SECURITY & COMPLIANCE

Security by design,
proven on every release.

CytoTrax confines sensitive information to a small and precisely known footprint, isolates it at the database level, records every action in an audit trail that stays intact under all circumstances, and re-proves all of it automatically on every single change.

Four principles run through everything

Security in CytoTrax is a property of the design rather than a feature added late.

01

Privacy by design

Clinical information is confined to two clearly defined surfaces, and every privacy control is concentrated on protecting them. A small, precisely known footprint is the strongest privacy control there is.

02

Enforce below the application

The strongest controls sit in the database and the platform rather than in application code. Tenant separation and audit integrity are guaranteed independently of how the application behaves.

03

Safe by default

When a control can't be applied, CytoTrax declines the operation rather than proceeding — a request without a tenant context returns no data, not all data.

04

Prove it continuously

More than one hundred automated security tests run against a real database on every change, so none of these controls can regress unnoticed.

Security posture at a glance

Controls that are live in the product today, spanning identity, transport, storage, and the release pipeline itself.

Tenant isolation

PostgreSQL row level security, enabled and forced on every table, enforced against a restricted database role.

Authentication

Multi factor authentication on the laboratory portal and the administration console. Argon2id password hashing.

Authorisation

Role based permissions re-checked against the database on every request, never trusted from a token.

Session management

Thirty minute inactivity timeout, twelve hour absolute maximum, and immediate revocation on sign out or password change.

Transport security

TLS throughout, HTTP Strict Transport Security, a full set of browser security headers, and origin verification.

Encryption at rest

Server side encryption for uploaded quality control documents, plus provider managed encryption of database and storage volumes.

Audit trail

Append only in both databases, enforced by database permissions. Creates, changes, deletions and reads are all recorded.

File uploads

Content inspected rather than trusted by file name, size capped, antivirus scanned, served only through an authenticated endpoint.

Retention & deletion

Scheduled automatic purge of expired sensitive data, plus administrator controlled deletion and redaction inside the product.

Resilience

Encrypted scheduled backups of both databases and of document storage, with a documented and tested restore procedure.

Secure development

Linting, type checking and dependency vulnerability scanning on every change, plus a dedicated security regression suite.

Safe configuration

The application refuses to start in production if it is configured in a way that would weaken any of the above.

Built to support your HIPAA compliance program

CytoTrax maps its technical safeguards to the HIPAA Security Rule (45 CFR §164.312) — access control, audit controls, integrity, person or entity authentication, and transmission security. Administrative safeguards are supported through audit retention, backup and contingency procedures, and automated testing; physical safeguards are delegated to our cloud provider under its own audited compliance program.

BUSINESS ASSOCIATE AGREEMENT AVAILABLE

CytoTrax will execute a business associate agreement, and holds subprocessors that handle protected health information to the same requirement. The full HIPAA control mapping, security test coverage, and operational runbooks are available on request to support your vendor assessment.