Skip to content
Trust & Compliance Portal

Donor data deserves a system built to be trusted.

Gammapeak bLIS is the laboratory information system for Organ Procurement Organizations and transplant labs. This portal documents how we protect protected health information, prove compliance, and guarantee the service keeps running, so your procurement and security reviews have a single source of truth.

99.95%
Uptime target
AES-256
Encryption at rest
< 24h
Backup recovery point
posture.statusOperational
  • HIPAA / HITECHBAA available
  • 21 CFR Part 11Records & signatures
  • SOC 2 Type 2Audit in progress
  • TLS 1.3 + AES-256In transit & at rest
  • Software escrowContinuous deposit
  • Cloudflare WAFEdge protection
us-east-1 · us-west-2Multi-region

Overview

A clinical-grade laboratory system, documented for procurement

Organ procurement runs on trust between coordinators, labs, and the families who say yes. bLIS earns its place in that workflow by treating security, privacy, and continuity as product requirements, not afterthoughts. Here is how that holds up under review.

Built for high-stakes donor services

bLIS handles the chain of custody for donor samples, serology, and crossmatch results where an error or an outage is never acceptable. Every design decision starts from that constraint.

Privacy as the default

Protected health information is minimized, access is least-privilege and logged, and PHI never leaves an encrypted, audited boundary. We sign a Business Associate Agreement before any production data is exchanged.

Engineered to keep running

The platform runs active across multiple AWS regions with automated, tested recovery. We pair that with software escrow so your access to the system survives any single point of failure, including us.

Regulatory compliance

HIPAA, HITECH, and 21 CFR Part 11

The two regulatory regimes that matter most to a transplant laboratory are addressed head-on, with the controls a manual reviewer expects to see, not generic assurances.

HIPAA · HITECH

Protected health information, handled to the letter

bLIS operates as a Business Associate under HIPAA and HITECH. Administrative, physical, and technical safeguards are implemented and documented across the platform.

  • Business Associate Agreement (BAA) executed before production data
  • PHI encrypted in transit and at rest; access is least-privilege
  • Immutable audit logging of every PHI access and change
  • Breach notification process aligned to HITECH timelines
FDA · 21 CFR Part 11

Electronic records and signatures that stand up to inspection

For regulated laboratory workflows, bLIS supports the controls required by Title 21 CFR Part 11 for trustworthy, reliable electronic records and signatures.

  • Attributable, time-stamped electronic signatures bound to records
  • Tamper-evident audit trails that cannot be altered or deleted
  • Versioned, retained records with controlled access and retrieval
  • Validated change control and documented system access controls

Business continuity

No single point of failure, including the company

Procurement teams are right to ask about the bus factor: what happens if a region, a dependency, or the vendor itself goes away. bLIS answers with active multi-region infrastructure, tested backups, and a software escrow arrangement that puts the source code within your reach.

infrastructure.topologyMulti-region AWS
Cloudflare WAF
Global edge · TLS 1.3 · WAF
us-east-1Primary
ECS Fargate
RDS (Multi-AZ)
S3 (encrypted)
us-west-2Active replica
ECS Fargate
RDS (Multi-AZ)
S3 (encrypted)
Escrow agent · continuous source deposit

Daily automated backups

Encrypted backups run automatically every day with point-in-time recovery on the primary database. Restores are tested on a recurring schedule so recovery is a routine, not a hope.

RPO < 24h · tested restores

Software escrow

Source code, build instructions, and infrastructure definitions are placed with an independent escrow agent under continuous deposit. Qualifying customers can request access under defined release conditions, so the platform outlives any one vendor.

Continuous source deposit

2
Active AWS regions
us-east-1 / us-west-2
99.95%
Uptime target
Monthly availability
Verified
Escrow deposits
Independently held

SOC 2 Type 2

A real audit, not an automated shortcut

bLIS is undergoing a rigorous SOC 2 Type 2 examination with an established third-party auditing firm. We chose a manual, evidence-based audit specifically so it survives the kind of careful procurement review your security team runs, rather than a badge generated by a scanner.

Audit in progressType 1 report available

The Type 1 report and the in-flight Type 2 status are available to review under NDA today. Request access in the portal below and we will share current standing and the expected report date.

  1. Controls implemented

    Security, availability, and confidentiality controls mapped to the Trust Services Criteria and operating across the platform.

  2. Readiness assessment

    Independent gap assessment completed with a recognized assurance firm; remediation items closed and evidence collected.

  3. Type 2 observation period

    Controls under examination over a continuous observation window by a major third-party auditing firm, with real evidence, not an automated questionnaire.

  4. 4

    Type 2 report issued

    Final SOC 2 Type 2 report available to qualifying procurement teams under NDA on completion of the audit.

Infrastructure security

Defense in depth, from the edge to the database

Encryption, edge protection, monitoring, and access control work together so a single weak point never becomes an incident.

TLS 1.3 · AES-256

End-to-end encryption

All traffic is encrypted with TLS 1.3 in transit. Data at rest, including database storage and S3 backups, is encrypted with AES-256 using managed keys.

Edge protection

Cloudflare WAF

A Web Application Firewall at the edge filters malicious traffic, mitigates DDoS, and enforces rate limits before requests ever reach the application.

Continuous scanning

Vulnerability monitoring

Dependencies and infrastructure are scanned continuously, with automated alerting and a defined remediation SLA for anything that surfaces.

RBAC · MFA

Least-privilege access

Role-based access control, enforced multi-factor authentication, and scoped credentials keep production access minimal and fully audited.

Tamper-evident

Immutable audit logs

Every privileged action and PHI access is recorded to tamper-evident logs retained for review and incident investigation.

Reproducible

Infrastructure as code

The entire environment is defined as code and version-controlled, so configuration is reviewable, reproducible, and recoverable.

Document request portal

Request the documentation your review needs

Compliance artifacts are shared under NDA with verified procurement and security teams. Tell us who you are and what you need; we route requests to our security team and reply with next steps and a mutual NDA.

  • HIPAA Business Associate Agreement (BAA)Executed before any production PHI is exchanged.
  • SOC 2 Type 1 / Type 2 reportType 1 available now; Type 2 on completion of the audit.
  • Software escrow legal agreementTerms for continuous source deposit and release conditions.

This request does not transmit PHI. Do not include patient or donor information in the message field. All documents are released under a mutual non-disclosure agreement.

Secure document request
Documents requested

Select all that apply. Released under mutual NDA.

By submitting you consent to be contacted about this request. No PHI is collected on this form.