BioSureBioSure
S · 01Security

Compliance is the product  not an add-on.

BioSure was built for labs that get inspected. Every workflow, control, and data policy is documented, auditable, and available to review.

Last audit
Jan 2026
Uptime
99.97%
Data residency
US / EU
BAA
All plans
02Frameworks

Every standard your program depends on.

We don't treat compliance as an optional checkbox. Each framework below is aligned to the specific workflow surfaces inside BioSure — not a blanket SOC 2 logo in the footer.

USP 797Native support

USP 797 Compounding Standards (2023 revision)

Every report template, air-sampling workflow, and gowning-qualification form is aligned to the 2023 USP 797 revision — with configurable limits for ISO 5 / 7 / 8 cleanrooms.

  • Cleanroom class configuration per site
  • Action-level and alert-level breach tracking
  • Surface, air, and personnel sampling workflows
  • Retrospective trending over any window
21 CFR Part 11Lab Pro & Enterprise

FDA 21 CFR Part 11 — Electronic Records & Signatures

Every mutation is captured as an immutable record with user, timestamp, intent, and cryptographic attribution. E-signatures meet Part 11 identification, non-repudiation, and linking requirements.

  • Two-factor identification for signers
  • Biometric or password-based signature binding
  • Audit trail that cannot be altered or deleted
  • Linking of signatures to the signed content
HIPAABAA on every plan · full section below

Health Insurance Portability and Accountability Act

BioSure operates as a Business Associate for labs handling PHI. We sign a BAA on day one and follow the HIPAA Security Rule for administrative, physical, and technical safeguards. See the dedicated HIPAA section below.

  • Signed Business Associate Agreement
  • Encryption at rest (AES-256) and in transit (TLS 1.2+)
  • Role-based access with least-privilege defaults
  • Breach-notification procedures per §164.410
SOC 2 Type IIType II report · Jan 2026

SOC 2 Type II infrastructure controls

Our cloud infrastructure is built on SOC 2 Type II-audited services. The BioSure application layer is on track for our own Type II report by Q3 2026 — Type I completed January 2026.

  • AWS us-east / us-west SOC 2 Type II regions
  • Quarterly penetration testing
  • Continuous vulnerability scanning
  • Independent annual audit
ISO 17025Aligned

ISO/IEC 17025 General requirements for testing labs

Documentation, method validation, and equipment calibration workflows are modelled after ISO 17025 expectations — helping your lab maintain accreditation without duplicating records.

  • Method validation workflows
  • Equipment calibration & maintenance logs
  • Proficiency-testing integration
  • Deviation & corrective-action tracking
03HIPAA

Built to handle Protected Health Information.

When your laboratory handles data that qualifies as Protected Health Information (PHI), BioSure operates as your Business Associate under the U.S. Health Insurance Portability and Accountability Act. We execute a Business Associate Agreement (BAA) before any PHI is processed, and apply the administrative, physical, and technical safeguards required by the HIPAA Security Rule (45 CFR Part 164, Subpart C).

BAA on every plan

We sign a Business Associate Agreement on day one.

RainerTek LLC executes a BAA with every customer that handles PHI in BioSure — before go-live, at no additional cost. The BAA defines permitted uses, safeguard obligations, breach-notification timelines, and return-or-destroy terms on termination.

Request a BAA →
Scope of PHI

Monitoring data is usually not PHI.

CFU counts, organism IDs, and cleanroom results describe a facility, not a patient. PHI can still enter the platform through free-text notes, uploaded documents, or contact records — so once a BAA is in place we hold the entire tenant to HIPAA-grade safeguards.

Minimum necessary

Access is scoped to least privilege.

Role-based access control and per-tenant isolation enforce the HIPAA “minimum necessary” standard — users and BioSure operators reach only the records their role requires, and every access is logged.

