Security & compliance

Security is the foundation of clinical genomics.

inferagen handles some of the most sensitive data in healthcare โ€” genomic sequences linked to identified patients. We engineer for that responsibility from day one.

Compliance posture

Our compliance posture.

Compliant

DPDP Act 2023

India's data-protection regime. DPO appointed, consent flows implemented, breach-notification procedures in place.

FHIR-compliant

ABDM (NHA)

ABDM-FHIR profile compliance for genomics. Sandbox-tested. Required for empanelment.

Certified

ISO/IEC 27001

International information security management standard. Certified at the parent entity (Orbitnexa Technologies).

Workflow-aligned

NABL aligned

Our workflow templates align with NABL ISO 15189 lab accreditation requirements.

Certified

ISO 9001

Quality management system. Certified at the parent entity (Orbitnexa Technologies).

Certified

ISO/IEC 20000

IT service management standard. Certified at the parent entity (Orbitnexa Technologies).

Compliant

GDPR

For European deployments. DPA on request.

BAA available

HIPAA-aligned

For US clinical partners. Encryption, audit logging, access controls in place.

Recognized & Registered

Startup India & MSME

Orbitnexa is recognized under Startup India and registered as MSME โ€” eligible for procurement benefits with public-sector and government-empanelled buyers.

Architecture

Built secure by default.

Data protection

  • โœ“Encryption at rest (AES-256) and in transit (TLS 1.3)
  • โœ“India data residency (default region: AWS Mumbai)
  • โœ“Genomic data tokenization โ€” sample IDs stored separately from patient PII
  • โœ“Secure deletion on customer request (30-day retention default)
  • โœ“Optional bring-your-own-key (BYOK) for enterprise customers

Access & audit

  • โœ“Role-based access control (RBAC) with least-privilege defaults
  • โœ“Single Sign-On (SSO) โ€” SAML 2.0, OAuth 2.0
  • โœ“Multi-factor authentication mandatory for all users
  • โœ“Comprehensive audit logs (every action, every export, every report sign-off)
  • โœ“Quarterly penetration testing by certified third-party

Subprocessors

Where your data lives.

SubprocessorPurposeLocation
AWSCompute, storage, backupMumbai (India region)
NVIDIAParabricks accelerationAWS Mumbai
Postmark / SESTransactional emailMumbai (India region)
PostHog (self-hosted)Product analyticsSelf-hosted, Mumbai
Grafana CloudInfra monitoringEU (metadata only)

We do not use any subprocessor that stores genomic data outside India unless the customer explicitly opts in for cross-border deployment.

Documentation

Documentation for your security review.

Security Whitepaper

PDF, 24 pages

Architecture, controls, and incident-response procedures.

Request the whitepaper

DPA template

Pre-signed by inferagen

Add your details and counter-sign. Email it back to privacy@inferagen.ai.

Download DPA

Subprocessor list

Live, machine-readable

Always-current list of every third-party we use.

Request the list

Need a security review call?

We'll join your CIO + InfoSec team for 30 minutes.

Book 30 min

Responsible disclosure

Found a vulnerability?

We take security disclosures seriously. Email security@inferagen.ai with:

  • โ€ข A description of the issue
  • โ€ข Steps to reproduce
  • โ€ข Your name and contact (for credit)

We commit to acknowledging your report within 24 hours and resolving valid issues within 90 days. We do not currently offer bug bounties but we publish acknowledgments on this page.

Read our full responsible disclosure policy โ†’