Yendou
  • RFI
  • Country & Site ID
  • Feasibility
  • Resources
    ResourcesCustomersWhat CROs and sites reportIdeasEssays on how CROs win bids
    Get startedBook a walkthroughSee the platform on your own RFPsLog inapp.yendou.com
  • Company
Log in Try Yendou
  • RFI
  • Country & Site ID
  • Feasibility
  • CustomersIdeas
  • Company

Try Yendou Log in
Enterprise ready

Security & Compliance

Version 1.1 · Issued 18 August 2026

Built for regulated clinical research, with controls that fit established customer governance.

Regulatory
GDPR21 CFR Part 11
Controls
No AI trainingImmutable audit logsRole-based access
Compliance
ISO 27001SOC 2 Type II

Current position

Yendou is an EU hosted, multi tenant platform for pre-award commercial and clinical operations. Customer data is tenant isolated, encrypted and role restricted. Persistent customer data is not used to train Yendou models or third party foundation models.

21 CFR Part 11
Control support. Append only document audit records, hashes and time and user linked events support regulated electronic record workflows. Intended use validation remains shared.
GDPR
Operational framework. DPA governed processing, EU persistence, data subject support and transfer safeguards are documented.
SOC 2 Type II
Certification in progress. The operational framework is active. Latest documented target for the Type II report: Q4 2026.
ISO 27001
Framework active. The operational framework is active. The certification programme is planned. Latest documented target: H1 2027.
What this document is

A diligence overview, not a certificate, legal opinion or substitute for your own validation and operating procedures. Contractual commitments are established in the executed agreement, DPA and implementation scope.

Scope and responsibility

Intended processing scope

  • Business and professional contact data for investigators, coordinators, research sites and customer personnel.
  • RFIs, RFPs, feasibility responses, site intelligence, study startup records, documents, email, approvals and audit evidence.
  • Authentication, single sign on, encrypted connected service credentials, security telemetry and product usage events.
Out of scope

Patient and clinical trial subject data are not part of the intended scope. Customers should prevent their inclusion unless a separately reviewed and contracted use case permits it.

Shared responsibility

Yendou
Platform security, tenant isolation, encryption, logging and secure delivery. Documented incident, continuity, backup and recovery processes. Subprocessor governance and agreed transfer safeguards.
You
User authorization, source data quality, role assignment and timely offboarding. Intended use assessment, standard operating procedures, training and validation for regulated workflows. Selection of enabled integrations, approved repositories and retention requirements.

Architecture, hosting and data boundaries

Cloud
Microsoft Azure production architecture with independent development, staging and production environments.
Application
Azure Container Apps, autoscaling and rolling deployments behind Azure Front Door Premium and a web application firewall.
Data
Azure Database for PostgreSQL, Redis, pgvector, encrypted object storage and Azure Key Vault.
Network
Private virtual networks and private endpoints for managed data services, with controlled public ingress at the edge.
Identity
Microsoft Entra ID and Google OpenID Connect, with customer roles and just in time provisioning.
Operations
Infrastructure as code, reviewed deployment plans, OIDC continuous delivery and centralized observability.

Data residency

  • Application data, databases, uploaded files, search indexes, stored embeddings, operational logs and backups are retained in the European Union under the current documented architecture.
  • Authorized AI inference may be processed in the United States using the minimum relevant content and contractual transfer safeguards.
  • Transactional or optional outbound email may use a United States provider according to the configured delivery route.
  • Yendou does not provide hosting in mainland China. Authorized users can access relevant workflows from mainland China, and implementation testing is recommended.
Tenant boundary Available

Customer created data is isolated through organization scoped application authorization and PostgreSQL row level security. Application transactions execute in an organization context.

Identity, access and cryptography

Identity and access

  • Unique user accounts, role based access and least privilege administration.
  • Customer administrators control customer facing access. Onboarding and offboarding govern internal accounts.
  • Authorized production administration requires VPN access and multi factor authentication.
  • Runtime services use Azure managed identities. Delivery pipelines use GitHub OIDC federation rather than stored deployment credentials.

Encryption and key management

Transport
TLS 1.2 or above for external and internal service connections.
General storage
AES-256 or Azure Storage Service Encryption.
Email and OAuth secrets
Per record or per credential set AES-256-GCM envelope encryption.
Key wrapping
Organization specific RSA-OAEP-256 keys protected in HSM backed Azure Key Vault.
Key handling
Production private key material is non exportable. Authorized wrap and unwrap operations are logged.
Rotation
Organization keys rotate automatically every 60 days. Data keys are re-wrapped without re-encrypting content.
AI disablement Configurable

AI processing can be disabled for your tenant. When it is disabled, customer content is not sent to an AI provider for inference.

Auditability and Part 11 support

Yendou provides technical controls intended to support trustworthy electronic records and governed review. Part 11 suitability depends on the configured workflow, the records in scope, validated intended use and customer procedures.

