BioRender recognizes the paramount importance of safeguarding the sensitive data our users trust us with and maintaining the privacy of our users. We strive to hold the highest standards of data privacy and security for the benefit of the global scientific community. As part of our commitment to data privacy and security, we have established this dedicated Trust Center, which serves as a comprehensive resource for those seeking to learn more about our security and privacy program. Within the Trust Center, individuals can request access to detailed reports and program specifics, demonstrating our dedication to transparency and accountability in all aspects of our operations.
Subprocessors
- Do you provide choice to the user to opt out of AI use?
- Are you storing any passwords in plaintext?
- Are upgrades or system changes installed during off-peak hours or in a manner that does not impact the customer?
- Is your company subject to the institution's geographic region's laws and regulations?
- Do backups containing the institution's data ever leave the institution's data zone either physically or via network routing?
Trust Center Updates
BioRender's Updated SOC 2 Type II Report
Our latest SOC 2 Type II report, audited by Sensiba LLP, is now available for download. This report reflects our continued commitment to maintaining strong security, availability, and confidentiality controls. Existing customers and prospects can request access through the Trust Centre.
CVE-2026-31431
BioRender (Science Suite Inc.) has assessed CVE-2026-31431, a Linux kernel local privilege escalation vulnerability recently disclosed with a CVSS score of 7.8.
BioRender has completed its assessment of this vulnerability across our infrastructure and confirmed that appropriate mitigations are in place. Remediation was carried out in accordance with our vulnerability management policy, which prioritizes high and critical severity findings for rapid response.
BioRender continuously monitors the threat landscape and maintains a proactive patching cadence to protect the confidentiality, integrity, and availability of customer data.


