Built for high-stakes donor services
bLIS handles the chain of custody for donor samples, serology, and crossmatch results where an error or an outage is never acceptable. Every design decision starts from that constraint.
Gammapeak bLIS is the laboratory information system for Organ Procurement Organizations and transplant labs. This portal documents how we protect protected health information, prove compliance, and guarantee the service keeps running, so your procurement and security reviews have a single source of truth.
Organ procurement runs on trust between coordinators, labs, and the families who say yes. bLIS earns its place in that workflow by treating security, privacy, and continuity as product requirements, not afterthoughts. Here is how that holds up under review.
bLIS handles the chain of custody for donor samples, serology, and crossmatch results where an error or an outage is never acceptable. Every design decision starts from that constraint.
Protected health information is minimized, access is least-privilege and logged, and PHI never leaves an encrypted, audited boundary. We sign a Business Associate Agreement before any production data is exchanged.
The platform runs active across multiple AWS regions with automated, tested recovery. We pair that with software escrow so your access to the system survives any single point of failure, including us.
The two regulatory regimes that matter most to a transplant laboratory are addressed head-on, with the controls a manual reviewer expects to see, not generic assurances.
bLIS operates as a Business Associate under HIPAA and HITECH. Administrative, physical, and technical safeguards are implemented and documented across the platform.
For regulated laboratory workflows, bLIS supports the controls required by Title 21 CFR Part 11 for trustworthy, reliable electronic records and signatures.
Procurement teams are right to ask about the bus factor: what happens if a region, a dependency, or the vendor itself goes away. bLIS answers with active multi-region infrastructure, tested backups, and a software escrow arrangement that puts the source code within your reach.
Encrypted backups run automatically every day with point-in-time recovery on the primary database. Restores are tested on a recurring schedule so recovery is a routine, not a hope.
RPO < 24h · tested restores
Source code, build instructions, and infrastructure definitions are placed with an independent escrow agent under continuous deposit. Qualifying customers can request access under defined release conditions, so the platform outlives any one vendor.
Continuous source deposit
bLIS is undergoing a rigorous SOC 2 Type 2 examination with an established third-party auditing firm. We chose a manual, evidence-based audit specifically so it survives the kind of careful procurement review your security team runs, rather than a badge generated by a scanner.
The Type 1 report and the in-flight Type 2 status are available to review under NDA today. Request access in the portal below and we will share current standing and the expected report date.
Security, availability, and confidentiality controls mapped to the Trust Services Criteria and operating across the platform.
Independent gap assessment completed with a recognized assurance firm; remediation items closed and evidence collected.
Controls under examination over a continuous observation window by a major third-party auditing firm, with real evidence, not an automated questionnaire.
Final SOC 2 Type 2 report available to qualifying procurement teams under NDA on completion of the audit.
Encryption, edge protection, monitoring, and access control work together so a single weak point never becomes an incident.
All traffic is encrypted with TLS 1.3 in transit. Data at rest, including database storage and S3 backups, is encrypted with AES-256 using managed keys.
A Web Application Firewall at the edge filters malicious traffic, mitigates DDoS, and enforces rate limits before requests ever reach the application.
Dependencies and infrastructure are scanned continuously, with automated alerting and a defined remediation SLA for anything that surfaces.
Role-based access control, enforced multi-factor authentication, and scoped credentials keep production access minimal and fully audited.
Every privileged action and PHI access is recorded to tamper-evident logs retained for review and incident investigation.
The entire environment is defined as code and version-controlled, so configuration is reviewable, reproducible, and recoverable.
Compliance artifacts are shared under NDA with verified procurement and security teams. Tell us who you are and what you need; we route requests to our security team and reply with next steps and a mutual NDA.
This request does not transmit PHI. Do not include patient or donor information in the message field. All documents are released under a mutual non-disclosure agreement.