DNA Synthesis Screening Tracker

Methodology

This tracker records what DNA synthesis providers publicly disclose about biosecurity screening. It does not, and cannot, measure what any company actually does internally. Everything below exists to keep that distinction from collapsing.

The rule that governs every cell

If a provider does not publicly say it, the value is not stated — never no. A company can screen rigorously and never publish a page about it. Writing “no” would be a factual claim about internal practice that no external observer can support from public sources. The only field where a negative is recorded is IGSC membership, because the consortium publishes an authoritative member roster, which makes absence from that list a checkable fact rather than an inference.

What each value means

Stated
The provider's own public materials contain the claim. A source URL and the location of the claim on the page are recorded.
Not stated
A maintainer reviewed the provider's public materials and found no such claim. This is a statement about the published record, not about the company.
Unverified
Nobody has checked this cell yet. It is not a finding of any kind.
Legal mandate: none / partial / binding
Describes the provider's headquarters jurisdiction, not the provider. “Partial” means a requirement attaches to some transactions only — for example federally funded purchasers or export-controlled agents — rather than to all commercial sales.

Sources

  1. The International Gene Synthesis Consortium public member list.
  2. Each provider's own biosecurity or gene synthesis policy page, cited per cell.
  3. US Department of Health and Human Services, Screening Framework Guidance for Providers and Users of Synthetic Nucleic Acids.
  4. Peer-reviewed commentary on screening gaps, cited in the accompanying essay.

Secondary reporting is never used as the source for a cell. If it is not on the provider's own site or an official roster, it does not go in the table.

How updates work

A scheduled job runs monthly. For every provider with a recorded policy URL it fetches the page, strips markup and scripts, normalises whitespace, and hashes the remaining text. That hash is compared against the previous run's. Any difference opens a GitHub issue naming the changed URLs, which a human then reviews before any cell moves. Automation detects change; it never edits the dataset. Each row carries its own last_verified date, so a stale cell is visible rather than implied to be current.

Scope and known limits

Corrections

If a cell is wrong — including if you work at a listed provider and your public policy says something this table missed — open an issue with the URL and the text. Corrections are applied promptly and the full history is public in the repository.