Security Rule safeguards · 45 CFR §164.308–316

Administrative

§164.308
  • Designated security official and documented workforce security policies
  • Role-based access management with least-privilege provisioning
  • Workforce activity reviewed through an immutable audit log
  • Contingency planning — encrypted backups and quarterly DR tests
  • Signed business associate agreements with every PHI subprocessor

Physical

§164.310
  • Hosted in AWS SOC 2 Type II data centers (US East / West)
  • Facility and hardware access controlled by the hosting provider
  • No PHI stored on workforce laptops or local devices
  • Certified media sanitization and disposal at end of life

Technical

§164.312
  • Unique user IDs, JWT sessions, automatic logoff, and 2FA
  • AES-256 encryption at rest, TLS 1.2+ encryption in transit
  • Audit controls recording every create, update, and delete
  • Integrity controls and soft-deletion to prevent tampering
  • Authentication via bcrypt-hashed passwords and OAuth 2.0 / OIDC

A shared-responsibility model.

HIPAA compliance is a partnership. BioSure secures the platform; your lab governs how PHI is entered, who is invited, and how results are disclosed. This split is codified in our BAA.

BioSure — Business Associate

Your lab — Covered Entity / BA

Sign a BAA before any PHI is processed

Sign a BAA with BioSure before storing PHI in the platform

Encrypt PHI at rest (AES-256) and in transit (TLS 1.2+)

Enter only the PHI your testing and reporting genuinely require

Enforce access controls, audit logging, and tenant isolation

Provision users and assign least-privilege roles for your team

Maintain backups, disaster recovery, and infrastructure security

Manage workforce onboarding, offboarding, and credential hygiene

Detect, investigate, and report breaches of PHI we process

Obtain patient authorizations and issue any required notices

Return or destroy PHI on termination of the agreement

Export or confirm disposition of PHI during offboarding

Breach notification · §164.410

If PHI is ever compromised, you hear from us fast.

In the event of a breach of unsecured PHI, BioSure notifies the affected covered entity without unreasonable delay and no later than 60 calendar days after discovery — with the detail you need to meet your own notification obligations. We have recorded zero data incidents since 2024.

Subcontractors · §164.308(b)

Every subprocessor that could touch PHI is under a BAA.

Where a subprocessor may create, receive, maintain, or transmit PHI on our behalf — such as our AWS hosting and storage — we hold a signed HIPAA business associate agreement with them. The full subprocessor register is published below.

04Controls

The architecture behind every report.

Four domains, continuously audited. Available in a SIG-Lite or CAIQ questionnaire, and documented in our architecture brief (NDA on request).

01 · Data

  • AES-256 at rest, TLS 1.3 in transit
  • Daily encrypted backups, 35-day retention
  • Customer-owned data — full export anytime, no lock-in
  • Optional data residency (US / EU) on Enterprise

02 · Access

  • Role-based permissions with least-privilege defaults
  • Optional SAML SSO / OIDC on Enterprise
  • Session logging with geolocation and device fingerprint
  • Two-factor authentication available for all users

03 · Infrastructure

  • Hosted on AWS us-east / us-west, SOC 2 Type II regions
  • 99.9% uptime SLA on Lab Pro and Enterprise
  • Multi-AZ redundancy, disaster recovery tested quarterly
  • Content-Security Policy + Subresource Integrity enforced

04 · Operations

  • Quarterly third-party penetration testing
  • Continuous dependency and container scanning
  • Annual independent security audit
  • Public vulnerability disclosure program
05Transparency

Subprocessors, disclosures, and requests.

We keep a public register of every service that processes your lab's data. Request a SOC 2 report, CAIQ, BAA template, or penetration-test summary — typical turnaround is one business day.

SubprocessorsUpdated Jan 2026
  • Amazon Web Services

    Primary hosting, object storage

    US East / West

  • Cloudflare

    CDN, DDoS mitigation, WAF

    Global edge

  • Postmark

    Transactional email delivery

    US

  • Sentry

    Error monitoring (opt-in)

    US / EU

  • Stripe

    Billing & payments

    US

  • Datadog

    Application performance monitoring

    US

Continuously audited · 99.97% uptime · 0 data incidents since 2024

Raise a concern →