DNA synthesis biosecurity screening
Screening every DNA and RNA synthesis order against a curated database of dangerous pathogen and toxin sequences before it is manufactured — commercial compliance-automation platforms and cryptographically privacy-preserving nonprofit screening tools that gene-synthesis providers like Twist Bioscience now run on every incoming order, driven by an October 2026 US regulatory deadline dropping the flagging threshold to 50 base pairs.
- Research
- Lab
- Pilot
- Scale-up
- Commercial
- Mature
01Overview and value chain#
Markers EC: EU dual-use export control framework for synthetic nucleic acids | OECD: Biotech and health | Regulator: FDA (USA)
DNA synthesis biosecurity screening checks every incoming gene- or oligo- synthesis order against a continuously updated database of sequences of concern — fragments of known pathogens, toxins and other regulated biological agents — before a provider manufactures the DNA, and separately verifies the customer’s credentials to legitimately order such material. The US 2026 regulatory framework tightens the mandatory flagging threshold from 200 to 50 base pairs by October 2026, an order-of-magnitude increase in how small a suspicious fragment must be caught. One commercial screening platform reports screening tens of thousands of constructs with turnaround times under three seconds and zero false positives validated against 67 million base pairs of real synthesis data. This sits downstream of the DNA-writing technology covered in genomics-dna-design.md — a compliance and risk-screening layer that runs on top of a synthesis order, not the synthesis chemistry itself.
Key directions of DNA synthesis biosecurity screening:
- Sequence-of-concern screening (Sequence-of-Concern Screening): real-time comparison of an order’s DNA/RNA sequence against a curated, continuously updated database of pathogen and toxin fragments.
- Customer and order compliance automation (Compliance Automation): automated verification of customer credentials and institutional legitimacy alongside the sequence check, reducing manual compliance review time for synthesis providers.
- Privacy-preserving cryptographic screening (Privacy-Preserving Screening): screening protocols that check a sequence against a controlled-agent database without exposing the customer’s proprietary sequence data to the screening operator.
- Cross-jurisdiction compliance (Cross-Jurisdiction Compliance): screening databases and annotations that incorporate both US framework requirements and other national export-control regimes for providers selling internationally.
Sectoral value chain#
[synthesis order submitted] ──> [sequence screening] ──> [customer verification] ──> [order cleared/flagged]
│
(sequence-of-concern database match)
│
▼
[DNA/RNA manufactured] <─── [compliance record logged] <──┘Value chain levels#
| Level | Description | Key inputs/outputs |
|---|---|---|
| Order intake | customer submits a DNA/RNA sequence for synthesis | In: sequence data, customer info. Out: screening request. |
| Sequence screening | comparing the sequence against a threat database | In: sequence data, sequence-of-concern database. Out: match/no-match result. |
| Customer verification | confirming the orderer’s institutional legitimacy | In: customer credentials. Out: verified/flagged customer status. |
| Risk assessment | evaluating flagged matches for genuine biosecurity risk | In: match result, context data. Out: clear, escalate or deny decision. |
| Compliance logging | recording the screening decision for regulatory audit | In: screening decision. Out: auditable compliance record. |
| Order fulfillment | manufacturing the cleared DNA/RNA sequence | In: cleared order. Out: synthesized DNA/RNA product. |
Cross-cutting technologies:
- Sequence-of-concern screening (Sequence-of-Concern Screening): continuously curated pathogen/toxin fragment databases with real-time matching algorithms.
- DNA order compliance automation (Order Compliance Automation): software that automates customer credential checks alongside sequence screening.
- Distributed oblivious PRF screening (Privacy-Preserving Cryptography): cryptographic protocols that screen a sequence without revealing it to the screening service.
02US#
The US anchors both the regulatory driver and the leading commercial and government-affiliated screening providers, following an October 2026 deadline that sharply tightens flagging requirements.
October 2026 threshold tightening, commercial compliance SaaS, government-research-institute screening services#
- 50-base-pair flagging deadline: providers and manufacturers must begin flagging synthesis orders at 50 base pairs by October 2026, down from a 200-base-pair threshold, under the US biosecurity framework.
- Biosecurity Modernization and Innovation Act (2026): proposed legislation (S. 3741) would mandate that all gene-synthesis providers screen orders and customers, establish a dangerous-sequence registry, and create a NIST governance sandbox for testing biosecurity tools.
