CovaSyn

Trust & Compliance

What pharma QA can expect from a software vendor, precise, regulatory-aware, no marketing speak.

What happens to your molecular structures

This is the first question pharma procurement asks, and it deserves an answer without hesitation. Uploaded structures are drug candidates, the most valuable thing a customer has.

No use for training

Your inputs are processed solely to answer the respective request and are never used to train our own or third-party models. This commitment sits in the data processing agreement, not just on this page. The model providers we use are contractually excluded from it too.

Tenant separation

Every record belongs to an account, and separation is enforced at row level in the database, not only in the application. Access through a foreign account returns no rows, not a filtered view.

EU hosting

Operated in Germany at Hetzner Online GmbH, data held within the EU, no mirroring outside the EU. For enterprise, optionally as a container on your own infrastructure.

Deletion on request

Deleted on request within 30 days, including backup copies within their rotation cycle. After contract end within 90 days. Rights to inputs and results remain entirely yours.

Independent Benchmark (ICLR 2026)

On the peer-reviewed MolecularIQ benchmark (Bartmann et al., Klambauer Lab JKU Linz, ICLR 2026), frontier LLMs score 14 to 41 percent on chemical structure analysis. With CovaSyn MCP attached, the same models reach 76 to 92 percent. Four models, 3,540 verified tasks, 12,540 responses. Symbolic verification against ground truth, no LLM judges.

ModelBaseline+ CovaSyn MCPΔ
Claude Haiku 4.521.18 %85.38 %+64.2 pp · 4.03×
Claude Opus 4.740.75 %91.51 %+50.8 pp · 2.25×
OpenAI GPT-5.522.29 %89.92 %+67.6 pp · 4.03×
Gemini 3.5 Flash13.68 %75.66 %+61.98 pp · 5.53×

Source: Bartmann C., Schimunek J., Ielanskyi M., Seidl P., Klambauer G., Luukkonen S. (2026). MolecularIQ: Characterizing Chemical Reasoning Capabilities Through Symbolic Verification on Molecular Graphs. ICLR 2026 (Poster). arXiv:2601.15279. Snapshot: 2026-05-17.

Benchmark summary: score across all six model × configuration combinations
Full benchmark data

Compliance Posture

FrameworkStatusNote
EU Annex 11 (Computerised Systems)AlignedAudit trail, determinism, access control built-in
21 CFR Part 11 (Electronic Records)AlignedTamper evidence via output hashing, signed audit logs
GAMP 5 (Software Category 4)Configured ProductConfiguration only, no custom code at customer site
ICH M7 (R2) Mutagenic ImpurityDedicated ToolsMutagenicity assessment plus expert review workflow
ICH Q1A/E StabilityDedicated ToolsArrhenius fit and shelf-life estimation with 95% CI
ICH Q12 Lifecycle ManagementReadinessVersioning and change-control pathways documented

What 'Aligned' actually means here

Three measurable properties, not a marketing label:

Determinism

Tool versions are pinned. Identical input → identical output, reproducible weeks later. No RNG seed drift, no LLM probabilism in the numerical path.

Audit Trail

Every tool call is logged with input, output, tool version, timestamp, and API key ID. Logs are exportable as CSV or JSON.

Tamper Evidence

Output includes a SHA-256 hash. If an audit log entry is modified post-hoc, re-hashing surfaces the change.

What validation means at CovaSyn

What we do NOT claim

Security questionnaires, pre-filled

SIG Lite and CAIQ v4 are fully answered and available here. Both are generated from a single maintained answer library, so one edit takes effect in both at once. Together they cover most of what a company-specific questionnaire asks. If your procurement insists on their own form, it is filled in one to two hours instead of two weeks.

Data processing agreement with the Art. 32 GDPR technical and organisational measures annex, deletion concept, access concept and incident response plan are provided on request.

Subprocessors

Complete list, each with purpose and processing location. Changes are announced with a right to object.

ProviderPurposeLocation
Hetzner Online GmbHHosting of the platform and the databaseEUDeutschland
Supabase (Datenbank und Authentifizierung)Data storage, accounts and loginEUEU-Region
Stripe Payments Europe Ltd.Payment processing and invoicingEUIrland
Microsoft 365 (Exchange Online)Business email communicationEUEU-Region
Anthropic PBCLanguage model for the chat assistant in the structure editor and for the interpretation feature in campaign analysis; transmits the structure being worked on, the conversation history and tool results, respectively statistical evaluationsNon-EUUSA (Standardvertragsklauseln)
Cloudflare, Inc.Domain name resolution and upstream network protectionNon-EUUSA (Standardvertragsklauseln)
Resend (Plus Five Five, Inc.)Delivery of system messages such as confirmations and billing noticesNon-EUUSA (Standardvertragsklauseln)
Twilio SendGridFallback path for delivering system messagesNon-EUUSA (Standardvertragsklauseln)
Trustpilot A/SCollection and display of customer reviewsEUDänemark
Google Ireland Ltd.Website reach measurement, being replaced by our own measurementNon-EUIrland (Datenübermittlung in die USA möglich)

Report a vulnerability

Reports go to security@covasyn.com. We respond to legitimate reports within 5 business days and work with coordinated disclosure, 90 days. The machine-readable version is at /.well-known/security.txt per RFC 9116.

Need the validation pack?

Included in the Enterprise tier. Book a discovery call for a walkthrough.

Trust & Compliance | CovaSyn