BioCV Security Overview
Last updated: 4 November 2025Security contact: info@biocv.org
We design the LISA platform with a defense‑in‑depth approach. This page summarizes key technical and organizational measures (TOMs). More detail is available under NDA on request.
Governance & Access
Security ownership with defined roles; regular risk assessments.
Employee background checks where permitted by law; confidentiality obligations and security training.
Role‑based access control; least privilege; periodic access review; SSO/MFA for employees and administrators.
Data Protection
Encryption in transit: TLS for all external connections and service‑to‑service channels where supported.
Encryption at rest: Industry‑standard encryption for databases, object storage, and backups.
Key management: Managed KMS with restricted access and logging.
Application & Platform Security
Secure SDLC with code review and dependency scanning; secrets managed via vault/KMS.
Environment separation (dev/test/prod); infrastructure as code; immutable deployments where feasible.
Rate limiting, input validation, and protections against common web exploits.
Centralized logging and monitoring; alerting on anomalies.
Vulnerability & Patch Management
Regular vulnerability scanning; prioritization based on severity and exposure.
Patch timelines aligned to risk; emergency patching for critical issues.
Third‑party component inventory with update tracking.
Device & IoT Security
Controlled provisioning/identity for BioCV devices; secure communications between BioTag/BioNode and gateways/cloud.
Update mechanism for firmware/software to deliver security fixes and improvements for supported devices.
Physical security appropriate to deployment environment; tamper considerations in design.
Business Continuity & Resilience
Redundant hosting and data replication; regular, tested backups.
Documented disaster recovery objectives; periodic exercises.
Incident Response & Notifications
Documented incident response plan with detection, triage, containment, eradication, recovery, and lessons learned.
For service disruptions, our support team targets an initial response within 48 hours on Working Days (see SLA).
For personal data breaches, we notify affected customers without undue delay in line with GDPR/UK GDPR and applicable law.
Customer Responsibilities
Configure access controls (roles, MFA) and API keys; maintain customer network and device hygiene.
Keep endpoints, gateways, and apps up to date; promptly apply provided security updates.
Review audit logs and alerts; follow best practices for credential management.
Compliance & Sub‑processors
We align our controls with GDPR Art. 32 and industry best practices.
Our current sub‑processors are listed at https://biocv.org/legal/subprocessors.
Additional information (e.g., penetration test summaries) is available to enterprise customers under NDA.
Vulnerability Disclosure
We welcome responsible disclosure. Report potential vulnerabilities to info@biocv.org with steps to reproduce and any relevant logs. Please avoid publicly disclosing an issue before we have verified and remediated it.
Last updated: 4 November 2025