- Commercial and institute-run screening services: a Columbia University spinout offers an end-to-end compliance-automation SaaS platform used by synthesis providers, while an applied-research institute’s commercial ThreatSEQ web service — adopted by Twist Bioscience — won an R&D 100 Award for its continuously curated screening database.
03CN#
No confirmed Chinese-based screening-tool vendor was found; Chinese synthesis providers instead adopt international (largely Swiss- or US-developed) screening tools to meet dual-jurisdiction compliance requirements.
export-control-driven compliance adoption, dual-jurisdiction screening, IGSC consortium membership#
- Export-control compliance: Chinese export-control regulations create a de facto requirement for DNA-synthesis-for-export providers to assess whether a sequence falls under controlled or sensitive categories.
- International tool adoption: a Shanghai-based high-throughput DNA synthesis provider adopted a Swiss-developed open-source screening tool specifically to maintain compliance across both US and Chinese regulatory systems — evidence of cross-border tool adoption rather than a domestic screening-vendor market.
- International Gene Synthesis Consortium membership: major Chinese and other Asian synthesis providers have joined the IGSC, signaling adoption of international screening norms even without a confirmed domestic screening tool vendor.
04EU#
Switzerland hosts two of the field’s most prominent screening-tool developers, both structured as nonprofit foundations providing free, internationally available tools rather than commercial SaaS products.
Swiss nonprofit foundation model, free open-source and privacy-preserving tools, international standard-setting role#
- Common Mechanism (Basel-adjacent Swiss foundation): launched May 2024 as a free, open-source synthesis-screening package more robust against evasion attempts — including AI-generated sequences — than basic sequence-matching approaches, spun out of a US biosecurity nonprofit into an independent Swiss foundation.
- Privacy-preserving cryptographic screening (Basel, Switzerland): a Swiss-foundation-run service uses distributed oblivious pseudorandom function cryptography so a sequence can be screened against a controlled database without exposing the customer’s proprietary sequence data to the screening operator itself.
- EU dual-use export control: the EU’s dual-use goods export control framework governs synthetic nucleic acid exports, the regulatory backdrop against which the two Swiss-based tools operate internationally.
05Leading companies and research institutes#
| Company / Institute | Country | Key products / platforms | Tech features | Status 2026 |
|---|---|---|---|---|
| Aclid | 🇺🇸 USA | End-to-end gene-synthesis compliance platform | Columbia University spinout; real-time screening, sub-3-second turnaround; customers incl. Ansa Biotechnologies | Commercial |
| Battelle | 🇺🇸 USA | ThreatSEQ™ DNA screening web service | R&D 100 Award winner; continuously curated Sequence of Concern database; adopted by Twist Bioscience | Commercial |
| IBBIS | 🇨🇭 Switzerland | Common Mechanism (commec) | Free, open-source; robust against AI-generated sequence evasion; adopted by Dynegene (China) for dual-jurisdiction compliance | Research |
| SecureDNA | 🇨🇭 Switzerland | Distributed Oblivious PRF screening system | Zero false positives validated against 67M base pairs; privacy-preserving cryptographic screening | Research |
06Tech stack and innovations#
The category’s technical core is a continuously updated threat database paired with a matching algorithm fast and robust enough to run on every synthesis order without materially slowing production.
- Sequence-of-concern database curation (Biocuration Pipeline):
- Databases of pathogen and toxin sequence fragments require continuous updating as new sequences of concern are identified, a labor-intensive curation process one commercial provider has spent decades building.
- Screening algorithms must catch both exact matches and near-matches designed to evade simple string-matching, including sequences deliberately altered or AI-generated to slip past basic screening.
- Real-time compliance automation (Order Screening Pipeline):
- Screening now runs as an automated step in the order-intake pipeline rather than a manual review, delivering risk assessments in seconds so it does not become a synthesis-provider bottleneck.
- Customer credential verification runs alongside sequence screening, since a benign sequence ordered by an illegitimate customer is still a biosecurity risk the screening step must catch.
- Privacy-preserving screening cryptography (Distributed Oblivious PRF):
- Cryptographic protocols let a screening service confirm whether a sequence matches a controlled database without the screening operator ever seeing the customer’s actual proprietary sequence — addressing synthesis providers’ IP-confidentiality concerns about third-party screening.
- This is the technical innovation that made free, third-party screening tools viable for commercial gene-synthesis providers unwilling to expose proprietary customer sequences to an external screening service.
