Myelin · Vendor assessment pack
Pre-filled for your third-party risk review
Version 1.0 · Issued 31 July 2026 · Answers stated as enforced on that date
Adopting a new external-data vendor costs a governance function three to six months of its own work — subprocessor onboarding, DPIA input, records-of-processing update, third-party risk assessment, data classification, DPA. The constraint is your team’s capacity, not ours. So this page answers, in advance and in public, what that process asks: copy from it into your own templates, and cite it.
Every No, Partial and Planned below states its compensating control or its trigger, and none has been softened. We are a pre-first-customer, single-founder company; where a control assumes a team, the honest answer is here rather than in the meeting where you would otherwise find it. This document is not legal advice, and the final DPA is negotiated per client with counsel review.
Section 1
Vendor facts
The fields most third-party risk intake forms ask for before anything else.
Service
Transit and quality-review layer for R&D data exchanged between a sponsor and its external partners
Deployment model
Multi-tenant SaaS; delivered data lands in storage the sponsor owns and controls
Company stage
Pre-revenue, single-founder, POC → pilot. Stated openly wherever a control assumes a team
Data processing role
Processor. The sponsor is controller for research data, review metadata and account data
Primary data location
European Union — Ireland (database, staging), Dublin (compute), Belgium (transfer worker, backups)
Customer data retention
Transit-only. Staged files purged automatically 7 days after checksum-verified delivery
Certifications held
None. SOC 2 Type II / ISO 27001 deliberately sequenced — see §6 GRC and §7
Independent pen test
Not yet — commissioned at first pilot. Two internal adversarial reviews completed 2026-07
Cyber insurance
Not yet held; expected to be required by, and priced into, the first pilot contract
Special-category data
Research files may contain pseudonymized study-subject data. Myelin holds no re-identification key
Section 2
Processing roles
Myelin is a processor throughout. The sponsor is controller and defines the lawful basis.
| Data category | Role | Notes |
|---|---|---|
| Research data in transit (FASTQ, DICOM, WSI, …) | Processor | Processed solely on documented instructions: stage → check → review → deliver → purge. May contain pseudonymized study-subject data; the sponsor remains controller, and Myelin never re-identifies and holds no key. |
| Review metadata (decisions, comments, votes, audit events) | Processor | Generated inside the sponsor’s governed workflow and retained in the audit trail as the sponsor’s compliance record. |
| Account data of sponsor and partner users | Processor | Users exist only because the sponsor operates bridges. A minimal independent-controller carve-out for service administration and security notices is standard and belongs in the DPA. |
Myelin performs no profiling, no automated decision-making producing legal effects, no advertising use, and no training of models on customer data. One express carve-out is contractually defined rather than assumed: service improvement using de-identified, aggregated quality learnings — rule definitions and parameters, pass/fail statistics, finding categories — never file content, never personal data, and never anything identifying a client, partner or study. It is granted by a dedicated clause in the pilot contract and reflected in the DPA’s documented-instructions language, not left outside it.
Section 3
DPIA input — risks and mitigations
Written as input to your assessment, not as a substitute for it. The residual column is our own read; yours governs.
Re-identification of pseudonymized study subjects while data is in transit
Myelin never re-identifies and holds no key. Automated checks can block obvious identifiers in file and folder names (dates of birth, MRN-like and SSN-like patterns) before the delivery moves. Pseudonymization itself remains the sponsor’s control.
Residual Low — but note the path-level check does not read DICOM header tags (§7).
Unauthorized access to staged research files
Server-side authorization on every request through a single fail-closed path; Postgres Row-Level Security as an independent second layer; staged files reachable only through short-lived signed URLs issued after an authorization check; partner API keys scoped to named projects with a per-bridge kill switch the client operates.
Residual Low.
One tenant reaching another tenant’s data
Tenant isolation hardened and re-verified across every authorization site (2026-07-30), tested as two separate live tenants. The administrator role is a tenant-administrator with no cross-tenant reach; the only cross-tenant role provisions tenants and has zero customer-data access.
Residual Low.
Excessive retention — a second copy of research data accumulating at the vendor
Architecture-native: staging is transit-only. Staged copies are purged automatically 7 days after checksum-verified delivery, each purge recorded per file in the audit trail. Delivered data exists only in the sponsor’s own bucket.
Residual Low. Adopting Myelin creates no new long-term retention obligation for research data.
Personal data leaving the EU
Every tier holding or transiting research data and business data is EU. The single cross-border flow is transactional email — recipient name, email address and business metadata only, never file names, file content or checksums — under the provider’s DPA and EU-approved transfer mechanisms.
