Security, Terms & Cookies
This page summarizes the service's security practices, acceptable use expectations, and browser storage used by the application.
Security practices
- Access is intended for authenticated users and is limited by roles and permissions.
- Sensitive downloads are served through authorized endpoints rather than unrestricted file links.
- Important sensitive access and denied-access events are recorded for review and monitoring.
- Account lockout, secure cookies, security headers, host restrictions, and no-cache controls are enabled where applicable.
- Dependencies and build artifacts should be scanned and kept on supported, patched releases.
These controls reduce risk but do not eliminate it. Production security also requires protected credentials, encrypted infrastructure and backups, restricted network access, tested recovery procedures, trained personnel, and a documented incident-response process.
Security concerns and incident reporting
Do not send full patient records, passwords, tokens, or genetic results through an unsecured email or public form. Report suspected unauthorized access, lost credentials, or exposed information through the support or security contact provided by your organization.
Potential incidents should be investigated under the applicable incident-response and breach-notification procedures.
Cookies and browser storage
The application uses necessary cookies and browser storage to support sign-in, session security, and normal operation. Blocking required cookies may prevent the application from working correctly.
If non-essential analytics, advertising, or third-party tracking is introduced, this notice should be updated and any required consent should be obtained before that tracking is enabled.
Acceptable use
Authorized users must protect their credentials, use only the access granted to them, verify recipients before releasing reports, and promptly report suspected misuse. Users must not attempt to bypass authorization, access another person's information without a legitimate need, upload malicious content, or share accounts.
Access may be suspended when necessary to protect patients, the service, or the organization.
Scope of this page
This summary does not replace a contract, business associate agreement, Notice of Privacy Practices, patient consent, authorization, or other legal terms that may apply to a particular organization or test.