The Data Developers
Security

Enterprise-Grade Security & Compliance

A public-data-only architecture with governed cloud delivery, source lineage, and procurement-ready controls.

No PII

The estate uses public data products only; no patient-level source files, no claims PHI, and no proprietary customer data required.

No Patient Data

Architecture is HIPAA-compatible because delivered products are public biomedical reference datasets, not covered PHI.

No Proprietary Data

Customers keep their internal data in their own warehouse and join it under their own governance controls.

Delivery controls

Secure warehouse-native access

BigQuery IAM and Snowflake role-based access keep data in authorized environments.

BigQuery IAM controls

Access is managed through Google Cloud IAM, dataset permissions, audit logs, and customer-controlled project boundaries.

Snowflake role-based access

Native shares are governed with account-level authorization, roles, grants, and warehouse-local query controls.

Compliance

Procurement-ready posture

GCP NativeHIPAA-compatible architectureBAA available on requestPublic data onlySOC 2 in progress
Lineage

Data lineage and version control

Every row is traceable to source authority, ingestion batch, transformation logic, and refresh metadata.

Every data product traceable to source authority

Ingestion metadata tracked for each refresh

Version history maintained for labels, schemas, and curated mappings

Validation exceptions surfaced for customer review