Validated for regulatory submissions.
Clinical trial data requires a compliance framework that goes beyond standard SaaS security. Metamorphic AI is built to satisfy the requirements of global regulatory agencies, independent auditors, and your internal QA teams.
- SOC 2 TYPE IIActive
- ISO 27001Active
- GDPRCompliant
- FDA 21 CFR PART 11Compliant
- ALCOA+Enforced
Five frameworks. One coherent posture.
Each certification addresses a distinct layer of the compliance requirement for pharmaceutical AI platforms — from information security management through to data integrity and regulatory submissions.
Security, Availability & Confidentiality
Independently audited controls verified over time, not just at a point in time. Continuous assurance that Metamorphic AI's controls for security, availability, and confidentiality operate as described.
Information Security Management
Systematically managed, continuously monitored, and independently certified information security controls across the organisation and platform.
EU Data Protection
Full compliance with EU data protection regulation, including data subject rights, purpose limitation, and documented Data Processing Agreements provided as standard.
Electronic records and signatures regulation satisfied throughout the document lifecycle.
No separate validation exercise required from the customer. The platform is validated per FDA Computer Software Validation guidance, with IQ/OQ/PQ documentation available on request.
Data Integrity by Architecture
Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, Available. Enforced by architecture — not by process.
Defence-in-depth across every layer.
Controls operate at every layer of the stack — from network perimeter through to individual document actions. No single control failure exposes customer data.
Network & perimeter
Network segmentation, firewall hardening, intrusion detection, and encrypted remote access with MFA enforced at all entry points.
Least-privilege by role
Role-based access control aligned to document workflow roles. Quarterly access reviews. Access revoked within SLA on termination.
Isolated and encrypted
Encryption at rest and in transit. Per-company data isolation at the database level. Your study data never shared across tenants or used to train models. Formal retention and deletion procedures.
Always-on visibility
24/7 incident response. Continuous monitoring. Annual independent penetration testing. Complete, validated audit trails across all document activity.
43 controls. All passing.
All controls are continuously monitored. Status reflects the current verified state.
Infrastructure Security
16 CONTROLS · ALL PASSING- Encryption key access restrictedPrivileged access to encryption keys is restricted to authorised users with a documented business need.Passing
- Access control procedures establishedFormal procedures govern adding, modifying, and removing user access across all system components.Passing
- Production database access restrictedPrivileged access to production databases is limited to authorised personnel with a documented need.Passing
- Firewall access restrictedFirewall administration access is controlled and limited to authorised users.Passing
- Production OS access restrictedOperating system access in the production environment is restricted to authorised users.Passing
- Production network access restrictedProduction network access is limited to authorised personnel only.Passing
- Access revoked upon terminationTermination checklists ensure access is revoked for departing employees within defined SLAs.Passing
- Unique network authentication enforcedProduction network authentication requires unique usernames/passwords or authorised SSH keys.Passing
- Remote access MFA enforcedAll remote access to production systems requires multi-factor authentication.Passing
- Remote access encryptedRemote access to production systems is permitted only via approved encrypted connections.Passing
- Intrusion detection system utilisedContinuous network monitoring detects and alerts on potential security breaches in real time.Passing
- Infrastructure performance monitoredMonitoring tools track system performance and generate automated alerts at predefined thresholds.Passing
- Network segmentation implementedNetwork segmentation prevents lateral movement and unauthorised access to customer data.Passing
- Network firewalls reviewedFirewall rulesets are reviewed at least annually; required changes are tracked to completion.Passing
- Network firewalls utilisedFirewalls are configured to prevent unauthorised access to all system components.Passing
- Network and system hardening maintainedHardening standards are documented, based on industry best practices, and reviewed at least annually.Passing
Organisational Security
12 CONTROLS · ALL PASSING- Asset disposal proceduresElectronic media containing confidential information is purged or destroyed per best practices; certificates of destruction are issued.Passing
- Production inventory maintainedA formal inventory of production system assets is maintained and kept current.Passing
- Portable media encryptedPortable and removable media devices are encrypted when in use.Passing
- Anti-malware deployedAnti-malware is deployed, routinely updated, and installed across all relevant systems.Passing
- Employee background checksBackground checks are conducted on all new employees as part of the hiring process.Passing
- Code of Conduct — contractorsContractor agreements include or reference the company Code of Conduct.Passing
- Code of Conduct — employeesEmployees acknowledge the Code of Conduct at hire; violations are subject to disciplinary action.Passing
- Confidentiality agreement — contractorsContractors sign a confidentiality agreement at the time of engagement.Passing
