Role and task determine what can be seen and done.
Data security
Your data. Your rules.
You decide what to store in BIOS, who can access it and for how long. Each permission can be changed or revoked.
We do not claim certifications without independent confirmation.
Different access rights apply to each.
Important access and release events are recorded.
Conducted before organisations are connected at scale.
Security by default
Seven principles for handling data
The purpose is defined in advance
A new purpose requires a new legal basis.
Only the data needed
Scope is limited by task, role and duration.
Policy-based access
Technical capability does not confer permission.
Secure transfer and storage
Channels, secrets and environments are separated.
AI receives only the facts it needs
The dataset is limited to the specific task.
Actions are recorded
Who worked with the data, when and why is logged.
Safe stopping
When in doubt, the result is not released.
Architecture
Protection throughout the data lifecycle
Lifecycle
From collection to deletion
Measures are documented for each pilot.
Source, purpose, consent or another lawful basis.
Versions, provenance and access by role and purpose.
The minimum necessary set rather than access to the entire history.
A separate decision on recipient, purpose, format and channel.
Retention is determined by purpose, contract and applicable requirements.
Requests are handled in accordance with the law, mandatory retention and technical logs.
Oversight
People remain in control of their data
Rights and exceptions are described in the data policy.
Find out what is processed
Request information about your data, processing purposes and legal bases.
Correct your data
Report an inaccuracy and provide the correct information.
Withdraw consent
End processing that relies on consent.
Restrict or delete
Submit a request within the limits permitted by law.
What has been verified
We state only what we can substantiate
No compliance marks or promises that have not yet undergone independent verification.
Legal documents
The data policy, consents and controller's details are available on the website.
Technical protection
Access rights, activity history and secure transfer are being tested.
Independent assessment
The scope of external review is determined before connecting large numbers of organisations.
Certifications
BIOS does not use ISO, SOC 2, HIPAA or other compliance labels without confirmation.
Security contact
Report a security risk
Describe the issue. Do not send documents, passwords or secrets.