Security you can evaluate.
Concrete technical controls, explicit data handling policies, and an honest compliance roadmap. We document what we do so your security team can assess fit.
Concrete technical controls, explicit data handling policies, and an honest compliance roadmap. We document what we do so your security team can assess fit.
FluxMateria does not acquire any rights to your molecular data, material compositions, or computational results. Your structures, analyses, and decision packets remain your intellectual property. We are a computation tool, not a data business.
TLS 1.2+ enforced on all connections. HTTPS required for all API and web traffic. HSTS enabled.
AES-256 encryption for all stored data including molecular inputs, results, and audit logs. Encryption keys managed via AWS KMS.
| Capability | Pilot | Team | Enterprise |
|---|---|---|---|
| Email / password | ✓ | ✓ | ✓ |
| SSO (SAML 2.0 / OIDC) | — | — | ✓ |
| Multi-factor authentication | — | ✓ | ✓ |
| Role-based access control | — | ✓ | ✓ |
| Service accounts + API keys | — | ✓ | ✓ |
| Audit logging | Basic | ✓ | Full |
Six predefined roles with principle-of-least-privilege defaults:
API key authentication with per-key scoping and rotation support. Service accounts for programmatic access with configurable permissions.
Per-user and per-organization rate limits. Configurable thresholds on Enterprise plans. PostgreSQL-backed with Redis-ready upgrade path.
All API inputs validated via Pydantic schema enforcement. Malformed requests rejected before reaching compute. Structured error responses.
All API traffic over HTTPS (TLS 1.2+). HTTP requests redirected. No unencrypted API access permitted.
| Framework | Status | Details |
|---|---|---|
| SOC 2 Type 2 | In progress | Roadmap and controls documentation available on request |
| ISO 27001 | Planned | Targeted after SOC 2 completion |
| GDPR | Aligned | Data processing agreement available. EU data residency on Enterprise plans. |
| FDA 21 CFR Part 11 | Documentation available | Alignment documentation provided for Enterprise customers on request |
| HIPAA / BAA | Case-by-case | Available for Enterprise customers handling PHI |
We complete standard vendor security questionnaires (SIG Lite, CAIQ, custom). Contact security@fluxmateria.com to initiate the process.
We welcome security assessments during pilot and procurement discussions. Contact our security team for documentation, questionnaire completion, or technical architecture details.