Residual Low. A Transfer Impact Assessment is needed only for that email flow, and its scope is deliberately trivial. EU email provider on the roadmap.
Tampering with the compliance record
Every state change appends to a SHA-256 hash-chained audit log. Database triggers reject UPDATE, DELETE and TRUNCATE even for the privileged role, and a persisted watermark defeats silent truncation. An automated job recomputes the full chain daily and writes its own verdict into the trail.
Residual Low. This is also the compensating control for the segregation-of-duties gap below.
Segregation of duties — a single founder holds administrative access
Stated openly rather than engineered around. Compensated by the append-only audit trail, which the privileged role cannot alter or delete, and by MFA on every infrastructure account. Hiring controls activate at first hire.
Residual Accepted risk at this stage, and the reason the audit trail is built the way it is. This is a real gap; assess it as one.
Vendor failure or discontinuity mid-engagement
Delivered data is already in the sponsor’s bucket and is unaffected. A delivery still in flight has never left the partner’s possession and can be sent the way it was sent before Myelin. The audit trail is exportable in full, on demand, by the sponsor’s own governance users. Nightly backups stream to a versioned EU bucket under a write-only identity and have been restore-tested.
Residual Low for delivered data. Continuous audit export into sponsor-controlled archive is on the roadmap (§7).
Subprocessor changed without the controller’s knowledge
Subprocessor register (§4) is re-issued on any change; general written authorization with a notice-and-objection window is accepted in the DPA.
Residual Low.
Section 4
Subprocessors and international transfers
Re-issued on any change. General written authorization with a notice-and-objection window is accepted in the DPA.
| Subprocessor | Service | Data processed | Region |
|---|---|---|---|
| Supabase | Postgres database, authentication, temporary file staging | Business data, account identifiers, temporary research files, audit trail | EU — eu-west-1 (Ireland) |
| Vercel | Application hosting and compute | Data in transit through the app; no primary data store. Research file bytes bypass Vercel entirely | EU — functions pinned to dub1 (Dublin) |
| Google Cloud | Transfer worker, database backups, destination object storage | Research files in transit; database backups | EU — europe-west1 (Belgium). Delivery destination is the sponsor’s own bucket, in the region the sponsor chooses |
| Resend | Transactional email | Recipient name and email address; business metadata. Never file names, file content or checksums | US — the only non-EU flow |
Chapter V position: all primary data — database, staging, compute, backups, transfer worker — is EU by architecture, so no transfer mechanism is engaged. The one cross-border flow is transactional email metadata, covered by the provider’s DPA and EU-approved transfer mechanisms. A Transfer Impact Assessment is therefore needed only for that flow, and its scope is deliberately trivial: recipient name and email address plus business metadata, with no research data, file names or checksums.
Section 5
Technical and organisational measures (Art. 32)
The TOMs annex a DPA will ask for.
Encryption in transit
TLS on every hop — browser to staging, browser to app, app to database, worker to buckets, email
Encryption at rest
AES-256 with provider-managed keys. Customer-managed keys are a pilot-tier roadmap item
Access control
Three-layer role model (platform / bridge / project), enforced server-side through a single fail-closed authorization path, with Row-Level Security as an independent second layer
Credential handling
Partner API keys are 238-bit random secrets stored as SHA-256 hashes, shown once at issue, scoped to named projects, revocable individually or per bridge
Traceability
Append-only SHA-256 hash-chained audit log on every state change; chain recomputed daily by an automated job; export as CSV or a 21 CFR Part 11-styled PDF, each export itself audited
Delivery integrity
Per-file md5 recorded at delivery. Files stream with bounded memory and per-file checkpoints, so an interrupted terabyte-scale delivery resumes rather than restarts
Backups
Nightly logical backups to a versioned EU bucket under a write-only identity that cannot delete its own history. Restore-tested with the audit chain re-verified intact on the restored copy; quarterly cadence; independent freshness alerting
Environment separation
Production and staging separated end to end — distinct database projects, cloud projects and delivery identities. Production deploys only via pull request to a protected branch gated by CI including secret scanning
Monitoring
Independent alerting on backup failure, backup staleness, and terminal transfer failure
Vulnerability management
Automated dependency scanning on the application and CLI; findings tracked to closure in a version-controlled register
Incident response
Documented process — detect, contain, assess, notify, remediate, post-mortem — with severity tiers. Personal-data breach notification to the sponsor without undue delay, target within 72 hours
Section 6
Pre-answered security questionnaire
Grouped by CAIQ v4 domain; SIG-Lite categories map onto the same groups. When you send your own questionnaire, these are the answers you will get — so send it only if your process requires the artifact.