Attributable activity
Role based access and user linked actions. Email decryption records include user ID and timestamp.
Record integrity
Defined document audit records are append only, with insert and select but no update or delete, and store document hash and evidence paths.
Change evidence
Collaborative document content audit records use SHA-256 content hashing per edit and are immutable.
Infrastructure audit
Database, Key Vault, storage, application, firewall, Container Apps and VPN events are centrally logged.
Retention
Core production diagnostic and audit logs are documented with 365 day retention. Contract specific requirements should be confirmed.
Review and approval
Source visibility, SME routing, human review, approval history and controlled library reuse support governed workflows.
How we word the claim Customer validation

Yendou supports 21 CFR Part 11 aligned electronic record controls. Part 11 applies to electronic records and signatures within a regulated process: Yendou provides supporting technical controls, and the customer determines intended use and completes procedural and validation responsibilities. We do not make a blanket certification claim.

GDPR, privacy and AI governance

Processor
Customer entered records, documents, email and workflow data, governed by documented customer instructions, the contract and the DPA.
Independent controller
Reference data from publicly available professional and research site sources, under a legitimate interests framework with transparency, objection, correction and removal.

Privacy controls

  • Data minimization and purpose limitation within configured workflows.
  • Support for access, correction, export, objection and deletion requests under the DPA.
  • EU 2021/914 Standard Contractual Clauses, transfer impact assessment and supplementary measures for restricted transfers where applicable.
  • Written subprocessor terms, confidentiality and security obligations, change notice and transfer safeguards.
  • Structured export and deletion or anonymization under the agreed exit and retention schedule, including protected backup expiry.

AI data handling

  • Customer content is never used to train Yendou models or third party foundation models.
  • AI processing occurs only in an enabled workflow invoked by an authorized user.
  • Only the minimum relevant content is sent for the requested inference.
  • Content is not shared across customers or added to a shared Yendou knowledge base.
  • Source attribution, SME review and approval provide human governance for generated responses.

Monitoring, incident response and resilience

Monitoring and secure operations

  • Azure Log Analytics and Application Insights collect infrastructure and application telemetry.
  • Automated alerting covers application error rates, firewall blocking spikes, and database CPU and connection thresholds.
  • Infrastructure as code, code review, automated testing, dependency scanning and OIDC based deployment support controlled change.
  • Production resource locks and lifecycle protections reduce accidental destructive change.

Incident lifecycle

  • Detect and assess. Centralized telemetry, alerts and engineering triage establish scope and severity.
  • Contain and remediate. Access isolation, credential rotation, corrective deployment and recovery actions are coordinated.
  • Notify. Qualifying personal data breaches are handled without undue delay under the DPA and applicable GDPR Article 33 and 34 obligations.
  • Review. Root cause analysis and control improvements follow material incidents.

Availability and recovery

Database
Zone redundant production high availability with automatic failover.
Backups
35 day production point in time recovery and EU geo-redundant backup.
Object storage
EU geo-redundant production storage and deletion protection.
Recovery objectives
Recovery point objective no more than 4 hours. Recovery time objective no more than 24 hours.
Testing
Periodic restoration, redeployment and business continuity testing.

Assurance roadmap and diligence package

SOC 2 Type II Configurable

Yendou operates a SOC 2 aligned control framework, and the Type II certification and attestation programme is in progress. The latest documented completion target is Q4 2026. Until the report is issued, the status is certification in progress.

ISO 27001 Scoped

The ISO 27001 operational framework and certification programme are planned after the SOC 2 programme, with a latest documented target of H1 2027. Until certification is issued, the status is planned.

Available through enterprise diligence

  • Platform architecture and data flow documentation.
  • Security control and email encryption descriptions.
  • DPA, subprocessor schedule, transfer and incident response information.
  • Assurance roadmap evidence, subject to confidentiality controls.
  • Implementation specific data mapping, role model, retention configuration and validation evidence.

References: eCFR 21 CFR Part 11 · U.S. FDA Part 11 Scope and Application · EUR-Lex Regulation (EU) 2016/679.

Evidence basis. Consolidated from Yendou architecture, email security, data protection, DPA and enterprise diligence materials reviewed through 18 August 2026. Customer specific commercial terms and named customer information are excluded.

Yendou

Clinical Research Infrastructure for mid-cap CROs

Product

RFI Processing Country & Site ID Site Feasibility

Company

About Customers

Resources

Trials & Triumphs Ideas Integrations Security & Compliance

Follow

LinkedIn X

Legal

Imprint Privacy Cookies
© 2026 Yendou GmbH · Berlin, Germany Made for the work between RFI and First Patient In

We use essential cookies to run this site. With your consent, we also use analytics cookies to understand how the site is used and improve it. See our Cookie Policy.

Partner with us

Tell us where Yendou can move your next bid, or your next study. We read every message.

What are you trying to improve?

We’ll only use this to reply. Read our Privacy Policy.