MyelinMyelın
How it worksBriefSecurityVendor assessmentDevelopersSign in

Myelin · Vendor assessment pack

Pre-filled for your third-party risk review

Version 1.0 · Issued 31 July 2026 · Answers stated as enforced on that date

Adopting a new external-data vendor costs a governance function three to six months of its own work — subprocessor onboarding, DPIA input, records-of-processing update, third-party risk assessment, data classification, DPA. The constraint is your team’s capacity, not ours. So this page answers, in advance and in public, what that process asks: copy from it into your own templates, and cite it.

Every No, Partial and Planned below states its compensating control or its trigger, and none has been softened. We are a pre-first-customer, single-founder company; where a control assumes a team, the honest answer is here rather than in the meeting where you would otherwise find it. This document is not legal advice, and the final DPA is negotiated per client with counsel review.

Section 1

Vendor facts

The fields most third-party risk intake forms ask for before anything else.

Service

Transit and quality-review layer for R&D data exchanged between a sponsor and its external partners

Deployment model

Multi-tenant SaaS; delivered data lands in storage the sponsor owns and controls

Company stage

Pre-revenue, single-founder, POC → pilot. Stated openly wherever a control assumes a team

Data processing role

Processor. The sponsor is controller for research data, review metadata and account data

Primary data location

European Union — Ireland (database, staging), Dublin (compute), Belgium (transfer worker, backups)

Customer data retention

Transit-only. Staged files purged automatically 7 days after checksum-verified delivery

Certifications held

None. SOC 2 Type II / ISO 27001 deliberately sequenced — see §6 GRC and §7

Independent pen test

Not yet — commissioned at first pilot. Two internal adversarial reviews completed 2026-07

Cyber insurance

Not yet held; expected to be required by, and priced into, the first pilot contract

Special-category data

Research files may contain pseudonymized study-subject data. Myelin holds no re-identification key

Section 2

Processing roles

Myelin is a processor throughout. The sponsor is controller and defines the lawful basis.

Data categoryRoleNotes
Research data in transit (FASTQ, DICOM, WSI, …)ProcessorProcessed solely on documented instructions: stage → check → review → deliver → purge. May contain pseudonymized study-subject data; the sponsor remains controller, and Myelin never re-identifies and holds no key.
Review metadata (decisions, comments, votes, audit events)ProcessorGenerated inside the sponsor’s governed workflow and retained in the audit trail as the sponsor’s compliance record.
Account data of sponsor and partner usersProcessorUsers exist only because the sponsor operates bridges. A minimal independent-controller carve-out for service administration and security notices is standard and belongs in the DPA.

Myelin performs no profiling, no automated decision-making producing legal effects, no advertising use, and no training of models on customer data. One express carve-out is contractually defined rather than assumed: service improvement using de-identified, aggregated quality learnings — rule definitions and parameters, pass/fail statistics, finding categories — never file content, never personal data, and never anything identifying a client, partner or study. It is granted by a dedicated clause in the pilot contract and reflected in the DPA’s documented-instructions language, not left outside it.

Section 3

DPIA input — risks and mitigations

Written as input to your assessment, not as a substitute for it. The residual column is our own read; yours governs.

Re-identification of pseudonymized study subjects while data is in transit

Myelin never re-identifies and holds no key. Automated checks can block obvious identifiers in file and folder names (dates of birth, MRN-like and SSN-like patterns) before the delivery moves. Pseudonymization itself remains the sponsor’s control.

Residual Low — but note the path-level check does not read DICOM header tags (§7).

Unauthorized access to staged research files

Server-side authorization on every request through a single fail-closed path; Postgres Row-Level Security as an independent second layer; staged files reachable only through short-lived signed URLs issued after an authorization check; partner API keys scoped to named projects with a per-bridge kill switch the client operates.

Residual Low.

One tenant reaching another tenant’s data

Tenant isolation hardened and re-verified across every authorization site (2026-07-30), tested as two separate live tenants. The administrator role is a tenant-administrator with no cross-tenant reach; the only cross-tenant role provisions tenants and has zero customer-data access.

Residual Low.

Excessive retention — a second copy of research data accumulating at the vendor

Architecture-native: staging is transit-only. Staged copies are purged automatically 7 days after checksum-verified delivery, each purge recorded per file in the audit trail. Delivered data exists only in the sponsor’s own bucket.

Residual Low. Adopting Myelin creates no new long-term retention obligation for research data.

Personal data leaving the EU

Every tier holding or transiting research data and business data is EU. The single cross-border flow is transactional email — recipient name, email address and business metadata only, never file names, file content or checksums — under the provider’s DPA and EU-approved transfer mechanisms.