- Confidentiality agreement — employeesEmployees sign a confidentiality agreement during onboarding.Passing
- Performance evaluations conductedManagers conduct formal performance evaluations for direct reports at least annually.Passing
- MDM system utilisedA mobile device management system centrally manages mobile devices used to access platform services.Passing
- Visitor procedures enforcedVisitors to data centre or secure areas must sign in, wear a badge, and be escorted by an authorised employee.Passing
Product Security
5 CONTROLS · ALL PASSING- Data encryption at restAll datastores housing sensitive customer data are encrypted at rest.Passing
- Data transmission encryptedSecure transmission protocols encrypt all confidential data sent over public networks.Passing
- Penetration testing performedIndependent penetration testing is conducted at least annually with remediation tracked within defined SLAs.Passing
- Control self-assessments conductedAnnual self-assessments verify controls are operating effectively; corrective actions are tracked to completion.Passing
- Vulnerability and monitoring proceduresFormal policies govern vulnerability management and system monitoring across all in-scope components.Passing
Data & Privacy
10 CONTROLS · ALL PASSING- Data retention procedures establishedFormal retention and disposal procedures govern the secure retention and disposal of company and customer data.Passing
- Customer data deleted upon leavingCustomer data containing confidential information is purged or removed when customers leave the service.Passing
- Data classification policy establishedA data classification policy ensures confidential data is properly secured and restricted to authorised personnel.Passing
- Data deletion requests handledDeletion requests are validated and processed in accordance with applicable laws and regulations.Passing
- Identity verification conductedIndividuals' identities are verified with appropriate assurance before granting access to personal information.Passing
- Privacy inquiries handledProcesses capture, log, verify, and respond to requests, inquiries, and disputes related to individual privacy rights.Passing
- Personal information securely disposedPersonal information is anonymised, securely erased, or destroyed when no longer required.Passing
- Privacy policy maintainedA clearly dated, plain-language privacy policy covers purposes, data types, individual rights, and third-party sharing.Passing
- Explicit consent obtainedExplicit consent is obtained, documented, and retained before collecting, using, or disclosing sensitive information.Passing
- Non-essential data opt-out availableIndividuals may opt out of the collection or use of non-essential personal information.Passing
Built for GxP. Not retrofitted to it.
General-purpose platforms carry security certifications. Very few are built to operate inside the regulatory framework governing pharmaceutical clinical data. Metamorphic AI is designed from the ground up for GxP environments — with the documentation, controls, and validation artefacts inspection teams expect.
A complete record. From source data to final approval.
Every element of a generated document is recorded at each stage of the workflow. The record is append-only — no retrospective modification is permitted by any user, including administrators.
An auditor can trace any content decision back to its source without relying on individual memory or reconstructed timelines: what source data was used, what context was applied, what actions were taken, and who reviewed and approved the final output.
- Protocol and source data ingested
- Context snapshot locked at study initiation
- Each section generated, with source data referenced
- Reviewer actions and comments recorded
- Approval signatures timestamped and attributed
- Final approved version sealed
Electronic records in practice.
Electronic signatures are linked to specific individuals and timestamped at execution. Audit trails are system-generated and cannot be modified by any user, including administrators.
The platform is validated per FDA Computer Software Validation (CSV) guidance, with IQ/OQ/PQ documentation available on request.
Part 11 compliance requires no separate validation exercise from the customer.
Attribution without effort.
When a document is generated, the system records the source data used, the context applied, each action taken, and a timestamp for every event. This produces an attribution chain satisfying the Attributable and Contemporaneous requirements automatically — without additional effort from the user.
Output is original and preserved in a tamper-evident record.
Compliance at generation time, not after the fact.
Metamorphic AI enforces QMS compliance at the point of document generation. When SOPs are encoded into the platform, they become active enforcement rules. Every document is checked against the governing SOP before any output is produced, with a compliance attestation record generated for every document.
Everything your security team needs. On request.
Enterprise security reviews, DPAs, and validation documentation are available under NDA. NDA-gated materials are reviewed and shared within 2 business days.
| Document | Availability |
|---|---|
| SOC 2 Type II Report | NDA required |
| ISO 27001 Certificate | On request |
| Annual penetration test summary | NDA required |
| Data Processing Agreement (DPA) | On request |
| System validation documentation (IQ/OQ/PQ) | NDA required — 21 CFR Part 11 |
| 21 CFR Part 11 compliance statement | On request |
For urgent requests or to begin an enterprise security review, contact the security team directly. NDA-gated materials are shared within 2 business days of request.
security@metamorphic-ai.com