Enterprise-Grade Security & Compliance
A public-data-only architecture with governed cloud delivery, source lineage, and procurement-ready controls.
No PII
The estate uses public data products only; no patient-level source files, no claims PHI, and no proprietary customer data required.
No Patient Data
Architecture is HIPAA-compatible because delivered products are public biomedical reference datasets, not covered PHI.
No Proprietary Data
Customers keep their internal data in their own warehouse and join it under their own governance controls.
Secure warehouse-native access
BigQuery IAM and Snowflake role-based access keep data in authorized environments.
BigQuery IAM controls
Access is managed through Google Cloud IAM, dataset permissions, audit logs, and customer-controlled project boundaries.
Snowflake role-based access
Native shares are governed with account-level authorization, roles, grants, and warehouse-local query controls.
Procurement-ready posture
Data lineage and version control
Every row is traceable to source authority, ingestion batch, transformation logic, and refresh metadata.
Every data product traceable to source authority
Ingestion metadata tracked for each refresh
Version history maintained for labels, schemas, and curated mappings
Validation exceptions surfaced for customer review