Security
Introduction
This page explains adsilico’s approach to managing information security, cybersecurity, and privacy protection of information and assets in Adsilico Limited. Whilst this information is publicly available, if you are interested in learning more, please contact us using the information provided in the Contact Us section.
Our Commitment
We understand the importance of information security, cybersecurity, and privacy protection in the context of collecting data and input, training AI models, and providing products and services for in silico trials, computational modelling and simulations. Therefore, the management of the organisation commits to the protection of information security in the organisation as well as the lawful processing of personal data (personally identifiable information - PII). To achieve this goal, we introduce the Information Security Management System (ISMS), which is compliant with the ISO/IEC 27001:2022 standard. We apply Technical and Organisational Measures (TOMs) specified in the ISO 27001 Annex A to ensure the highest levels of information security for our clients.
Security Certifications and Systems
adsilico operates under multiple management systems based either on ISO standards or applicable regulations - you can learn more about other systems in the Regulatory & Compliance section. The information below presents only those systems that apply to information security, cybersecurity, and privacy protection.
Management System |
Resources |
|---|---|
|
ISO 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements This standard introduces the Information Security Management System (ISMS), which implements a systematic approach to managing information confidentiality, integrity, and availability. adsilico defines and operates the ISMS in compliance with the ISO 27001:2022 standard - the most popular standard worldwide concerning information security. Compliance with this standard is confirmed by the independent certification of TUV Nord GMBH, which is our notified body. The certification is valid for a three-year cycle with independent surveillance audits taking place annually. |
|
Compliance
adsilico is a UK-based organisation operating in a global market. Therefore, we are committed to comply with the applicable security and data privacy regulations globally, including:
-
UK General Data Protection Regulation
-
UK Data Protection Act 2018
-
(EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealed Directive 95/46/EC (General Data Protection Regulation) - GDPR
FAQs
-
What is your approach to information security?
We decided to define and operate an Information Security Management System to comply with the ISO 27001:2022 standard. It introduces a systematic and comprehensive approach to information security, cybersecurity, and privacy protection. -
Is adsilico ISO 27001:2022 certified?
Yes, it is. We are certified by TUV Nord GMBH who is our notified body. The certification is valid for three years, and every year during that period, we have an independent surveillance audit from the notified body, TUV Nord, to prove compliance and effectiveness of the ISMS. -
What is the scope of your Information Security Management System?
Our ISMS, as specified in the ISMS Information Security Policy, covers all locations and all roles in the organisation. It means that whatever product or service you order from us, it is delivered in a secure manner accordingly to the rules specified in the ISMS. -
How do you protect personally identifiable information (PII)?
We apply Technical and Organisational Measures (TOMs) specified in Annex A of ISO 27001:2022 to protect any information, including PII. TOMs cover all technical measures listed in any relevant privacy regulations like GDPR or UK DPA. The list of TOMs can be downloaded from this page in the form of an ISMS ISO27001 Statement of Applicability document. -
Do you use suppliers? How do you ensure the security of information when working with suppliers?
Yes, we use technical suppliers to help us provide our services and products. We engage with a supplier only after it has successfully passed the supplier verification process. During that activity, we check for security, ISO 27001, privacy, and AI requirements. -
Is data encrypted at rest?
Yes, all data is encrypted at rest with state-of-the-art encryption algorithms. We always implement at least storage-level encryption. -
Is the data encrypted in transfer?
Yes, data is encrypted during transfer. We allow and require communication only over secure and encrypted channels, implementing protocols such as TLS 1.2+, HTTPS, etc. -
Do you use strong authentication mechanisms?
Yes, we do. By default, we have a strong password policy enforced with multi-factor authentication (MFA) required. Whenever possible, we use single sign-on (SSO) technology to additionally strengthen access controls. -
How do you handle data backups and recovery?
We take backups regularly (at least daily) and test their quality with the backup recovery procedures on a monthly basis. Backups are securely stored in a separate and geographically distant location from the one where backups are taken.
Contact Us
If you would like to contact us regarding our information security position, please send us an email to