Residual Low. A Transfer Impact Assessment is needed only for that email flow, and its scope is deliberately trivial. EU email provider on the roadmap.

Tampering with the compliance record

Every state change appends to a SHA-256 hash-chained audit log. Database triggers reject UPDATE, DELETE and TRUNCATE even for the privileged role, and a persisted watermark defeats silent truncation. An automated job recomputes the full chain daily and writes its own verdict into the trail.

Residual Low. This is also the compensating control for the segregation-of-duties gap below.

Segregation of duties — a single founder holds administrative access

Stated openly rather than engineered around. Compensated by the append-only audit trail, which the privileged role cannot alter or delete, and by MFA on every infrastructure account. Hiring controls activate at first hire.

Residual Accepted risk at this stage, and the reason the audit trail is built the way it is. This is a real gap; assess it as one.

Vendor failure or discontinuity mid-engagement

Delivered data is already in the sponsor’s bucket and is unaffected. A delivery still in flight has never left the partner’s possession and can be sent the way it was sent before Myelin. The audit trail is exportable in full, on demand, by the sponsor’s own governance users. Nightly backups stream to a versioned EU bucket under a write-only identity and have been restore-tested.

Residual Low for delivered data. Continuous audit export into sponsor-controlled archive is on the roadmap (§7).

Subprocessor changed without the controller’s knowledge

Subprocessor register (§4) is re-issued on any change; general written authorization with a notice-and-objection window is accepted in the DPA.

Residual Low.

Section 4

Subprocessors and international transfers

Re-issued on any change. General written authorization with a notice-and-objection window is accepted in the DPA.

SubprocessorServiceData processedRegion
SupabasePostgres database, authentication, temporary file stagingBusiness data, account identifiers, temporary research files, audit trailEU — eu-west-1 (Ireland)
VercelApplication hosting and computeData in transit through the app; no primary data store. Research file bytes bypass Vercel entirelyEU — functions pinned to dub1 (Dublin)
Google CloudTransfer worker, database backups, destination object storageResearch files in transit; database backupsEU — europe-west1 (Belgium). Delivery destination is the sponsor’s own bucket, in the region the sponsor chooses
ResendTransactional emailRecipient name and email address; business metadata. Never file names, file content or checksumsUS — the only non-EU flow

Chapter V position: all primary data — database, staging, compute, backups, transfer worker — is EU by architecture, so no transfer mechanism is engaged. The one cross-border flow is transactional email metadata, covered by the provider’s DPA and EU-approved transfer mechanisms. A Transfer Impact Assessment is therefore needed only for that flow, and its scope is deliberately trivial: recipient name and email address plus business metadata, with no research data, file names or checksums.

Section 5

Technical and organisational measures (Art. 32)

The TOMs annex a DPA will ask for.

Encryption in transit

TLS on every hop — browser to staging, browser to app, app to database, worker to buckets, email

Encryption at rest

AES-256 with provider-managed keys. Customer-managed keys are a pilot-tier roadmap item

Access control

Three-layer role model (platform / bridge / project), enforced server-side through a single fail-closed authorization path, with Row-Level Security as an independent second layer

Credential handling

Partner API keys are 238-bit random secrets stored as SHA-256 hashes, shown once at issue, scoped to named projects, revocable individually or per bridge

Traceability

Append-only SHA-256 hash-chained audit log on every state change; chain recomputed daily by an automated job; export as CSV or a 21 CFR Part 11-styled PDF, each export itself audited

Delivery integrity

Per-file md5 recorded at delivery. Files stream with bounded memory and per-file checkpoints, so an interrupted terabyte-scale delivery resumes rather than restarts

Backups

Nightly logical backups to a versioned EU bucket under a write-only identity that cannot delete its own history. Restore-tested with the audit chain re-verified intact on the restored copy; quarterly cadence; independent freshness alerting

Environment separation

Production and staging separated end to end — distinct database projects, cloud projects and delivery identities. Production deploys only via pull request to a protected branch gated by CI including secret scanning

Monitoring

Independent alerting on backup failure, backup staleness, and terminal transfer failure

Vulnerability management

Automated dependency scanning on the application and CLI; findings tracked to closure in a version-controlled register

Incident response

Documented process — detect, contain, assess, notify, remediate, post-mortem — with severity tiers. Personal-data breach notification to the sponsor without undue delay, target within 72 hours

Section 6

Pre-answered security questionnaire

Grouped by CAIQ v4 domain; SIG-Lite categories map onto the same groups. When you send your own questionnaire, these are the answers you will get — so send it only if your process requires the artifact.

Application & interface security

Partial

Is the application developed under a secure SDLC?

