Genedata Trust Center

Confidence comes from evidence.

Bring your security, architecture, privacy, and procurement questions into one review. Understand the controls, the deployment boundary, and the commitments for your workload.

Identity and access

Review workspace boundaries, single sign-on, role permissions, and the row and column controls required by your workload.

Evidence to review

Request an access-control walkthrough using your proposed roles and datasets.

Security capabilities

Encryption and secrets

Stored secrets use envelope encryption. Review transport security, key ownership, and rotation responsibilities for each connection and deployment.

Evidence to review

Request the key-management design and verify the transport settings for your selected sources.

Security architecture

Audit and governance

Keep policy decisions, ownership, and activity evidence connected to the workflows they govern.

Evidence to review

Review a representative access event, its evidence, and the retention policy with your control owner.

Governance capabilities

Privacy and data handling

Review the purposes of processing, deletion process, subprocessors, and contractual responsibilities before onboarding personal data.

Evidence to review

Use the privacy policy and DPA as the starting point for your legal review.

Data Processing Addendum

AI and human oversight

Agree which models may process your data, what context is sent, how outputs are reviewed, and who may authorize an action.

Evidence to review

Confirm provider-specific retention and training terms for the selected model configuration during the review.

AI and agent capabilities

Operations and recovery

Agree service objectives, escalation ownership, backups, and recovery acceptance criteria for the production workload.

Evidence to review

Request the operational runbook and validate recovery expectations against the contracted service scope.

Service-level agreement

Framework status, stated clearly.

SOC 2 controls are mapped; attestation has not been performed. ISO 27001 certification is not held. Framework mapping describes documented control alignment, not independent certification.

Review current compliance status
Architecture and deployment

Agree the boundary before moving the data.

Review managed cloud, customer-cloud, or jurisdiction-bound deployment requirements with the team. Region availability and service commitments are confirmed in the deployment proposal and contract.

Data boundarySources, storage locations, transfers, retention, and deletion
Control boundaryIdentity, policy, secrets, audit access, and operator responsibilities
Service boundaryInfrastructure ownership, support, backups, and recovery acceptance
Enterprise review pack

Prepare a complete evaluation.

Use this checklist with your technical, legal, and business owners. Request the applicable security evidence and deployment documents directly from the Genedata team.

Procurement checklist

0 / 8 complete