Enterprise Platform: Security & Compliance

Security, Compliance & Data Sovereignty

Golden Helix is built for institutions that demand complete control over patient genomic data, with certifications, deployment flexibility, and audit trails to prove it.

ISO 13485 Certified QMS
VarSeq Dx · CE Marked (IVDR)

Certified for Clinical Genomics

Golden Helix maintains the certifications and regulatory marks that clinical laboratories require. Our quality management system governs every stage of software design, development, and delivery.

ISO 13485:2016

Certified quality management system for the design, development, and delivery of medical device software. Governs our entire software lifecycle from requirements through release.

CE-IVDR 2017/746

VarSeq Dx is CE marked for in vitro diagnostic use in the European Economic Area. Installation verification and tiered proficiency are bundled and required before diagnostic use.

Workflow Validation

Field Application Scientists support transparent NGS workflow validation from sample prep through reporting. No black-box pipelines. You understand and control every step of your validated process.

VarSeq Suite and VarSeq Dx

Golden Helix develops two software products under one ISO 13485-certified medical device quality management system. VarSeq Suite is licensed for research use. VarSeq Dx is an in vitro diagnostic medical device CE-marked under Regulation (EU) 2017/746 (IVDR) for clinical diagnostic use.

VarSeq Suite

Research Use Only
Intended Use

Research applications in genomics: variant analysis, annotation, filtering, and reporting workflows that researchers and laboratories design, validate, and control themselves.

Regulatory Status

VarSeq Suite is labeled and intended for Research Use Only (RUO). It is not a medical device and has not been cleared, approved, certified, or registered by any regulatory authority for clinical diagnostic use. Golden Helix makes no representation that VarSeq Suite satisfies requirements applicable to medical devices, in vitro diagnostic products, or clinical laboratory regulations in any jurisdiction.

Geographic Availability

Worldwide, subject to applicable export controls.

Customer Responsibility

Any laboratory-developed test (LDT), clinical workflow, or patient-related application developed or implemented using VarSeq Suite is independently designed, validated, and controlled solely by you. You are solely responsible for determining the suitability, performance, regulatory status, and compliance of any such use under applicable laws and regulations.

Regulated Medical Device

VarSeq Dx

CE Marked · IVDR
Software Capabilities

VarSeq Dx provides the most of the VarSeq Suite capabilities: variant annotation, filtering, ACMG/AMP classification, CNV and structural variant analysis, automation, and reporting.

Intended Use

Clinical diagnostic use as described in its applicable Instructions for Use (IFU). VarSeq Dx is intended for use by qualified laboratory professionals and is designed to support, not replace, professional medical judgment.

Regulatory Status

VarSeq Dx is an in vitro diagnostic medical device CE-marked under Regulation (EU) 2017/746 (IVDR).

Geographic Availability

VarSeq Dx is offered only in jurisdictions where Golden Helix has determined it is authorized for distribution as a medical device.

Before Clinical Use

Before VarSeq Dx may be operated as a medical device, each deployment must complete:

  • Installation Verification Test (IVT) confirms proper installation and end-to-end workflow of VarSeq Dx in the customer’s environment.
  • User Proficiency Test (UPT), or an approved equivalent, completed by each user.

Both are described in the applicable IFU and supported by Golden Helix Field Application Scientists.

At a glance

 VarSeq SuiteVarSeq Dx
ManufacturerGolden Helix, Inc.Golden Helix, Inc.
Manufacturing QMSISO 13485:2016 certifiedISO 13485:2016 certified
Regulatory statusResearch Use Only. Not a medical device.In vitro diagnostic medical device, CE marked under Regulation (EU) 2017/746 (IVDR)
Intended useResearch applicationsClinical diagnostic use per IFU
Geographic availabilityWorldwide, subject to export controlsAuthorized jurisdictions only
Required before clinical useNot for clinical diagnostic useIFU + Installation Verification Test (IVT) + User Proficiency Test (UPT)
Validation responsibilityCustomer (LDT validation)Qualified laboratory professionals, operating under applicable laws and accreditation

Full intended use, regulatory status, and license terms are set forth in the applicable Instructions for Use and End User License Agreement.