TypeScript strict, lint and build gates before every merge, versioned schema migrations, protected release branch with CI. No formal SDLC policy document yet at this stage; change-control procedure is documented.

Yes

Are security requirements tested before release?

Every authorization-relevant change is verified live against seeded personas before push. Two internal adversarial security reviews completed in 2026, findings fixed or tracked openly.

Yes

Is user input validated server-side?

All mutations pass through server actions with server-side validation. The partner API validates against typed schemas and returns RFC 9457 problem+json.

Yes

Are APIs authenticated and rate-limited?

Bearer keys (238-bit CSPRNG, SHA-256 at rest), per-project scoping, rate limiting, and a client-operated kill switch per bridge.

Yes

Is there protection against OWASP Top-10 classes?

Server-side authorization on every route and action, RLS defence-in-depth, parameterized queries, CSP and security headers, SSRF guards with DNS re-resolution on the only user-supplied outbound fetch.

Identity & access management

Yes

Is access role-based and least-privilege?

Three-layer model (platform / bridge / project). A user must be a project member to see a project at all.

Yes

Are privileged roles restricted and audited?

The administrator role is a tenant-administrator with no cross-tenant reach (hardened and verified 2026-07-30). The only cross-tenant role provisions tenants and has zero customer-data access. Every privileged change lands in the audit trail.

Yes

Is authentication delegated to a managed identity provider?

Managed auth provider issuing JWTs, server-verified on every request.

Planned

Is MFA enforced for platform users?

Supported by the auth provider; enforcement is a pilot-tier item. All founder and operator accounts on every piece of infrastructure carry MFA today.

Yes

Can the customer revoke partner access themselves?

Client-side member removal, bridge pause and decommission, and a per-bridge API kill switch that blocks every partner key immediately.

Yes

Is there a joiner / mover / leaver process?

Documented access-lifecycle procedure. In-product removal is immediate — memberships are database rows checked on every request. Quarterly access recertification.

Cryptography & key management

Yes

Is data encrypted in transit and at rest?

TLS on every hop; AES-256 at rest with provider-managed keys.

Planned

Are customer-managed keys (CMEK/BYOK) supported?

Pilot-tier roadmap item, stated openly.

Yes

Are secrets managed outside code?

Platform environment variables and a cloud secret manager with EU replication. No secrets in the repository; CI runs automated secret scanning.

Data security & privacy lifecycle

Yes

Where does customer data reside?

EU. Database and staging in Ireland, compute in Dublin, transfer worker and backups in Belgium. Delivered data goes to the sponsor’s own bucket in the region the sponsor chooses.

Yes

Is customer data segregated between tenants?

Row-Level Security keyed on membership at the database layer plus application-layer scoping. Cross-tenant isolation re-verified as two live tenants, 2026-07-30.

No

Is production data used in test?

Staging runs on a separate project with synthetic personas and fixtures. Local development cannot reach production by construction.

Yes

Is data disposed of after use?

Staging is transit-only: automatic purge 7 days after checksum-verified delivery, audited per file. Delivered data lives only in sponsor storage.

Yes

Is data integrity verified end-to-end?

Per-file md5 recorded at delivery on every transfer, verified end-to-end in production.

No

Do you email or export customer file content?

Notification emails carry business metadata only — never file names, content or checksums.

Governance, risk & compliance

No

Do you hold SOC 2 or ISO 27001?

Deliberately sequenced: the observation-window clock starts when a contract requires it. The controlled documentation set is maintained audit-ready in the meantime. We would rather say this than imply otherwise.

Planned

Has an independent penetration test been performed?

Commissioned at first pilot. Two internal adversarial reviews were completed in 2026 with findings fixed or openly tracked.

Yes

Is there a risk register / findings tracker?

Every finding with status, severity and fix evidence, kept in version control alongside the code.

Partial

Are security policies documented?

Operational procedures for retention, audit review, access lifecycle, change control and incident response are documented. A formal ISMS policy set comes with the certification phase.

N/A

Is there security awareness training?

Single founder. Becomes applicable at first hire.

Personnel

N/A

Are personnel screened and under confidentiality terms?

Single founder and sole operator; NDAs are standard practice with prospects and partners. Hiring controls activate at first hire.

No

Is segregation of duties enforced?

Not possible at single-founder stage, and stated rather than engineered around. Compensating control: every administrative action lands in an append-only hash-chained audit trail that the privileged role cannot alter.

Infrastructure & resilience

Yes

Is infrastructure managed and patched by cloud providers?

Fully managed platforms throughout. No self-managed servers or virtual machines.

Yes

Are environments separated?

Production and staging separated end to end — distinct database projects, cloud projects and delivery identities. Production deploys only through a pull request to a protected branch gated by CI. Verified 2026-07-30.

