Data security

Your data. Your rules.

You decide what to store in BIOS, who can access it and for how long. Each permission can be changed or revoked.

We do not claim certifications without independent confirmation.

By defaultOnly the access needed

Role and task determine what can be seen and done.

SeparationPersonal and medical data are stored separately

Different access rights apply to each.

OversightA history of sensitive actions

Important access and release events are recorded.

Before launchIndependent security review

Conducted before organisations are connected at scale.

Security by default

Seven principles for handling data

01

The purpose is defined in advance

A new purpose requires a new legal basis.

02

Only the data needed

Scope is limited by task, role and duration.

03

Policy-based access

Technical capability does not confer permission.

04

Secure transfer and storage

Channels, secrets and environments are separated.

05

AI receives only the facts it needs

The dataset is limited to the specific task.

06

Actions are recorded

Who worked with the data, when and why is logged.

07

Safe stopping

When in doubt, the result is not released.

Architecture

Protection throughout the data lifecycle

Identity
User verification
Session protection
Access role and purpose
Data
Secure upload
Encryption in transit
Protected storage
AI processing
Only the data needed
Isolated draft
Safety checks
Oversight
Consent and rules
Activity history
Incident handling

Lifecycle

From collection to deletion

Measures are documented for each pilot.

CollectionChecking the legal basis

Source, purpose, consent or another lawful basis.

ProcessingA limited dataset

Versions, provenance and access by role and purpose.

UseFacts for a specific task

The minimum necessary set rather than access to the entire history.

TransferAn authorised dataset

A separate decision on recipient, purpose, format and channel.

RetentionPeriod and version

Retention is determined by purpose, contract and applicable requirements.

DeletionDeletion or restriction

Requests are handled in accordance with the law, mandatory retention and technical logs.

Oversight

People remain in control of their data

Rights and exceptions are described in the data policy.

ACCESS

Find out what is processed

Request information about your data, processing purposes and legal bases.

CORRECTION

Correct your data

Report an inaccuracy and provide the correct information.

WITHDRAWAL

Withdraw consent

End processing that relies on consent.

RESTRICTION

Restrict or delete

Submit a request within the limits permitted by law.

What has been verified

We state only what we can substantiate

No compliance marks or promises that have not yet undergone independent verification.

In place

Legal documents

The data policy, consents and controller's details are available on the website.

Under review

Technical protection

Access rights, activity history and secure transfer are being tested.

Before a broad launch

Independent assessment

The scope of external review is determined before connecting large numbers of organisations.

Not claimed

Certifications

BIOS does not use ISO, SOC 2, HIPAA or other compliance labels without confirmation.

Security contact

Report a security risk

Describe the issue. Do not send documents, passwords or secrets.