generated: '2026-08-15' method: searched source: >- https://www.benchling.com/trust (HTTP 200), plus https://securitytrust.benchling.com/ (HTTP 200, the gated Trust Portal) and https://www.benchling.com/information-security-policy (HTTP 200). description: >- Benchling runs a real trust center with named third-party attestations, which matters for this provider more than for most: its customers are pharma and biotech companies whose lab records fall under FDA 21 CFR Part 11 and GxP, so the compliance page is part of the product, not marketing. Certifications are named on the public page; the underlying reports sit behind a gated Trust Portal. Note what is NOT here — no security.txt, no published vulnerability disclosure policy and no bug bounty, so a researcher who finds a flaw has no documented route in beyond trust@benchling.com. trust_center: url: https://www.benchling.com/trust status: 200 portal: https://securitytrust.benchling.com/ portal_status: 200 portal_note: >- Gated trust portal hosting the security whitepaper and the underlying audit reports; document access requires a request. contact: trust@benchling.com certifications: - name: SOC 2 Type 2 type: attestation note: AI features stated as in scope. - name: ISO/IEC 27001:2022 type: certification note: AI features stated as in scope. - name: ISO/IEC 27017:2015 type: alignment - name: ISO/IEC 27018:2025 type: alignment regulatory_frameworks: - name: FDA 21 CFR Part 11 type: compliance note: >- Electronic records and electronic signatures. The v3 API exposes a first-class AuditLog resource, which is the technical substrate this requires. - name: EU Annex 11 type: compliance - name: GxP type: compliance note: >- Validation support is sold as an Enterprise-tier capability — plans/benchling-plans-pricing.yml. - name: GDPR type: compliance - name: EU-US Data Privacy Framework type: program - name: CCPA type: compliance - name: NIST type: alignment - name: C5 (Germany) type: alignment - name: NCSC (UK) type: alignment security_practices: encryption_at_rest: AES-256 encryption_in_transit: TLS 1.2 or higher penetration_testing: Annual, by an independent third party mfa: Required sso: SSO / OIDC identity provider support audit_trail: Audit trail plus citation architecture for AI outputs documents: - name: Information Security Policy url: https://www.benchling.com/information-security-policy status: 200 - name: Security Whitepaper url: https://securitytrust.benchling.com/ status: 200 gated: true - name: Agreements and Terms url: https://www.benchling.com/agreements-and-terms status: 200 - name: Privacy Center url: https://www.benchling.com/privacy status: 200 vulnerability_disclosure: published: false security_txt: false bug_bounty: false note: >- probe-security-programs.py returned vdp=none trust=none on 2026-08-15, and /.well-known/security.txt 404s on www.benchling.com and docs.benchling.com (benchling.com answers 200 with an HTML sign-in shell, not a document — see well-known/benchling-well-known.yml). No HackerOne, Bugcrowd or Intigriti programme and no /security or /responsible-disclosure page was found. The only published security address is trust@benchling.com, which is a trust / compliance contact rather than a disclosure channel. No VulnerabilityDisclosure or Security pointer is emitted as a result.