Security enforced by where the software runs.

Multi-tenant SaaS platforms inherit shared risk. Golden Helix puts the full software suite on your infrastructure, behind your firewall.

4
HIPAA technical safeguards

Access Controls

LDAP/Active Directory integration enforces role-based access to patient data. SSO via SAML means credentials are managed at the institutional level with your existing password policies.

Audit Trails

Every user action within VarSeq and VSWarehouse is logged and attributed to authenticated individuals. Interpretations, classifications, and signed-out reports carry full user provenance.

Transmission Security

In air-gapped and firewall-mirrored deployments, patient data never traverses the public internet. All outbound connections support authenticated proxy routing.

Data Integrity

All analysis, interpretation, and reporting occurs within your institution's controlled environment. Workflow state saving ensures any past analysis can be reproduced exactly as it was run.

Regulatory Coverage

HIPAA Technical SafeguardsOn-premises architecture
GDPRData residency within jurisdictional boundaries
IVDR 2017/746CE marked VarSeq Dx for diagnostic use in the EEA
CAP / CLIAProject-specific templates and audit trails for accreditation
ISO 13485Certified quality management for medical device software
Pen-Tested
OWASP Top 10 Reviewed

Built for Regulated Environments

Clinical genomics operates at the intersection of the most sensitive data categories and the strictest regulatory frameworks. Golden Helix is architected to meet these requirements without forcing trade-offs.

  • VarSeq Suite (RUO) and VarSeq Dx are separately licensed products with distinct regulatory status: Research Use Only and CE-marked under IVDR, respectively
  • Installation verification by Field Application Scientists before clinical use
  • Tiered proficiency certification program ensures analyst competency
  • Versioned annotation sources and locked-down pipelines for reproducible clinical results

Need Compliance Documentation?

Request security architecture details, certification documents, or a compliance review call.

Request Evaluation

Patient data stays on your infrastructure.

With Golden Helix, there is no shared tenancy, no vendor-hosted patient data, and no dependency on external cloud services to run your clinical workflows.

Cross-Border Data Protection

As genomic testing expands internationally, labs face increasing requirements to keep data within jurisdictional boundaries. On-premises deployment eliminates cross-border transfer concerns entirely.

“Multi-tenant SaaS platforms mean sharing security liability with your provider. Self-managed deployment puts your security team in full control of the perimeter.”
Platform
On-Prem, Private Cloud & Air-Gapped Deployment
Three deployment tiers with progressive security isolation

The Threat Landscape

Ransomware

Air-gapped systems are immune to network-delivered encryption attacks. No internet connection means no remote attack vector.

Data Exfiltration

On-premises deployment keeps patient data within your physical network boundary. No data traverses the public internet in any deployment tier.

Shared Tenancy Risk

Multi-tenant platforms expose you to your provider’s security posture. Self-managed deployment means your perimeter is yours to control.

Irreversible Exposure

Unlike compromised credentials, genomic data cannot be reissued. A breach of genetic information has permanent consequences for affected patients.

Enterprise Security Controls

Single Sign-On

Active Directory, SAML, and LDAP integration. Credentials are managed at the institutional level. Passwords never leave your network. Complexity, rotation, and reuse policies follow your existing standards.

On-Premises Credentials

Workspace Isolation

Logical data separation for multi-group and multi-site deployments. Each clinical team operates independently within their workspace while sharing institutional knowledge through controlled catalogs.

Role-Based Access

Admin Dashboard

Centralized resource management and usage monitoring. Track active users, sample throughput, and storage consumption across your entire deployment from a single administrative interface.

Full Visibility

Compliance Insights & Webcasts

Regulatory guidance, IVDR transition strategies, and best practices for validating clinical genomics workflows.

On-Demand Webcasts

View All Webcasts

Ready for Enterprise-Grade Security?

Join institutions worldwide that trust Golden Helix for secure, compliant clinical genomics infrastructure.

ISO 13485 Certified QMS
VarSeq Dx · CE Marked (IVDR)
Air-Gapped Capable