SterileAtlas handles sensitive commercial, regulatory, privileged IP, GLP study, animal-welfare, and clinical-operations information across facilities, biotechs, investors, IP counsel, CROs, and preclinical laboratories. This page describes the platform's security posture — the controls live in this build and the enterprise compliance roadmap.
Demonstration platform. "Implemented" controls are live in this build. "Roadmap" items describe the intended production architecture and are not yet certified or implemented — SterileAtlas is not currently SOC 2 certified.
Five roles (Admin, Editor, Viewer, Buyer, Provider). Profile editing is ownership-gated — only the owning account or platform staff can mutate a facility, company, investment firm, IP firm, CRO, or preclinical lab.
Authentication, profile mutations (incl. CRO and preclinical-lab edits) and secure data-room access are recorded to an immutable audit log (actor, action, entity, IP, timestamp). Logging never blocks a request.
Every mutation API validates against a zod allowlist; unknown keys are stripped and child relations replaced transactionally — no mass-assignment.
Passwords hashed with bcrypt; signed session cookies; login rate-limiting per IP to blunt credential stuffing.
Confidential / FTO / partnership inquiries are routed to the owning firm through a login-gated channel — no public exposure of contacts.
Write APIs authorize owner-or-staff before any change, run inside a transaction, and return minimal responses.
Per-lab document data rooms are login-gated and role-based — restricted documents (final reports, validation reports) are hidden from unauthorized roles, and every access is recorded to the audit trail.
Controls mapped to the Trust Services Criteria; independent attestation planned for production.
Data-subject access/erasure workflows, EU data residency, and consent management.
Safeguards for protected health information in clinical-operations data — BAAs, minimum-necessary access, and de-identification for analytics.
Compliant electronic records and signatures for protocols, CSRs, and engagement agreements — audit-trailed, ALCOA+ (live in sister GMP/EDMS products).
Encrypted document vault (confidential IP, clinical, GLP study & sponsor data) with per-tenant keys.
Encrypted sponsor–lab / sponsor–CRO data rooms with granular, time-boxed access and watermarking.
ALCOA+ controls for GLP study records and AAALAC-aligned retention for animal-welfare documentation.
Matter-level conflict screens and information barriers for legal-privilege segregation.
SAML / OIDC single sign-on and SCIM provisioning.
238 events recorded in the append-only audit log.
Audit-trail detail is restricted to platform staff (Admin / Editor). Sign in with a staff account to view recent events.