Platform

Uncountable Security

Last updated August 2026

Certifications

Independently Audited, Every Year

External audit is the part of security you cannot self-assess, so we start there.

SOC 2 Type II Certified, with an annual external audit. The most recent report carries no qualifications and no exceptions. Available under NDA through your account team.

ISO 27001 Certified, with the annual audit maintained alongside SOC 2 Type II. This covers how security is governed, not only how it is built.

ISO 22301:2019 Certified for business continuity management. Certificate BCMS-UN-111125, issued by A-LIGN and ANAB-accredited, valid to November 2028. The certificate covers our business continuity management system, including production systems, personnel, and engineering and support processes.

GDPR Fully compliant, with data processing agreements available.

Additional frameworks. Our security program incorporates controls from industry standards including the NIST and CIS frameworks. Specific control mapping is available on request.

Where Your Data Lives

Your Region, Your Isolation, Your Keys if You Want Them

Uncountable runs on Amazon Web Services, with deployments available in the United States, the European Union, and Japan.

Isolated per customer. By default Uncountable is multi-tenant, with each customer in their own database schema. A single-tenant deployment is available where a customer requires it, including for regulated GxP use.

Optionally inside your own cloud. Uncountable can be deployed within your own virtual private cloud. Customer-managed keys, or bring your own key, are available in single-tenant VPC deployment.

Encrypted throughout. AES-256 at rest. TLS 1.3 in transit, with a minimum of TLS 1.2, and HTTP redirected to HTTPS automatically.

Delivered through a monitored CDN. Content delivery via AWS CloudFront, monitored end to end.

Your data is yours. We treat it as confidential and proprietary, you own what you upload and what you export, and you can request a full export at any time.

Section 3 · Who Can Reach It

Access Is Scoped to the Person

Role-based access control. Permissions are set by role, and data is classified so that different classifications carry different access rules.

Single sign-on. SAML v2, configured by you in your own identity provider. We have interfaced with Microsoft Active Directory, Okta, Microsoft Entra, and SAP.

Multi-factor authentication. Enforced where configured.

Automated provisioning. SCIM is supported, so accounts are provisioned and deprovisioned by your directory rather than by hand.

IP allowlisting. Account access can be restricted to the addresses you specify.

External parties see only their own work. Clients, suppliers, and partner labs invited through the Uncountable Portal reach specific forms and records, never the platform and never another party's data.

Application integrity. The Uncountable application cannot be embedded in or proxied through an external client.

Stopping Data Leaving

Export Controls and Data Loss Prevention

Most data loss is authorized users moving more than they should, so the controls sit on the way out as well as the way in.

Export limits you set. Caps on the number of experiments and notebook files a user can export. Set them to block outright, or to warn administrators silently so unusual behavior can be monitored without tipping off the user. Limits can differ by user group, so tighter restrictions apply where they are needed.

Microsoft Purview Information Protection. Uncountable integrates with Purview and can apply your own sensitivity labels to data leaving the platform, configurable at material family or project level. That means access to an exported file, including one the platform generated, follows the provenance of the data inside it.

Antivirus on the way in. Every file uploaded to Uncountable is scanned, so infected files do not reach your environment through us.

Section 5 · How the Application Is Protected

Built and Tested Against Known Attacks

Annual external penetration testing, covering the OWASP Top 10 and beyond. An attestation is available.

Regular network vulnerability scanning.

Hardened web servers. Content Security Policy, HTTP Strict Transport Security, and X-Content-Type-Options, X-Frame-Options, and XSS protection headers, audited regularly.

Email. Sent through the AWS secured email service, with SPF configured for domain security.

Browser support. All modern browsers and operating systems, including mobile browsers on iOS and Android.

Resilience and Recovery

Uptime, Backups, and Getting Back

99.9 percent availability, committed. Met every month of Uncountable's operational history.

Recovery point and recovery time objectives of ten minutes.

Multi-availability-zone high availability and point-in-time recovery on the standard deployment.

Immutable backups. S3 immutable storage with versioning, held geographically separate and encrypted, with 35-day retention. Longer-term backups can be delivered to you on request.

Tested, not assumed. Restore testing runs under the SOC 2 audit program. The most recent restore test was 28 May 2026 and all data was restored successfully.

A documented continuity plan, certified under ISO 22301 and shared with customers.

A public status page, visible without a login.

When Something Goes Wrong

Incident Response and Disclosure

Breach notification within 48 hours of confirming a security incident, with specific timelines defined in your DPA and aligned to GDPR obligations.

Report a vulnerability. security@uncountable.com. If you believe you have found a security issue, contact us there.

What You Can See for Yourself

Your Own Audit Trail

Immutable and permanent. The audit trail cannot be altered and is retained for the life of the contract.

Exportable. CSV, XLSX, or JSON.

Streamable to your own tooling, including Splunk and Datadog, so our logs can sit alongside the rest of your estate.

Entity-level, not just admin-level. Individual users can see the audit trail for the records they own without going through an administrator.

A published changelog, on our support site.

AI and Your Data

What Happens to Your Data When AI Touches It

Your data is isolated per customer and is not used to train foundation models.

Models trained on your data operate exclusively within your own isolated tenant. Your data never contributes to general model training, and all models are destroyed when the contract ends. AI features run on AWS Bedrock enterprise APIs.

For Regulated Industries

Built for GxP and Quality-Regulated Work

Electronic signature and audit trail capabilities aligned to 21 CFR Part 11 and EU Annex 11.

Single-tenant deployment available where a regulated environment requires it.

A validation framework. IQ, OQ, and PQ structure, a traceability matrix, and a supplier quality agreement, supporting your own computer system validation lifecycle as a scoped engagement.

Timestamped, versioned, attributable records. Every change carries who, what, and when.

ISO 17025. Uncountable is already in use inside ISO 17025-accredited laboratories.

Get the Evidence

What Your Security Team Will Ask For

Most reviews ask for the same things. Your account team can provide:

  • SOC 2 Type II report, under NDA
  • ISO 27001 and ISO 22301 certificates
  • Penetration test summary
  • A completed industry-standard security questionnaire, kept current
  • Data processing agreement
  • NIST and CIS control mapping

See how Uncountable transforms research & development