Yes

Are backups performed and tested?

Nightly logical backups to a versioned EU bucket under a write-only identity. Restore-tested with the audit chain re-verified intact; quarterly cadence; independent freshness alerting.

Yes

What are your RPO and RTO?

RPO ≤ 24 hours; RTO measured in seconds at current volume, re-measured at each restore test. Point-in-time recovery is triggered by first pilot data.

Partial

Is there a disaster recovery plan?

The restore procedure is codified as an executable mode of the backup job, so it cannot drift from the code. A full DR runbook with scheduled drills is a phase-2 item.

Yes

Does customer data survive a vendor outage?

By design. Delivered data lives in the sponsor’s own bucket; Myelin staging is transit-only. Loss of Myelin never strands validated data.

Logging, monitoring & incident management

Yes

Are security-relevant events logged and tamper-protected?

Every state change appends to a hash-chained log. Database triggers reject UPDATE, DELETE and TRUNCATE even for the privileged role; a persisted watermark defeats truncation; the full chain is recomputed daily.

Yes

Can customers access relevant logs?

In-product activity views per scope, a governance audit-trail page with filters, and CSV or Part 11-styled PDF export — each export itself audited.

Yes

Is there a documented incident response process?

Detect, contain, assess, notify, remediate, post-mortem, with severity tiers.

Yes

Will customers be notified of breaches?

Without undue delay, target within 72 hours for personal-data breaches.

Supply chain

Yes

Is there a subprocessor register?

Published at §4 of this page and re-issued on any change.

Partial

Are subprocessor DPAs in place?

All four providers offer standard DPAs; countersignature and collection is an open action ahead of first pilot. Tracked, not hidden.

Yes

Do you notify customers of subprocessor changes?

Register re-issued on change; contractual notice-and-objection terms land with the pilot DPA.

Section 7

Records of processing — Art. 30 extract

Ready to paste into your RoPA.

Processing activity

Transit and quality review of sponsor R&D data; platform account administration

Categories of data subjects

Sponsor staff; partner staff; pseudonymized study subjects within research files (sponsor-controlled)

Categories of personal data

Account identifiers (name, email, role); review and audit metadata naming actors; pseudonymized subject data inside research files

Purpose

Secure transit, quality gating and traceable delivery of research data on the controller’s documented instructions

Recipients

Subprocessors listed in §4; the sponsor’s own storage on delivery

International transfers

Transactional email metadata to the US. No other transfer

Retention

Staging: purged 7 days after verified delivery · Database and audit trail: per DPA · Backups: 30-day rolling

Security measures

See §5

Section 8

Known gaps, stated in full

Nothing below is disclosed reluctantly. An assessment that discovers these later costs you more than one that starts from them.

  • ○No SOC 2 Type II or ISO 27001 certification. Deliberately deal-gated — the observation clock starts when a contract requires it.
  • ○No independent penetration test yet; commissioned at first pilot.
  • ○Segregation of duties is not achievable at single-founder stage. Compensated by the tamper-evident audit trail, not solved by it.
  • ○Subprocessor DPAs are available but not all countersigned and collected. Open founder action ahead of first pilot.
  • ○Transactional email metadata transits the US. No research data, file names or checksums are ever emailed; EU email provider on the roadmap.
  • ○Automated GDPR Art. 17 erasure path is in implementation. Staged-file deletion is immediate and audited today; database-held personal data is erased through a supervised manual procedure with an audit record in the interim.
  • ○Customer-managed encryption keys are not yet supported.
  • ○De-identification checks read file and folder paths, not DICOM header tags or burned-in pixel data. Quality checks can require a QC report but do not yet read the values inside it.
  • ○Continuous audit-trail export into sponsor-controlled archive is on the roadmap. Export is self-service and unlimited today.
  • ○No data protection officer appointed — not required at current scale; to be revisited at pilot scale.

Section 9

Available under NDA

The controlled documentation set behind every answer on this page.

System description and architecture · data-flow and residency register · access-control matrix as enforced · backup and recovery evidence with restore-test results · GxP scope and electronic-signature position · a 21 CFR Part 11 / Annex 11 control-traceability matrix · operational procedures · the internal adversarial review reports and the remediation register. Ask and we will send them.

Questions your process needs answered that are not on this page?

hello@myelinbridge.com

Security overview · Brief · Privacy notice

Print this page (Ctrl/Cmd + P) for a PDF you can attach to an assessment record.

MyelinMyelın

Accelerate the signal, protect your data

BriefVendor assessmentSecurityPrivacyDevelopersContact

© 2026 Myelin. EU infrastructure · transit, not storage.