SECURITY & COMPLIANCE
Security by design,
proven on every release.
CytoTrax confines sensitive information to a small and precisely known footprint, isolates it at the database level, records every action in an audit trail that stays intact under all circumstances, and re-proves all of it automatically on every single change.
Four principles run through everything
Security in CytoTrax is a property of the design rather than a feature added late.
Privacy by design
Clinical information is confined to two clearly defined surfaces, and every privacy control is concentrated on protecting them. A small, precisely known footprint is the strongest privacy control there is.
Enforce below the application
The strongest controls sit in the database and the platform rather than in application code. Tenant separation and audit integrity are guaranteed independently of how the application behaves.
Safe by default
When a control can't be applied, CytoTrax declines the operation rather than proceeding — a request without a tenant context returns no data, not all data.
Prove it continuously
More than one hundred automated security tests run against a real database on every change, so none of these controls can regress unnoticed.
Security posture at a glance
Controls that are live in the product today, spanning identity, transport, storage, and the release pipeline itself.
Tenant isolation
PostgreSQL row level security, enabled and forced on every table, enforced against a restricted database role.
Authentication
Multi factor authentication on the laboratory portal and the administration console. Argon2id password hashing.
Authorisation
Role based permissions re-checked against the database on every request, never trusted from a token.
Session management
Thirty minute inactivity timeout, twelve hour absolute maximum, and immediate revocation on sign out or password change.
Transport security
TLS throughout, HTTP Strict Transport Security, a full set of browser security headers, and origin verification.
Encryption at rest
Server side encryption for uploaded quality control documents, plus provider managed encryption of database and storage volumes.
Audit trail
Append only in both databases, enforced by database permissions. Creates, changes, deletions and reads are all recorded.
File uploads
Content inspected rather than trusted by file name, size capped, antivirus scanned, served only through an authenticated endpoint.
Retention & deletion
Scheduled automatic purge of expired sensitive data, plus administrator controlled deletion and redaction inside the product.
Resilience
Encrypted scheduled backups of both databases and of document storage, with a documented and tested restore procedure.
Secure development
Linting, type checking and dependency vulnerability scanning on every change, plus a dedicated security regression suite.
Safe configuration
The application refuses to start in production if it is configured in a way that would weaken any of the above.
Built to support your HIPAA compliance program
CytoTrax maps its technical safeguards to the HIPAA Security Rule (45 CFR §164.312) — access control, audit controls, integrity, person or entity authentication, and transmission security. Administrative safeguards are supported through audit retention, backup and contingency procedures, and automated testing; physical safeguards are delegated to our cloud provider under its own audited compliance program.
BUSINESS ASSOCIATE AGREEMENT AVAILABLE
CytoTrax will execute a business associate agreement, and holds subprocessors that handle protected health information to the same requirement. The full HIPAA control mapping, security test coverage, and operational runbooks are available on request to support your vendor assessment.