Inato · Trust Center

Inato Trust Center

Trust center

Inato maintains a public trust center documenting ISO 27001, HIPAA, and GDPR compliance.

CompanyClinical TrialsHealthcareLife SciencesPharmaceuticalsClinical ResearchMarketplaceArtificial Intelligence
Trust center: https://support.inato.com/data-security

Certifications & Compliance

ISO 27001HIPAAGDPR

Source

Trust Center

inato-trust-center.yml Raw ↑
generated: '2026-08-17'
method: searched
probe: true
source: https://support.inato.com/data-security
url: https://support.inato.com/data-security
trust_center:
  platform: Drata
  url: https://app.drata.com/trust/9cb59bcb-0c38-11ee-865f-029d78a187d9
  discovered_in: >-
    the "Contact Our Security Team" block of support.inato.com/data-security
    (extracted from the site's client-side bundle, since the page is
    JS-rendered)
  readable: false
  probe:
    status: 403
    detail: >-
      Cloudflare bot challenge ("Just a moment...") on app.drata.com; the Drata
      public API (public-api.drata.com/public/trust-center/<id>) answers 401
      Unauthorized. The trust center is real and Inato-owned, but its contents —
      including whatever audit reports Drata is tracking — could not be read by
      machine on 2026-08-17. Certifications below are therefore taken from
      Inato's own security page, not from the trust center.
certifications:
- ISO 27001
- HIPAA
- GDPR
certifications_not_claimed:
- SOC 2
- 21 CFR Part 11
- HITRUST
- PCI DSS
- FedRAMP
frameworks:
- name: HIPAA
  detail: 'HIPAA "Preparatory to Research" (45 CFR 164.512); Business Associate Agreement (BAA) available and required before any EHR connector is enabled'
- name: ISO 27001
  detail: Information security management — claimed as a badge; certificate available on request, not published
- name: GDPR
  detail: >-
    EU data protection. Inato states the processor posture explicitly: "Inato
    processes the data on your behalf, under your instruction and
    authorization." Regional data-residency commitments claimed for the GCP
    environment.
controls:
- encryption: AES-256 for data at rest and in transit
- de_identification: >-
    Names, dates of birth, addresses and contact details are stripped the moment
    a file is uploaded or synced, before any AI processing begins
- pseudonymization: Records pseudonymized and stored under random identifiers in secure Google Cloud storage
- data_hosting: Google Cloud Platform (Inato-owned projects)
- network_defense: Google Cloud Armor for DDoS and external threat defense
- access_control: >-
    Logical access controls designed to prevent Inato staff from viewing
    identifiable patient data; sponsors see only aggregated, de-identified
    pre-screening insights
- retention: Original uploaded files are not retained in viewable form
- integration_posture: >-
    EHR integrations are read-only bulk FHIR — architecturally unable to write,
    modify or delete data in the site's EHR, and the site approves the access
    scope inside its own EHR
ai_governance:
- model: Google Gemini, deployed inside Inato's own Google Cloud projects
- no_third_party_llm: Patient data is never sent to any third-party US-based LLM provider
- no_training: >-
    No site or patient data is used to train AI models; Google does not use it to
    train their foundation models. Non-patient signals (user feedback on AI
    response accuracy) may be used to tune prompts and configuration
- human_in_the_loop: >-
    The AI flags and summarizes; the site team reviews every patient and makes
    every final call before anyone moves to screening
- explainability: >-
    Criterion-by-criterion summary of met / not met / unknown with the clinical
    evidence relied on, which the site team can read, challenge and override
- bias_control: Each patient is assessed against protocol criteria individually, never ranked against other patients
- purpose_limitation: >-
    Patient data is processed solely for the site's specific trial — not for
    product development, AI training or research, except as agreed in writing
contact: security@inato.com
documentation_on_request: >-
  Compliance documentation, security-review templates and the BAA are offered via
  security@inato.com rather than published for download.
evidence:
- source: https://support.inato.com/data-security
  keywords: [iso 27001, hipaa, gdpr, aes-256, business associate agreement, google gemini, cloud armor, de-identification]
- source: https://app.drata.com/trust/9cb59bcb-0c38-11ee-865f-029d78a187d9
  status: 403
  keywords: [drata, trust center]
weakest_link:
  connector: AdvancedMD
  detail: >-
    The AdvancedMD connector is credential-based: the site shares its AdvancedMD
    login name, password and Office Key with Inato. Inato's own guidance
    recommends creating a dedicated AdvancedMD account for Inato. This is the one
    connector that is not token- or FHIR-scoped, and it sits inside an otherwise
    strong read-only posture.
  source: https://support.inato.com/connections/advancedmd

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/inato-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.