Security

Information security

The controls protecting account and enquiry data, and the standards we are building toward. Last updated 5 August 2026.

Certification status

Cytosomatic Labs is not currently certified against ISO/IEC 27001 or ISO/IEC 27701. That work is in progress. The controls below describe what we actually operate today; they have not been assessed by an external certification body. We will publish certificate details here once a certificate is issued.

Frameworks

Standards and regulations shaping our practice

ISO/IEC 27001

Information security management systems

We are structuring our information security management system around the Annex A control set: defined asset ownership, access control, cryptography, operations security, supplier relationships and incident management. Certification is in progress and not yet held.

ISO/IEC 27701

Privacy information management

Extends the ISMS to personal data. It shapes how we record processing purposes, retention periods and data-subject request handling. Certification is in progress and not yet held.

GDPR

EU General Data Protection Regulation

We process personal data on a lawful basis, collect only what an enquiry or account requires, honour access, correction, deletion and objection requests, and document our processors. Our practices are described in the privacy policy.

HIPAA

US health information privacy

We are not a covered entity and do not receive protected health information through this website or our research. If a future collaboration involves PHI, it will require a business associate agreement and a separate controlled environment — it will not run on this website.

Controls

What we operate today

Access control

  • Authentication is handled by a managed identity provider; we never store passwords ourselves.
  • Optional Google sign-in — we never see your Google credentials.
  • Row-level access rules mean a signed-in account can read only its own records.
  • Team access to systems is granted on a need-to-use basis and reviewed as roles change.

Data protection

  • All traffic to this site is served over TLS.
  • Data at rest is encrypted by our managed database provider.
  • Enquiry and account data are minimised to what is needed to reply to you.
  • No payment data and no patient health records are collected on this site.

Operations

  • Dependencies are scanned for known vulnerabilities and updated on a regular cadence.
  • Automated database security checks run against access rules and exposure.
  • Application and access logs are retained for a limited operational window.
  • Backups are managed by our infrastructure provider with point-in-time recovery.

Incident response

  • A named owner triages any suspected security event.
  • Containment first, then root-cause analysis, then a written post-incident record.
  • Affected individuals and, where required, regulators are notified within statutory timeframes.
  • Findings are converted into control changes, not just a log entry.

Subprocessors

Who else touches the data

ServicePurpose
Application hosting platformServes this website and its server functions.
Managed database and authentication providerStores accounts and partnership enquiries; issues authentication sessions.
GoogleIdentity provider, only when a visitor chooses to sign in with a Google account.

These providers act on our instructions. We do not sell personal information or share it with anyone else except where required by law.

Reporting a vulnerability

If you believe you have found a security issue in this website, please tell us through the contact page before disclosing it publicly. Give us enough detail to reproduce the issue. We will acknowledge your report, keep you updated while we investigate, and we will not pursue action against good-faith research that avoids privacy violations, service degradation and data destruction.