Robust security features

QuartzBio protects privacy, intellectual property, and other critical data with a variety of robust security measures, including:

Encryption at rest

  • Raw data encrypted in S3 (AES256)
  • Biomarker database is encrypted (AES256)
  • Any local instance storage is encrypted (AES256)

Encryption in transit

  • Aspera (AES256)
  • Any request to BM database encrypted via SSL

Server access

  • Servers are behind firewall and are only accessible after authentication
  • Access to server resources is restricted to authorized team members
  • System and security groups used to provide fine-grained access controls of any resource

Regulatory compliance

QuartzBio serves customers worldwide and we help ensure compliance with key region-specific regulations governing the handling and privacy of data, including:

  • Applicable GDPR policy
  • Privacy policy
  • Compliance officer is located in Germany
  • AWS infrastructure in Germany data center (eu-central-1) for studies requiring data to reside in EU
  • Uses HIPAA-compliant services
  • Services are being used to comply with HIPAA security requirements (e.g. encryption, monitoring, access management)

QuartzBio is compliant with all relevant provisions of 21 CFR part 11, using a checklist to determine the applicability of the guideline for each system we deploy. Contact us for details.

QuartzBio platform components were developed and are routinely assessed for compliance with relevant portions of GxP regulations and can be validated as part of a client setup to fit into a client’s GxP system.

QuartzBio utilizes extensive logging capabilities to capture logs at any level. All user actions and data access are tracked in our audit trail which can be made accessible to the client upon request in flat-file, human-readable form or client-specific report to meet client requirements.

QuartzBio is registered in the Human Genetic Resource Administration of China (HGRAC) system.

Additional certifications available upon request

AI enablement with security and privacy

QuartzBio is committed to ensuring any AI enablement complies with data privacy and security standards. All AI models are running within QuartzBio-controlled, monitored, and secured infrastructure, and no data is leaving this controlled environment. QuartzBio is not using OpenAI’s public APIs and no data is shared to train publicly available large language models (LLMs).

Learn how our platform can transform your programs.

Related resources

Documentation

Technical Infrastructure and Architecture Brief

Product Literature

QuartzBio AI Virtual Assistant Frequently Asked Questions