Application & interface security
Is the application developed under a secure SDLC?
TypeScript strict, lint and build gates before every merge, versioned schema migrations, protected release branch with CI. No formal SDLC policy document yet at this stage; change-control procedure is documented.
Are security requirements tested before release?
Every authorization-relevant change is verified live against seeded personas before push. Two internal adversarial security reviews completed in 2026, findings fixed or tracked openly.
Is user input validated server-side?
All mutations pass through server actions with server-side validation. The partner API validates against typed schemas and returns RFC 9457 problem+json.
Are APIs authenticated and rate-limited?
Bearer keys (238-bit CSPRNG, SHA-256 at rest), per-project scoping, rate limiting, and a client-operated kill switch per bridge.
Is there protection against OWASP Top-10 classes?
Server-side authorization on every route and action, RLS defence-in-depth, parameterized queries, CSP and security headers, SSRF guards with DNS re-resolution on the only user-supplied outbound fetch.
Identity & access management
Is access role-based and least-privilege?
Three-layer model (platform / bridge / project). A user must be a project member to see a project at all.
Are privileged roles restricted and audited?
The administrator role is a tenant-administrator with no cross-tenant reach (hardened and verified 2026-07-30). The only cross-tenant role provisions tenants and has zero customer-data access. Every privileged change lands in the audit trail.
Is authentication delegated to a managed identity provider?
Managed auth provider issuing JWTs, server-verified on every request.
Is MFA enforced for platform users?
Supported by the auth provider; enforcement is a pilot-tier item. All founder and operator accounts on every piece of infrastructure carry MFA today.
Can the customer revoke partner access themselves?
Client-side member removal, bridge pause and decommission, and a per-bridge API kill switch that blocks every partner key immediately.
Is there a joiner / mover / leaver process?
Documented access-lifecycle procedure. In-product removal is immediate — memberships are database rows checked on every request. Quarterly access recertification.
Cryptography & key management
Is data encrypted in transit and at rest?
TLS on every hop; AES-256 at rest with provider-managed keys.
Are customer-managed keys (CMEK/BYOK) supported?
Pilot-tier roadmap item, stated openly.
Are secrets managed outside code?
Platform environment variables and a cloud secret manager with EU replication. No secrets in the repository; CI runs automated secret scanning.
Data security & privacy lifecycle
Where does customer data reside?
EU. Database and staging in Ireland, compute in Dublin, transfer worker and backups in Belgium. Delivered data goes to the sponsor’s own bucket in the region the sponsor chooses.
Is customer data segregated between tenants?
Row-Level Security keyed on membership at the database layer plus application-layer scoping. Cross-tenant isolation re-verified as two live tenants, 2026-07-30.
Is production data used in test?
Staging runs on a separate project with synthetic personas and fixtures. Local development cannot reach production by construction.
Is data disposed of after use?
Staging is transit-only: automatic purge 7 days after checksum-verified delivery, audited per file. Delivered data lives only in sponsor storage.
Is data integrity verified end-to-end?
Per-file md5 recorded at delivery on every transfer, verified end-to-end in production.
Do you email or export customer file content?
Notification emails carry business metadata only — never file names, content or checksums.
Governance, risk & compliance
Do you hold SOC 2 or ISO 27001?
Deliberately sequenced: the observation-window clock starts when a contract requires it. The controlled documentation set is maintained audit-ready in the meantime. We would rather say this than imply otherwise.
Has an independent penetration test been performed?
Commissioned at first pilot. Two internal adversarial reviews were completed in 2026 with findings fixed or openly tracked.
Is there a risk register / findings tracker?
Every finding with status, severity and fix evidence, kept in version control alongside the code.
Are security policies documented?
Operational procedures for retention, audit review, access lifecycle, change control and incident response are documented. A formal ISMS policy set comes with the certification phase.
Is there security awareness training?
Single founder. Becomes applicable at first hire.
Personnel
Are personnel screened and under confidentiality terms?
Single founder and sole operator; NDAs are standard practice with prospects and partners. Hiring controls activate at first hire.
Is segregation of duties enforced?
Not possible at single-founder stage, and stated rather than engineered around. Compensating control: every administrative action lands in an append-only hash-chained audit trail that the privileged role cannot alter.
Infrastructure & resilience
Is infrastructure managed and patched by cloud providers?
