructed timelines: what source data was used, what context was applied, what actions were taken, and who reviewed and approved the final output.

  1. Protocol and source data ingested
  2. Context snapshot locked at study initiation
  3. Each section generated, with source data referenced
  4. Reviewer actions and comments recorded
  5. Approval signatures timestamped and attributed
  6. Final approved version sealed
FDA 21 CFR PART 11

Electronic records in practice.

Electronic signatures are linked to specific individuals and timestamped at execution. Audit trails are system-generated and cannot be modified by any user, including administrators.

The platform is validated per FDA Computer Software Validation (CSV) guidance, with IQ/OQ/PQ documentation available on request.

Part 11 compliance requires no separate validation exercise from the customer.

ALCOA+ — DATA INTEGRITY BY DESIGN

Attribution without effort.

When a document is generated, the system records the source data used, the context applied, each action taken, and a timestamp for every event. This produces an attribution chain satisfying the Attributable and Contemporaneous requirements automatically — without additional effort from the user.

Output is original and preserved in a tamper-evident record.

QMS ENFORCEMENT

Compliance at generation time, not after the fact.

Metamorphic AI enforces QMS compliance at the point of document generation. When SOPs are encoded into the platform, they become active enforcement rules. Every document is checked against the governing SOP before any output is produced, with a compliance attestation record generated for every document.

VEEVA VAULT INTEGRATION
For customers on Veeva Vault QualityDocs, Metamorphic AI is complementary. Veeva stores the approved SOP; Metamorphic AI pulls it via API and encodes it into the platform for the study. Every output is demonstrably SOP-compliant by construction. Final approved documents are stored back into Veeva via API.
Security documentation

Everything your security team needs. On request.

Enterprise security reviews, DPAs, and validation documentation are available under NDA. NDA-gated materials are reviewed and shared within 2 business days.

DocumentAvailability
SOC 2 Type II ReportNDA required
ISO 27001 CertificateOn request
Annual penetration test summaryNDA required
Data Processing Agreement (DPA)On request
System validation documentation (IQ/OQ/PQ)NDA required — 21 CFR Part 11
21 CFR Part 11 compliance statementOn request

For urgent requests or to begin an enterprise security review, contact the security team directly. NDA-gated materials are shared within 2 business days of request.

security@metamorphic-ai.com