Store
- Uploads are encrypted at rest. Keys are rotatable without a re-upload.
- The DNA object store must not be publicly readable; a build that would make it public is intended to fail.
- We do not operate a public match pool.
Consent and reads
- A kit is not stored without a consent-ledger entry.
- Withdrawal closes every read path to that kit by guard, not by a manual checklist.
- Operator access to customer payloads is an audited exception, not a browsing habit.
Logs and AI
- Logs are redacted when written: SNP rows, genotype runs and email addresses do not land in log destinations.
- AI receives a request fragment only. Raw SNP rows and other customers' data stay out. Living people and minors are masked unless a logged override says otherwise.
- Customer data is not used to train models.
Backups
- Nightly encrypted off-box backups of the database and the object stores, with restore scripts that are drilled, not assumed.
- High-impact and bulk writes can be blocked by friction controls so a single action cannot silently rewrite a graph.
What this does not mean
Encryption and guards reduce risk. They do not make a sole-trader service immune to a determined attacker, a forced legal process, or a file you export and then lose.