Fully managed platforms throughout. No self-managed servers or virtual machines.
Are environments separated?
Production and staging separated end to end — distinct database projects, cloud projects and delivery identities. Production deploys only through a pull request to a protected branch gated by CI. Verified 2026-07-30.
Are backups performed and tested?
Nightly logical backups to a versioned EU bucket under a write-only identity. Restore-tested with the audit chain re-verified intact; quarterly cadence; independent freshness alerting.
What are your RPO and RTO?
RPO ≤ 24 hours; RTO measured in seconds at current volume, re-measured at each restore test. Point-in-time recovery is triggered by first pilot data.
Is there a disaster recovery plan?
The restore procedure is codified as an executable mode of the backup job, so it cannot drift from the code. A full DR runbook with scheduled drills is a phase-2 item.
Does customer data survive a vendor outage?
By design. Delivered data lives in the sponsor’s own bucket; Myelin staging is transit-only. Loss of Myelin never strands validated data.
Logging, monitoring & incident management
Are security-relevant events logged and tamper-protected?
Every state change appends to a hash-chained log. Database triggers reject UPDATE, DELETE and TRUNCATE even for the privileged role; a persisted watermark defeats truncation; the full chain is recomputed daily.
Can customers access relevant logs?
In-product activity views per scope, a governance audit-trail page with filters, and CSV or Part 11-styled PDF export — each export itself audited.
Is there a documented incident response process?
Detect, contain, assess, notify, remediate, post-mortem, with severity tiers.
Will customers be notified of breaches?
Without undue delay, target within 72 hours for personal-data breaches.
Supply chain
Is there a subprocessor register?
Published at §4 of this page and re-issued on any change.
Are subprocessor DPAs in place?
All four providers offer standard DPAs; countersignature and collection is an open action ahead of first pilot. Tracked, not hidden.
Do you notify customers of subprocessor changes?
Register re-issued on change; contractual notice-and-objection terms land with the pilot DPA.
Section 7
Records of processing — Art. 30 extract
Ready to paste into your RoPA.
Processing activity
Transit and quality review of sponsor R&D data; platform account administration
Categories of data subjects
Sponsor staff; partner staff; pseudonymized study subjects within research files (sponsor-controlled)
Categories of personal data
Account identifiers (name, email, role); review and audit metadata naming actors; pseudonymized subject data inside research files
Purpose
Secure transit, quality gating and traceable delivery of research data on the controller’s documented instructions
Recipients
Subprocessors listed in §4; the sponsor’s own storage on delivery
International transfers
Transactional email metadata to the US. No other transfer
Retention
Staging: purged 7 days after verified delivery · Database and audit trail: per DPA · Backups: 30-day rolling
Security measures
See §5
Section 8
Known gaps, stated in full
Nothing below is disclosed reluctantly. An assessment that discovers these later costs you more than one that starts from them.
- No SOC 2 Type II or ISO 27001 certification. Deliberately deal-gated — the observation clock starts when a contract requires it.
- No independent penetration test yet; commissioned at first pilot.
- Segregation of duties is not achievable at single-founder stage. Compensated by the tamper-evident audit trail, not solved by it.
- Subprocessor DPAs are available but not all countersigned and collected. Open founder action ahead of first pilot.
- Transactional email metadata transits the US. No research data, file names or checksums are ever emailed; EU email provider on the roadmap.
- Automated GDPR Art. 17 erasure path is in implementation. Staged-file deletion is immediate and audited today; database-held personal data is erased through a supervised manual procedure with an audit record in the interim.
- Customer-managed encryption keys are not yet supported.
- De-identification checks read file and folder paths, not DICOM header tags or burned-in pixel data. Quality checks can require a QC report but do not yet read the values inside it.
- Continuous audit-trail export into sponsor-controlled archive is on the roadmap. Export is self-service and unlimited today.
- No data protection officer appointed — not required at current scale; to be revisited at pilot scale.
Section 9
Available under NDA
The controlled documentation set behind every answer on this page.
System description and architecture · data-flow and residency register · access-control matrix as enforced · backup and recovery evidence with restore-test results · GxP scope and electronic-signature position · a 21 CFR Part 11 / Annex 11 control-traceability matrix · operational procedures · the internal adversarial review reports and the remediation register. Ask and we will send them.
Questions your process needs answered that are not on this page?
hello@myelinbridge.comSecurity overview · Brief · Privacy notice
Print this page (Ctrl/Cmd + P) for a PDF you can attach to an assessment record.