Zum Hauptinhalt springen

BioCV Security Overview

Last updated: 4 November 2025

Security contact: info@biocv.org

We design the LISA platform with a defense‑in‑depth approach. This page summarizes key technical and organizational measures (TOMs). More detail is available under NDA on request.

Governance & Access

  • Security ownership with defined roles; regular risk assessments.

  • Employee background checks where permitted by law; confidentiality obligations and security training.

  • Role‑based access control; least privilege; periodic access review; SSO/MFA for employees and administrators.

Data Protection

Encryption in transit: TLS for all external connections and service‑to‑service channels where supported.

Encryption at rest: Industry‑standard encryption for databases, object storage, and backups.

Key management: Managed KMS with restricted access and logging.

Application & Platform Security

  • Secure SDLC with code review and dependency scanning; secrets managed via vault/KMS.

  • Environment separation (dev/test/prod); infrastructure as code; immutable deployments where feasible.

  • Rate limiting, input validation, and protections against common web exploits.

  • Centralized logging and monitoring; alerting on anomalies.

Vulnerability & Patch Management

  • Regular vulnerability scanning; prioritization based on severity and exposure.

  • Patch timelines aligned to risk; emergency patching for critical issues.

  • Third‑party component inventory with update tracking.

Device & IoT Security

  • Controlled provisioning/identity for BioCV devices; secure communications between BioTag/BioNode and gateways/cloud.

  • Update mechanism for firmware/software to deliver security fixes and improvements for supported devices.

  • Physical security appropriate to deployment environment; tamper considerations in design.

Business Continuity & Resilience

  • Redundant hosting and data replication; regular, tested backups.

  • Documented disaster recovery objectives; periodic exercises.

Incident Response & Notifications

Documented incident response plan with detection, triage, containment, eradication, recovery, and lessons learned.

For service disruptions, our support team targets an initial response within 48 hours on Working Days (see SLA).

For personal data breaches, we notify affected customers without undue delay in line with GDPR/UK GDPR and applicable law.

Customer Responsibilities

  • Configure access controls (roles, MFA) and API keys; maintain customer network and device hygiene.

  • Keep endpoints, gateways, and apps up to date; promptly apply provided security updates.

  • Review audit logs and alerts; follow best practices for credential management.

Compliance & Sub‑processors

We align our controls with GDPR Art. 32 and industry best practices.

Our current sub‑processors are listed at https://biocv.org/legal/subprocessors.

Additional information (e.g., penetration test summaries) is available to enterprise customers under NDA.

Vulnerability Disclosure

We welcome responsible disclosure. Report potential vulnerabilities to info@biocv.org with steps to reproduce and any relevant logs. Please avoid publicly disclosing an issue before we have verified and remediated it.


Last updated: 4 November 2025