07Value chains and production pipelines#
Industrial pipeline of a screened gene-synthesis order#
┌───────────────────────────┐ ┌───────────────────────────┐
│ 1. Order submission │ ───> │ 2. Sequence screening │
└───────────────────────────┘ └───────────────────────────┘
│
▼
┌───────────────────────────┐ ┌───────────────────────────┐
│ 4. Risk assessment │ <─── │ 3. Customer verification │
└───────────────────────────┘ └───────────────────────────┘
│
▼
┌───────────────────────────┐ ┌───────────────────────────┐
│ 5. Compliance logging │ ───> │ 6. Order fulfillment │
└───────────────────────────┘ └───────────────────────────┘Stage 1: Order submission
A customer submits a DNA or RNA sequence to a gene-synthesis provider, triggering the automated screening pipeline before manufacturing begins.
Stage 2: Sequence screening
The submitted sequence is compared in real time against a continuously curated sequence-of-concern database, checking for matches to known pathogen, toxin or other regulated agent fragments down to the 50-base-pair threshold.
Stage 3: Customer verification
In parallel, the ordering customer’s institutional credentials are checked against known-legitimate-customer criteria, catching the case of a benign sequence ordered by an illegitimate or unverifiable customer.
Stage 4: Risk assessment
Any sequence or customer match is escalated for risk assessment, evaluating whether the flagged result represents a genuine biosecurity concern or a benign false positive requiring manual review.
Stage 5: Compliance logging
The screening decision — cleared, escalated or denied — is logged into an auditable compliance record, the documentation regulatory frameworks require providers to maintain.
Stage 6: Order fulfillment
Cleared orders proceed to synthesis, with the DNA or RNA manufactured and shipped to the customer once the compliance record is complete.
| Supplier | Price | Lead time | Certificates | Risk | Confidence |
|---|---|---|---|---|---|
| Aclid | on request | on request | compliance-saas us | Low | HIGH |
| Battelle (ThreatSEQ) | on request | on request | screening-service us | Low | HIGH |
| IBBIS (Common Mechanism) | free | immediate | open-source eu | Low | HIGH |
| SecureDNA | free | immediate | privacy-preserving eu | Low | HIGH |
Key directions:
- Sequence-of-concern screening — real-time comparison of an order’s sequence against a curated pathogen/toxin fragment database.
- Customer and order compliance automation — automated credential verification alongside sequence checks.
- Privacy-preserving cryptographic screening — protocols that screen a sequence without exposing it to the screening operator.
- Cross-jurisdiction compliance — screening databases that incorporate multiple national export-control regimes.
Regulatory: the binding driver is the US framework tightening the mandatory flagging threshold from 200 to 50 base pairs by October 2026; proposed legislation (S. 3741) would go further and mandate universal screening. No dedicated EU or Chinese biosecurity-screening regulator entity exists in this site’s registry, so regulators here is deliberately limited to FDA rather than forcing an ill-fitting match.
Companies not in table: Dynegene (Shanghai) is a DNA synthesis provider that adopted IBBIS’s Common Mechanism as a customer — the same relationship Twist Bioscience has with Battelle’s ThreatSEQ — not a screening vendor itself, so not tabled as a producer.
Two of the four entities (IBBIS, SecureDNA) are nonprofit foundations providing free tools rather than commercial vendors, tabled per the same precedent as MetaSUB Consortium elsewhere on this site — a real, widely-adopted operational capability, not a company selling a product.
Confidence note: Battelle’s Twist Bioscience adoption is confirmed via a 2019 announcement rather than fresher 2026 coverage — the underlying relationship is not the kind of fact that goes stale, but flagged here for completeness.
Scope note: this article covers pre-synthesis order screening specifically, not the DNA synthesis/writing technology itself (covered separately elsewhere on this site) or general biotech cybersecurity (network/IT security for biotech firms, a different and much broader category not screened this pass).
Regional honesty: the CN section is qualitative by design — the real finding is that Chinese synthesis providers adopt international tools rather than that a domestic screening-tool market doesn’t exist; framed accordingly rather than as an absence.
Pipeline stage: rated early-scale (stage 4 of 6) — every tabled entity has a live, operational screening capability today, but universal mandatory screening is not yet law anywhere; the October 2026 US threshold tightening and the pending S. 3741 legislation are the near-term catalysts that would move this from opt-in best-practice to compliance requirement.
Sources
- Aclid · US
- Battelle · US
- IBBIS · CH
- SecureDNA · CH