Built for enterprise R&D.

Dedicated infrastructure, compliance-ready architecture, and the security controls your IT and procurement teams require. One page, everything you need to evaluate.

Deployment options

Two models. Both on AWS. Choose the isolation level that fits your requirements.

Shared Cloud

Pilot & Business plans

Multi-tenant SaaS on AWS. Logical isolation at the database level. Fast onboarding — start screening in minutes.

  • Logical tenant isolation (org_id enforced)
  • AES-256 encryption at rest, TLS 1.2+ in transit
  • Shared compute with per-org rate limiting
  • US region default (us-east-1)
  • Automated daily backups

Dedicated Cloud

Enterprise plan

Your own AWS infrastructure. Dedicated database, file storage, and application server. Full physical isolation — no shared resources.

  • Dedicated PostgreSQL instance (your data only)
  • Dedicated S3 storage bucket
  • Dedicated application server
  • Choice of AWS region (US, EU, Asia-Pacific)
  • Customer-managed encryption keys (BYOK via AWS KMS)
  • Custom retention policies
  • VPC peering available on request

Cloud-hosted only

FluxMateria is delivered as a managed cloud service on AWS. We do not offer on-premises deployment. Dedicated Cloud gives you full infrastructure isolation with the operational simplicity of a managed service — your IT team does not need to provision, patch, or maintain anything.

Compliance & certifications

Where we are today and where we are heading. No vague "roadmap" — specific timelines.

Framework Status Timeline Details
SOC 2 Type 2 In progress Q4 2026 Controls documented. Observation period underway. Bridge letter available under NDA.
GDPR Aligned Current DPA available. EU data residency (eu-west-1) on Enterprise. Data deletion on request with certificates.
ISO 27001 Planned H1 2027 After SOC 2 completion. ISMS framework will extend SOC 2 controls.
FDA 21 CFR Part 11 Documentation available Current Alignment documentation for audit trails, electronic signatures, and access controls provided on request.
HIPAA / BAA Available On request BAA executed for Enterprise customers handling PHI on Dedicated Cloud deployments.

Security controls

What is implemented today. For full technical details, see our security page.

Authentication

  • SSO via SAML 2.0 / OIDC (Enterprise)
  • Multi-factor authentication
  • JWT with refresh token rotation
  • Service accounts + API keys

Access control

  • 6 predefined RBAC roles
  • Principle of least privilege
  • Organization-level data isolation
  • Cross-org access requires SystemAdmin

Encryption

  • AES-256 at rest (AWS KMS)
  • TLS 1.2+ in transit, HSTS enforced
  • BYOK on Dedicated Cloud
  • No unencrypted access paths

Audit & provenance

  • Append-only, tamper-evident audit log
  • All auth + data access events recorded
  • Exportable for SIEM integration
  • Deletion certificates on data purge

Data handling

  • Your data is never used for training
  • Never shared between customers
  • Never sold or monetized
  • Your IP remains yours — always

Data residency

  • US default (us-east-1)
  • EU available (eu-west-1)
  • Asia-Pacific on request
  • Data never leaves chosen region

API & integration

Built API-first. Fits your existing stack.

Platform

  • 150+ REST API endpoints
  • OpenAPI 3.0 documented (Swagger UI + ReDoc)
  • Per-user and per-org rate limiting
  • Batch processing for high-throughput campaigns

Data formats & export

  • JSON, CSV/TSV, SDF, PDF export
  • SMILES, InChI, and SDF input
  • CIF input for materials
  • Webhook notifications (Enterprise)

What your IT team needs to know

Infrastructure to provision None. Fully managed SaaS. No servers, no GPUs, no HPC cluster.
Client-side requirements Modern web browser (Chrome, Firefox, Safari, Edge) or any HTTP client for API access.
Network requirements HTTPS outbound to fluxmateria.com (port 443). No inbound firewall rules required.
SSO integration SAML 2.0 and OIDC supported on Enterprise plans. Works with Okta, Azure AD, Google Workspace, OneLogin.
Data sovereignty Data stays in your chosen AWS region. No cross-region replication unless requested. DPA available for GDPR.
Uptime SLA 99.9% availability target on Enterprise plans. Dedicated Cloud includes priority incident response.
On-premises Not available. Dedicated Cloud on AWS provides equivalent isolation without the operational burden of self-hosting.

Security due diligence

We support your security review process. Available artifacts and supported questionnaire formats.

Available under NDA

  • SOC 2 Type 2 Bridge Letter
  • Penetration Test Summary (grey-box)
  • Business Continuity Plan Overview
  • Subprocessor List
  • Architecture Diagram

Supported questionnaires

  • SIG Lite / SIG Full
  • CSA CAIQ
  • GDPR Data Transfer Impact Assessment
  • Custom enterprise security reviews
  • Vendor risk assessment forms

Ready to evaluate?

Start with a pilot on shared cloud, or go straight to a dedicated deployment discussion.

Contact Enterprise Sales Full Security Details