Trust & Security
Your data remains yours.
FedOMIX is a neutral orchestration layer, never a data grab. The roles are deliberately explicit, and the security model is a first-class part of the design, not a layer added afterward.
Data Ownership
Three roles, deliberately explicit.
- Your client owns the data.The organization commissioning the work remains the real data owner, always. Generated data is delivered into their storage, not accumulated by the platform.
- The provider remains the processor.That role, and the direct client relationship, don't change because the order flows through FedOMIX.
- FedOMIX handles policy and audit.We coordinate delivery, enforce access control and keep the audit trail — nothing more. Every action on the platform is attributable to a user, an organization and a time.
Security by design
- Encryption in transit and at rest
- Role-based access control per persona
- Organization-level tenant isolation
- Full audit log of every action
- Secure delivery with acknowledgement
- Configurable retention controls
Compliance-readiness is part of the design, not a claim: the architecture follows GDPR-aligned data-handling and processor/controller principles. FedOMIX does not hold ISO 27001, SOC 2, or HIPAA certification — "security by design" describes the architecture, not a certification.
Cloud & Region
Deployed where your data needs to live.
FedOMIX doesn't assume a cloud, a country or a compliance regime. Hosting, storage and data residency are deployment choices, matched to your organization — not fixed by the architecture.
-
Cloud-agnostic by design
FedOMIX runs self-hosted, on any major cloud, or in a hybrid setup. The platform was never built around one vendor's stack, and it isn't locked to one now.
-
Storage-agnostic delivery
Generated data lands wherever you tell it to — your own cloud storage, FedOMIX-managed storage, or on-prem pickup. That's a setting your organization controls, not a fixed pipeline.
-
Data residency, configured per deployment
Where your data and deliverables physically live is a deployment decision matched to your organization's jurisdiction, not something baked into the architecture.
-
Aligned to the regulation that applies to you
GDPR in the EU, HIPAA in the US, or another region's framework — the hosting environment is hardened to the bar that regime requires, decided per deployment rather than assumed.
Questions We're Usually Asked
A short, honest FAQ.
Do you store our raw data?
No, not by default. FedOMIX coordinates delivery and enforces access policy — it should not unnecessarily accumulate customer raw data. Generated data flows from the provider directly into your own storage. FedOMIX holds workflow state and metadata (order status, QC metrics, audit records), not raw genomic files, unless you explicitly choose a managed-storage option.
Do we have to replace our LIMS?
No. FedOMIX sits alongside your existing LIMS, pipelines and lab procedures as a standardized external interface — it doesn't require migration or a rip-and-replace. Providers keep their internal systems and customer relationships untouched; FedOMIX holds the order and its state, not your lab.
Is this GDPR-aligned?
The architecture follows GDPR-aligned data-handling and processor/controller principles by design: encryption in transit and at rest, organization-level tenant isolation, role-based access control, full audit logging, and configurable retention. We describe this as "security by design," not a certification — FedOMIX does not currently hold ISO 27001, SOC 2, or HIPAA certification, and we won't claim otherwise.
Who actually owns the data generated by an order?
The organization that commissioned the work — always. The provider generates the data as the processor; FedOMIX coordinates access and delivery but never becomes the data owner at any point in the workflow.
Can a provider or customer see another organization's data?
No. Every organization is isolated at the tenant level, with role-based access control applied per persona (customer, provider, platform operator). Any platform-operator access for support purposes is exception-based and always audit-logged.
Have a Security Question?
We're happy to go deeper.
Technical, security or commercial — ask us anything before deciding if FedOMIX is a fit.