Standards & complianceHL7 FHIRGA4GHACMG/AMPCPICABDMSAHIGDPRDPDPISO 27001
Trust & security

Genomic data demands the highest bar.

Genomic data is permanent, familial and predictive — a breach affects relatives who never consented. Security is not a feature here; it is the architecture.

Why it is different

Not like other data.

Permanent

You can reset a password. You cannot reset a genome — so protection has to last a lifetime.

Familial

Your genome implicates your relatives. Consent and governance must account for people not in the room.

Predictive

It reveals future risk, not just present state — raising the stakes for how it is stored and used.

Security architecture

Zero-trust, encrypted everywhere.

Engineered in from the first commit — least privilege by default, encryption in transit and at rest, and a full audit trail on every case.

Zero-trust access

Least-privilege, role-based access with strong authentication on every service.

Encryption everywhere

In transit and at rest, with managed keys and secrets isolation.

Immutable audit

Every access and assertion is logged and versioned, per case, for years.

Data residency

Cloud-agnostic deployment keeps data in-region for sovereign requirements.

Secure SDLC

Versioned knowledge bases, reviewed changes, and reproducible pipelines.

Isolation by design

Tenant and environment isolation limits blast radius and cross-exposure.

Compliance & standards

Aligned to the frameworks buyers require.

Data protectionGDPR (UK/EU) and India’s DPDP Act — lawful basis, consent, data-subject rights and breach processes.
Health informationHIPAA-ready controls for handling protected health information in applicable deployments.
Information securityWorking to ISO 27001 and SOC 2 control frameworks for the platform and organisation.
Genomic interoperabilityHL7 FHIR Genomics and GA4GH standards for secure exchange and reporting.
Clinical classificationTransparent ACMG/AMP and CPIC criteria engines — no opaque black boxes.
Medical deviceCDSCO pathway under the Medical Devices Rules 2017; UKCA route with the MHRA.

Some certifications are in progress as the platform matures toward regulated clinical use; current status available under NDA.

National alignment

ABDM, SAHI and BODH.

India’s digital health stack is the substrate we build on, the governance we design against, and the benchmark we intend to be measured by.

ABDMABHA identity, facility and practitioner registries, consent manager and health information exchange. We align to the national rails rather than build a parallel identity model.
SAHIAll seven governing sutras map to platform properties: trust through provenance, people first through enforced human sign-off, accountability through signature binding, and understandability through the evidence trail.
BODHFederated benchmarking as a digital public good under ABDM. Models train on-site and only weights return — which is how our federated architecture already works, and why we can enter third-party evaluation rather than avoid it.
Responsible AI

Intelligence you can defend.

Explainable

Evidence-linked outputs, never ungrounded generation.

Human oversight

A qualified reviewer signs off every clinical assertion.

Auditable

Versioned knowledge means a result is reproducible later.

Fairness-aware

Subgroup performance, calibration and refusal rate reported in every validation.

Get started

Talk to us about security.

We share architecture detail, control mappings and current certification status under NDA.