Trust
Security and privacy
What happens to your molecular structures, where the platform runs, how it is protected and what we explicitly do not claim. The security questionnaires for your procurement are fully answered and ready to download.
30 minutes on Microsoft Teams with the CovaSyn team. If it is not a fit, we will say so.
- Your requestfrom assistant, sketcher or form
- Encrypted in transitTLS 1.2 or higher, HSTS
- Tools compute in Germanyin memory, without a language model, not stored permanently
- Result to yourights remain yours
KeptAudit trail without content
NeverTraining on your data
Exceptions, stated openly: the chat assistant in the structure editor and campaign analysis use a language model from Anthropic (USA, standard contractual clauses).
Your data
What happens to your molecular structures
This is the first question pharma procurement asks, and it deserves an answer without hesitation. Uploaded structures are drug candidates, the most valuable thing a customer has.
No use for training
Your inputs are processed solely to answer the respective request and are never used to train our own or third-party models. This commitment sits in the data processing agreement, not just on this page. The model providers we use are contractually excluded from it too.
Tenant separation
Every record belongs to an account, and separation is enforced at row level in the database, not only in the application. Access from another account returns no rows, not a filtered view.
EU hosting
Operated in Germany at Hetzner Online GmbH, data held within the EU, no mirroring outside the EU. For enterprise customers, optionally as a container on your own infrastructure.
Deletion on request
Deleted on request within 30 days, including backup copies within their rotation cycle. After contract end within 90 days. Rights to inputs and results remain entirely yours.
Hosting and encryption
Where the platform runs and how it is protected.
- Location
- Servers at Hetzner Online GmbH in Nuremberg, physically in Germany. CovaSyn is not a subsidiary of a US company.
- Running it yourself
- For enterprise customers, optionally as a dedicated instance on your hardware. No data is then transferred to third countries.Running it in-house
- In transit
- Exclusively over TLS 1.2 or higher, with HSTS enabled.
- At rest
- Storage volumes are encrypted.
- Credentials and keys
- API keys and credentials are held only as hashes or in separate configuration and are never logged in clear text.
Access
Who can access what.
- Sign-in
- Sessions use cookies with HttpOnly, Secure and SameSite=Lax.
- Single sign-on
- For enterprise customers via SAML 2.0, tested with Microsoft Entra ID, Okta and Google Workspace. Users are assigned to your organisation on first sign-in based on the verified company domain.Guide for your IT
- Roles
- User, admin and organisation owner. API keys are scoped per account and can be revoked at any time.
- Logs
- Every tool call is logged with timestamp, tool, version, result status and key ID. Logs are exportable as CSV or JSON.
Operations
Incidents and reports.
- Security incidents
- A documented reporting path with named responsibilities is in place. Affected customers are informed no later than 24 hours after an incident that may relate to their data is identified. The 72-hour deadline for notifying the supervisory authority under Art. 33 GDPR is part of the procedure.
- Report a vulnerability
- Reports go to info@covasyn.com. We respond to legitimate reports within 5 business days and follow coordinated disclosure with a 90-day window. The machine-readable version is at /.well-known/security.txt per RFC 9116.
Regulated environments
What the software brings to your validation.
No software ships fully validated at purchase. Validation is the process in your organisation. CovaSyn provides the properties and, on request for regulated environments, the documents you validate with.
- Determinism
- Tool versions are pinned. Identical input reproducibly yields identical output, weeks later too. Neither chance nor a language model decides anything in the numerical path.
- Audit trail
- Every tool call is logged with timestamp, tool, version, result status and key ID, exportable as CSV or JSON.
- Checksums
- Outputs carry a SHA-256 checksum. If you keep it, you can later verify that a result is unchanged.
| Framework | What CovaSyn brings to it |
|---|---|
| EU GMP Annex 11 (computerised systems) | Audit trail, deterministic results and access control are built in and support your validation. |
| 21 CFR Part 11 (electronic records) | Outputs carry a SHA-256 checksum; logs are exportable as CSV or JSON. |
| GAMP 5 | Classified as category 4 (configured product): no custom code is developed at the customer site. |
| ICH M7 (R2), mutagenic impurities | Mutagenicity assessment tools with a workflow for review by your experts. |
| ICH Q1A and Q1E, stability | Shelf life by regression of long-term data against the one-sided 95% confidence bound (ICH Q1E), Arrhenius as supporting kinetics. |
| GAMP 5, change control | Versioning and change-control pathways are documented. Changes that can affect results are announced at least 30 days in advance. |
Validation at CovaSyn
- Every account delivers audit-grade outputs. Validation of your use case takes place at your site.
