Current position
Yendou is an EU hosted, multi tenant platform for pre-award commercial and clinical operations. Customer data is tenant isolated, encrypted and role restricted. Persistent customer data is not used to train Yendou models or third party foundation models.
A diligence overview, not a certificate, legal opinion or substitute for your own validation and operating procedures. Contractual commitments are established in the executed agreement, DPA and implementation scope.
Scope and responsibility
Intended processing scope
- Business and professional contact data for investigators, coordinators, research sites and customer personnel.
- RFIs, RFPs, feasibility responses, site intelligence, study startup records, documents, email, approvals and audit evidence.
- Authentication, single sign on, encrypted connected service credentials, security telemetry and product usage events.
Patient and clinical trial subject data are not part of the intended scope. Customers should prevent their inclusion unless a separately reviewed and contracted use case permits it.
Shared responsibility
Architecture, hosting and data boundaries
Data residency
- Application data, databases, uploaded files, search indexes, stored embeddings, operational logs and backups are retained in the European Union under the current documented architecture.
- Authorized AI inference may be processed in the United States using the minimum relevant content and contractual transfer safeguards.
- Transactional or optional outbound email may use a United States provider according to the configured delivery route.
- Yendou does not provide hosting in mainland China. Authorized users can access relevant workflows from mainland China, and implementation testing is recommended.
Customer created data is isolated through organization scoped application authorization and PostgreSQL row level security. Application transactions execute in an organization context.
Identity, access and cryptography
Identity and access
- Unique user accounts, role based access and least privilege administration.
- Customer administrators control customer facing access. Onboarding and offboarding govern internal accounts.
- Authorized production administration requires VPN access and multi factor authentication.
- Runtime services use Azure managed identities. Delivery pipelines use GitHub OIDC federation rather than stored deployment credentials.
Encryption and key management
AI processing can be disabled for your tenant. When it is disabled, customer content is not sent to an AI provider for inference.
Auditability and Part 11 support
Yendou provides technical controls intended to support trustworthy electronic records and governed review. Part 11 suitability depends on the configured workflow, the records in scope, validated intended use and customer procedures.
Yendou supports 21 CFR Part 11 aligned electronic record controls. Part 11 applies to electronic records and signatures within a regulated process: Yendou provides supporting technical controls, and the customer determines intended use and completes procedural and validation responsibilities. We do not make a blanket certification claim.
GDPR, privacy and AI governance
Privacy controls
- Data minimization and purpose limitation within configured workflows.
- Support for access, correction, export, objection and deletion requests under the DPA.
- EU 2021/914 Standard Contractual Clauses, transfer impact assessment and supplementary measures for restricted transfers where applicable.
- Written subprocessor terms, confidentiality and security obligations, change notice and transfer safeguards.
- Structured export and deletion or anonymization under the agreed exit and retention schedule, including protected backup expiry.
AI data handling
- Customer content is never used to train Yendou models or third party foundation models.
- AI processing occurs only in an enabled workflow invoked by an authorized user.
- Only the minimum relevant content is sent for the requested inference.
- Content is not shared across customers or added to a shared Yendou knowledge base.
- Source attribution, SME review and approval provide human governance for generated responses.
Monitoring, incident response and resilience
Monitoring and secure operations
- Azure Log Analytics and Application Insights collect infrastructure and application telemetry.
- Automated alerting covers application error rates, firewall blocking spikes, and database CPU and connection thresholds.
- Infrastructure as code, code review, automated testing, dependency scanning and OIDC based deployment support controlled change.
- Production resource locks and lifecycle protections reduce accidental destructive change.
Incident lifecycle
- Detect and assess. Centralized telemetry, alerts and engineering triage establish scope and severity.
- Contain and remediate. Access isolation, credential rotation, corrective deployment and recovery actions are coordinated.
- Notify. Qualifying personal data breaches are handled without undue delay under the DPA and applicable GDPR Article 33 and 34 obligations.
- Review. Root cause analysis and control improvements follow material incidents.
Availability and recovery
Assurance roadmap and diligence package
Yendou operates a SOC 2 aligned control framework, and the Type II certification and attestation programme is in progress. The latest documented completion target is Q4 2026. Until the report is issued, the status is certification in progress.
The ISO 27001 operational framework and certification programme are planned after the SOC 2 programme, with a latest documented target of H1 2027. Until certification is issued, the status is planned.
Available through enterprise diligence
- Platform architecture and data flow documentation.
- Security control and email encryption descriptions.
- DPA, subprocessor schedule, transfer and incident response information.
- Assurance roadmap evidence, subject to confidentiality controls.
- Implementation specific data mapping, role model, retention configuration and validation evidence.
References: eCFR 21 CFR Part 11 · U.S. FDA Part 11 Scope and Application · EUR-Lex Regulation (EU) 2016/679.
Evidence basis. Consolidated from Yendou architecture, email security, data protection, DPA and enterprise diligence materials reviewed through 18 August 2026. Customer specific commercial terms and named customer information are excluded.