Skip to content

Compliance and trust

Audit-ready from day one.

Compliance wraps the entire platform: it is the architecture, not a feature. This page is written for the quality, legal, security and procurement teams who will review us.

What Genovant is for, and what it is not.

In scope

  • Protocol design
  • Evidence synthesis
  • Cohort feasibility
  • Health economics and market access

Not in scope

Genovant is not a medical device. It does not diagnose, and it does not recommend treatment for an identifiable patient. Those requests are declined before any retrieval runs, and the decision is written to the audit trail.

Intended-use boundary

Four controls we don’t trade away for speed.

  • The citation gate

    Each claim is matched to a source span and checked for entailment before it is shown. Unsupported claims are marked “insufficient evidence”, not guessed.

  • The intended-use boundary

    Patient-specific diagnosis and treatment requests are refused, tested against a dedicated refusal suite with no partial credit.

  • The audit trail

    Append-only, hash-chained events: route, tools, model and version, sources, checks and reviewer decisions. Visible in the product and exportable.

  • Frozen evaluations

    Evaluation sets are built before any training, hashed, and never edited to make a result pass.

Your data stays where it is allowed to be.

Data classification and residency are decided before any cache, retrieval or model call. If a decision can’t be made, the request stops.

  • Patient-level data stays inside your data plane and its region
  • Model providers are called under zero-data-retention terms
  • Customer data is never used to train models without written approval
  • Feedback goes to an offline review queue, never to a live model
  • All showcases use public and synthetic data only

Every artifact passes all five gates before it touches a regulated workflow.

The 5-of-5 model-promotion gate. Improvement happens offline, and every production artifact can be rolled back to a pinned version.

  1. Gate 1 of 5

    Data-quality gate

    Data quality, licence and PHI conformance

  2. Gate 2 of 5

    Frozen test set

    SME-validated, version-locked question sets

  3. Gate 3 of 5

    Evaluation gate

    RAGAS and DeepEval thresholds met

  4. Gate 4 of 5

    Citation verifier

    Span match: supported or unsupported

  5. Gate 5 of 5

    SME sign-off

    Override log and a named accountable owner

Built to the frameworks regulated life sciences run on.

Tamper-proof HMAC-SHA-256 audit log, quarterly third-party attestation, and automated cross-jurisdiction checks on every artifact.

  • GxP

    Validated training-run plans; every recommendation traceable to source data

  • SOC 2 Type II

    Tamper-proof audit log, HMAC-SHA-256 hash chain, quarterly attestation

  • HIPAA / DPDP

    BAA, zero data retention, customer-managed keys, per-tenant residency

  • 21 CFR Part 11

    Electronic records and signatures, audit schema, SME override log

  • EU AI Act

    High-risk controls, model card, risk register, post-market monitoring

Multi-jurisdiction regulatory alignment

  • FDA

    ICH M11 protocol · 21 CFR 11 audit · submission templates

  • EMA

    CTR · EudraCT linkage · CTIS-ready evidence packages

  • CDSCO

    India clinical-trial rules · BA/BE · subject-level data

  • PMDA

    Japan submission mapping · jRCT cross-reference

Every answer carries the record of what produced it.

Model and version, policy decision, prompt and retrieval versions, sources with their dates, and every check result. If any field is missing, the answer is held back.

Example audit entryappend only, hash chained
event=request.received role=clinical
event=intent.classified class=patient_specific_treatment
event=policy.refuse action=blocked
event=audit.commit prev=3f9c…a201 hmac=7d41…e8b6

Reviewing us for your organisation?

Request our security and compliance pack: architecture overview, data-flow diagram and control summary.

Request the trust pack