Skip to content
CovaSyn
Book an initial call

Trust

Security and privacy

What happens to your molecular structures, where the platform runs, how it is protected and what we explicitly do not claim. The security questionnaires for your procurement are fully answered and ready to download.

30 minutes on Microsoft Teams with the CovaSyn team. If it is not a fit, we will say so.

Trust · data flowWhat happens to your data
  1. Your requestfrom assistant, sketcher or form
  2. Encrypted in transitTLS 1.2 or higher, HSTS
  3. Tools compute in Germanyin memory, without a language model, not stored permanently
  4. Result to yourights remain yours

KeptAudit trail without content

NeverTraining on your data

Exceptions, stated openly: the chat assistant in the structure editor and campaign analysis use a language model from Anthropic (USA, standard contractual clauses).

Your inputs are processed only for your request, not stored permanently and never used for training.

Your data

What happens to your molecular structures

This is the first question pharma procurement asks, and it deserves an answer without hesitation. Uploaded structures are drug candidates, the most valuable thing a customer has.

  • No use for training

    Your inputs are processed solely to answer the respective request and are never used to train our own or third-party models. This commitment sits in the data processing agreement, not just on this page. The model providers we use are contractually excluded from it too.

  • Tenant separation

    Every record belongs to an account, and separation is enforced at row level in the database, not only in the application. Access from another account returns no rows, not a filtered view.

  • EU hosting

    Operated in Germany at Hetzner Online GmbH, data held within the EU, no mirroring outside the EU. For enterprise customers, optionally as a container on your own infrastructure.

  • Deletion on request

    Deleted on request within 30 days, including backup copies within their rotation cycle. After contract end within 90 days. Rights to inputs and results remain entirely yours.

Hosting and encryption

Where the platform runs and how it is protected.

Location
Servers at Hetzner Online GmbH in Nuremberg, physically in Germany. CovaSyn is not a subsidiary of a US company.
Running it yourself
For enterprise customers, optionally as a dedicated instance on your hardware. No data is then transferred to third countries.Running it in-house
In transit
Exclusively over TLS 1.2 or higher, with HSTS enabled.
At rest
Storage volumes are encrypted.
Credentials and keys
API keys and credentials are held only as hashes or in separate configuration and are never logged in clear text.

Access

Who can access what.

Sign-in
Sessions use cookies with HttpOnly, Secure and SameSite=Lax.
Single sign-on
For enterprise customers via SAML 2.0, tested with Microsoft Entra ID, Okta and Google Workspace. Users are assigned to your organisation on first sign-in based on the verified company domain.Guide for your IT
Roles
User, admin and organisation owner. API keys are scoped per account and can be revoked at any time.
Logs
Every tool call is logged with timestamp, tool, version, result status and key ID. Logs are exportable as CSV or JSON.

Operations

Incidents and reports.

Security incidents
A documented reporting path with named responsibilities is in place. Affected customers are informed no later than 24 hours after an incident that may relate to their data is identified. The 72-hour deadline for notifying the supervisory authority under Art. 33 GDPR is part of the procedure.
Report a vulnerability
Reports go to info@covasyn.com. We respond to legitimate reports within 5 business days and follow coordinated disclosure with a 90-day window. The machine-readable version is at /.well-known/security.txt per RFC 9116.

Regulated environments

What the software brings to your validation.

No software ships fully validated at purchase. Validation is the process in your organisation. CovaSyn provides the properties and, on request for regulated environments, the documents you validate with.

Determinism
Tool versions are pinned. Identical input reproducibly yields identical output, weeks later too. Neither chance nor a language model decides anything in the numerical path.
Audit trail
Every tool call is logged with timestamp, tool, version, result status and key ID, exportable as CSV or JSON.
Checksums
Outputs carry a SHA-256 checksum. If you keep it, you can later verify that a result is unchanged.
What the software brings to your validation.
FrameworkWhat CovaSyn brings to it
EU GMP Annex 11 (computerised systems)Audit trail, deterministic results and access control are built in and support your validation.
21 CFR Part 11 (electronic records)Outputs carry a SHA-256 checksum; logs are exportable as CSV or JSON.
GAMP 5Classified as category 4 (configured product): no custom code is developed at the customer site.
ICH M7 (R2), mutagenic impuritiesMutagenicity assessment tools with a workflow for review by your experts.
ICH Q1A and Q1E, stabilityShelf life by regression of long-term data against the one-sided 95% confidence bound (ICH Q1E), Arrhenius as supporting kinetics.
GAMP 5, change controlVersioning and change-control pathways are documented. Changes that can affect results are announced at least 30 days in advance.

