NomosLogic

Security Stewardship

Data Security

Trust is our primary API. Clinical-grade protection for genetic and health data.

The Sovereign Hash

Proprietary HMAC-SHA256 protocol that indexes biological data without exposing personally identifiable information. Double-blind architecture maintains physical separation between PII and multi-omic results.

AES-256-GCM

At Rest

TLS 1.3

In Transit

Hardware Security Modules

Key Mgmt

Biological Data Sovereignty

NomosLogic does not — and will never — sell, rent, or lease individual-level genetic or health data. Revenue comes from Logic-as-a-Service subscriptions providing aggregate, de-identified intelligence.

Upon deletion, the cryptographic link between PII and the Sovereign Hash is destroyed immediately. De-identified metadata is retained for legal compliance (7–10 year statutory periods). Raw genetic files are moved to offline cold storage and purged after expiration.

Access & Identity Governance

Multi-factor authentication required for all user sessions. Employees have zero visibility into raw customer DNA; administrators access only anonymized logs.

“Break the Glass” protocol for authorized exceptions with full audit trails.

Regulatory Compliance

HIPAA (Security, Privacy, Breach Notification)
DPDPA & GIPA
GINA
CCPA / CPRA
EU GDPR (Sovereign Adequacy)
X12 / FHIR Standards