SOC 2, Axon, and Building for Pharma
SOC 2 is one step in how we’re building Axon for pharmaceutical and life sciences teams.
We recently completed our SOC 2 examination. We finished Type I in February, and after the Type II observation window ended in May, we now have our final SOC 2 Type II report available to customers and qualified prospects through our Trust Center under NDA.
At Mirror Physics, we’re trying to move quickly and deliver value to our customers. Most of that work comes through Axon, our agentic platform for drug discovery, where pharmaceutical companies can accelerate the scientific and operational work behind new therapeutic programs. It’s been great working directly with customers on shipping features, and then seeing scientists and experts use them in ways that meaningfully improve their day-to-day work.
We have built Axon from the beginning with intellectual property security in mind. That is reflected in the architecture of the product, the way we think about technical implementation, and the commitments we are making around certification and oversight.
The product cannot exist on features alone. If we are going to support pharmaceutical and life sciences teams, we have to earn the right to work with their data. Security and data privacy are Tier 1 concerns for them, and for us as well. These teams work with sensitive research, proprietary workflows, confidential strategy, and intellectual property that sits at the center of how new therapies are developed.
Our SOC 2 Type II report covers the controls behind Axon and the processes we have put in place to protect customer data. The controls include who can access customer data, how that access is reviewed, how product changes are made, how third-party vendors are evaluated, and how issues are detected and handled. The goal is to make sure our customer’s data is protected not just by policy, but by how the system is built and operated.
SOC 2 is one step in a larger security and compliance program at Mirror Physics. We are also working toward ISO 27001 and ISO 42001 as we continue strengthening both our information security management practices and our governance around AI systems.
This is especially important in pharma, where software vendors are not just evaluated on features. They are evaluated on whether they can fit into a regulated, risk-aware organization without creating more work for security, legal, IT, or compliance teams.
More importantly, we are treating this as part of how Mirror Physics and Axon grows. The work behind the report now becomes part of how we run the company: recurring access reviews, vendor reviews, control monitoring, policy updates, and clear ownership across the team.
Thank you to Vanta and Prescient Security for helping us throughout the SOC 2 process. And thank you especially to our first pharmaceutical customers. Your questions, diligence, and collaboration have helped shape Axon into a product that is not only useful, but built with the level of security and operational rigor this industry demands.