Validation at CovaSyn

  • Every account delivers audit-grade outputs. Validation of your use case takes place at your site.
  • On request for regulated environments (Enterprise): a validation pack with templates for user requirements (URS), functional specification (FS) and installation, operational and performance qualification (IQ, OQ, PQ), including the rationale for GAMP 5 category 4.
  • We arrange a walkthrough of the pack in the initial call.

What we do not claim

  • “GxP-validated” out of the box. Validation is a customer process, not a property of the software.
  • “Replaces QA review”. CovaSyn complements QA workflows, it does not replace them.
  • “FDA-approved”. CovaSyn is neither a medical device nor a drug; FDA approval does not exist for this kind of software.
  • Certifications. CovaSyn currently holds neither an ISO 27001 certification nor a SOC 2 Type II report; the controls themselves are documented in SIG Lite and CAIQ v4. HIPAA is generally not applicable to pharma research in the EU.

For your procurement

Security questionnaires, pre-filled.

SIG Lite and CAIQ v4 are fully answered and available here. Both are generated from a single maintained answer library, so one edit takes effect in both at once. Together they cover most of what a company-specific questionnaire asks.

Data processing under Art. 28 GDPR

Data processing agreement with the Art. 32 GDPR technical and organisational measures annex, ready to sign within 24 hours via the form on the DPA page. Deletion concept, access concept and incident response plan are provided on request.

Request the DPA

Transparency

Subprocessors

Complete list, each with purpose and processing location, matching the privacy policy. Changes are announced with a right to object. Two functions involve a language model from Anthropic with processing in the United States, covered by standard contractual clauses: the chat assistant in the structure editor and the interpretation feature in campaign analysis. All other tools operate without a language model and without third-country transfer.

Subprocessors
ProviderPurposeLocation
Hetzner Online GmbHHosting of the platform and the databaseEUGermany
Supabase (database and authentication)Data storage, accounts and loginEUEU region
Stripe Payments Europe Ltd.Payment processing and invoicingEUIreland
Microsoft 365 (Exchange Online)Business email communicationEUEU region
Anthropic PBCLanguage model for the chat assistant in the structure editor and for the interpretation feature in campaign analysis; transmits the structure being worked on, the conversation history and tool results or, for campaign analysis, statistical evaluationsNon-EUUSA (standard contractual clauses)
Cloudflare, Inc.Domain name resolution and upstream network protectionNon-EUUSA (standard contractual clauses)
Resend (Plus Five Five, Inc.)Delivery of system messages such as confirmations and billing noticesNon-EUUSA (standard contractual clauses)
Twilio SendGridFallback path for delivering system messagesNon-EUUSA (standard contractual clauses)
Trustpilot A/SCollection and display of customer reviewsEUDenmark
Google Ireland Ltd.Website analytics, being replaced by our own analyticsNon-EUIreland (transfer to the USA possible)

MolecularIQ

Measured on an independent benchmark

On the MolecularIQ benchmark, which we did not design (Bartmann et al., Klambauer Lab, JKU Linz), we measure our tools with symbolic verification against the stored solution, without a language model acting as judge.

Models alone
14 to 41%
With CovaSyn MCP
76 to 92%
Benchmark and methodology

Source: Bartmann C., Schimunek J., Ielanskyi M., Seidl P., Klambauer G., Luukkonen S. (2026). MolecularIQ: Characterizing Chemical Reasoning Capabilities Through Symbolic Verification on Molecular Graphs. arXiv:2601.15279. Snapshot: 2026-05-17.

FAQ

Frequently asked questions

Is our data used to train models?

No. Your inputs are processed solely to answer the respective request and are never used to train our own or third-party models. The commitment is part of the data processing agreement.

Where is our data kept?

In Germany, at Hetzner Online GmbH, with data held within the EU. On request the platform runs on your own infrastructure.

Is CovaSyn certified?

No. There is currently neither an ISO 27001 certification nor a SOC 2 report. The controls are documented in the SIG Lite and CAIQ v4 questionnaires, which you can download on this page.

Is the software validated?

No software ships fully validated at purchase. CovaSyn delivers audit-grade outputs and, on request, a validation pack with templates; validation of your use case takes place at your site.

Next step

We resolve open questions from QA or procurement together.

If your team needs more than this page and the questionnaires, we go through the points in the initial call.

30 minutes on Microsoft Teams with the CovaSyn team. If it is not a fit, we will say so.

Security and privacy | CovaSyn