Security is the foundation of clinical genomics.
inferagen handles some of the most sensitive data in healthcare โ genomic sequences linked to identified patients. We engineer for that responsibility from day one.
Compliance posture
Our compliance posture.
DPDP Act 2023
India's data-protection regime. DPO appointed, consent flows implemented, breach-notification procedures in place.
ABDM (NHA)
ABDM-FHIR profile compliance for genomics. Sandbox-tested. Required for empanelment.
ISO/IEC 27001
International information security management standard. Certified at the parent entity (Orbitnexa Technologies).
NABL aligned
Our workflow templates align with NABL ISO 15189 lab accreditation requirements.
ISO 9001
Quality management system. Certified at the parent entity (Orbitnexa Technologies).
ISO/IEC 20000
IT service management standard. Certified at the parent entity (Orbitnexa Technologies).
GDPR
For European deployments. DPA on request.
HIPAA-aligned
For US clinical partners. Encryption, audit logging, access controls in place.
Startup India & MSME
Orbitnexa is recognized under Startup India and registered as MSME โ eligible for procurement benefits with public-sector and government-empanelled buyers.
Architecture
Built secure by default.
Data protection
- โEncryption at rest (AES-256) and in transit (TLS 1.3)
- โIndia data residency (default region: AWS Mumbai)
- โGenomic data tokenization โ sample IDs stored separately from patient PII
- โSecure deletion on customer request (30-day retention default)
- โOptional bring-your-own-key (BYOK) for enterprise customers
Access & audit
- โRole-based access control (RBAC) with least-privilege defaults
- โSingle Sign-On (SSO) โ SAML 2.0, OAuth 2.0
- โMulti-factor authentication mandatory for all users
- โComprehensive audit logs (every action, every export, every report sign-off)
- โQuarterly penetration testing by certified third-party
Subprocessors
Where your data lives.
| Subprocessor | Purpose | Location |
|---|---|---|
| AWS | Compute, storage, backup | Mumbai (India region) |
| NVIDIA | Parabricks acceleration | AWS Mumbai |
| Postmark / SES | Transactional email | Mumbai (India region) |
| PostHog (self-hosted) | Product analytics | Self-hosted, Mumbai |
| Grafana Cloud | Infra monitoring | EU (metadata only) |
We do not use any subprocessor that stores genomic data outside India unless the customer explicitly opts in for cross-border deployment.
Documentation
Documentation for your security review.
Security Whitepaper
PDF, 24 pages
Architecture, controls, and incident-response procedures.
Request the whitepaperDPA template
Pre-signed by inferagen
Add your details and counter-sign. Email it back to privacy@inferagen.ai.
Download DPASubprocessor list
Live, machine-readable
Always-current list of every third-party we use.
Request the listNeed a security review call?
We'll join your CIO + InfoSec team for 30 minutes.
Responsible disclosure
Found a vulnerability?
We take security disclosures seriously. Email security@inferagen.ai with:
- โข A description of the issue
- โข Steps to reproduce
- โข Your name and contact (for credit)
We commit to acknowledging your report within 24 hours and resolving valid issues within 90 days. We do not currently offer bug bounties but we publish acknowledgments on this page.
Read our full responsible disclosure policy โ