- On request for regulated environments (Enterprise): a validation pack with templates for user requirements (URS), functional specification (FS) and installation, operational and performance qualification (IQ, OQ, PQ), including the rationale for GAMP 5 category 4.
- We arrange a walkthrough of the pack in the initial call.
What we do not claim
- “GxP-validated” out of the box. Validation is a customer process, not a property of the software.
- “Replaces QA review”. CovaSyn complements QA workflows, it does not replace them.
- “FDA-approved”. CovaSyn is neither a medical device nor a drug; FDA approval does not exist for this kind of software.
- Certifications. CovaSyn currently holds neither an ISO 27001 certification nor a SOC 2 Type II report; the controls themselves are documented in SIG Lite and CAIQ v4. HIPAA is generally not applicable to pharma research in the EU.
For your procurement
Security questionnaires, pre-filled.
SIG Lite and CAIQ v4 are fully answered and available here. Both are generated from a single maintained answer library, so one edit takes effect in both at once. Together they cover most of what a company-specific questionnaire asks.
Data processing under Art. 28 GDPR
Data processing agreement with the Art. 32 GDPR technical and organisational measures annex, ready to sign within 24 hours via the form on the DPA page. Deletion concept, access concept and incident response plan are provided on request.
Request the DPATransparency
Subprocessors
Complete list, each with purpose and processing location, matching the privacy policy. Changes are announced with a right to object. Two functions involve a language model from Anthropic with processing in the United States, covered by standard contractual clauses: the chat assistant in the structure editor and the interpretation feature in campaign analysis. All other tools operate without a language model and without third-country transfer.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the platform and the database | EUGermany |
| Supabase (database and authentication) | Data storage, accounts and login | EUEU region |
| Stripe Payments Europe Ltd. | Payment processing and invoicing | EUIreland |
| Microsoft 365 (Exchange Online) | Business email communication | EUEU region |
| Anthropic PBC | Language model for the chat assistant in the structure editor and for the interpretation feature in campaign analysis; transmits the structure being worked on, the conversation history and tool results or, for campaign analysis, statistical evaluations | Non-EUUSA (standard contractual clauses) |
| Cloudflare, Inc. | Domain name resolution and upstream network protection | Non-EUUSA (standard contractual clauses) |
| Resend (Plus Five Five, Inc.) | Delivery of system messages such as confirmations and billing notices | Non-EUUSA (standard contractual clauses) |
| Twilio SendGrid | Fallback path for delivering system messages | Non-EUUSA (standard contractual clauses) |
| Trustpilot A/S | Collection and display of customer reviews | EUDenmark |
| Google Ireland Ltd. | Website analytics, being replaced by our own analytics | Non-EUIreland (transfer to the USA possible) |
MolecularIQ
Measured on an independent benchmark
On the MolecularIQ benchmark, which we did not design (Bartmann et al., Klambauer Lab, JKU Linz), we measure our tools with symbolic verification against the stored solution, without a language model acting as judge.
- Models alone
- 14 to 41%
- With CovaSyn MCP
- 76 to 92%
Source: Bartmann C., Schimunek J., Ielanskyi M., Seidl P., Klambauer G., Luukkonen S. (2026). MolecularIQ: Characterizing Chemical Reasoning Capabilities Through Symbolic Verification on Molecular Graphs. arXiv:2601.15279. Snapshot: 2026-05-17.
FAQ
Frequently asked questions
Is our data used to train models?
No. Your inputs are processed solely to answer the respective request and are never used to train our own or third-party models. The commitment is part of the data processing agreement.
Where is our data kept?
In Germany, at Hetzner Online GmbH, with data held within the EU. On request the platform runs on your own infrastructure.
Is CovaSyn certified?
No. There is currently neither an ISO 27001 certification nor a SOC 2 report. The controls are documented in the SIG Lite and CAIQ v4 questionnaires, which you can download on this page.
Is the software validated?
No software ships fully validated at purchase. CovaSyn delivers audit-grade outputs and, on request, a validation pack with templates; validation of your use case takes place at your site.
Next step
We resolve open questions from QA or procurement together.
If your team needs more than this page and the questionnaires, we go through the points in the initial call.
30 minutes on Microsoft Teams with the CovaSyn team. If it is not a fit, we will say so.
