QuestOmics

Security

How your data is kept

QuestOmics handles human gut microbiome data, which often describes identifiable study participants. This page describes the measures actually in place, in the detail a research office or a security reviewer needs.

Last updated: July 2026

Our role, and yours

We are the data controller for your account details, your billing records, and the operational logs we keep to run the platform. We are a data processor for the sequencing files, sample metadata and analysis results you upload or generate, which describe your study and its participants: you or your institution decide what to study and who to study, and we act on your instructions. That split is written down in our data processing agreement.

Where it runs

Uploaded files and results are stored in Amazon S3 in Stockholm, Sweden. The application and its database run on a server in the same region. Analyses execute on dedicated compute servers in Germany. All three are inside the European Economic Area, so your sequencing data does not leave it. The full provider list, including the ones that do operate outside the EEA and what they can see, is on our subprocessors page.

Encryption

Everything in transit is encrypted with TLS, including your uploads, which go straight from your browser to object storage over a short-lived signed URL rather than passing through our application. Objects at rest are encrypted by the storage layer with AES-256.

Separation between accounts

Every stored object lives under a prefix keyed to the owning account, and every request for one is authorised against the signed-in user before a URL is issued. Analyses run in a working directory unique to that job, which is cleared when the job starts so a retry cannot read what a previous run left behind. Sharing happens only when you explicitly invite someone to a project.

Accounts and access

Passwords are never stored. We keep a scrypt hash with a per-account random salt, and compare it in constant time. You can sign in with Google instead, in which case we never see a password at all. The API is not reachable directly from the public internet: it listens only on the loopback interface, behind a proxy that accepts traffic from our network provider, and authenticated routes independently verify a session token. Administrative access to production is limited to the operator named below.

The analysis environment

Each analysis runs inside a sealed container image with a cleared environment, so a pipeline sees the files for that job and nothing else on the host. Images are built once and pinned, and the run records which image, which tool versions and which settings produced the result. That record is what your Methods section is written from, and it is also what lets us tell you exactly what processed a given file.

Written interpretations

When you ask for a written interpretation of a result, the result table is sent as text to a language model provider so the narrative can be produced. Raw sequencing files are never sent. The providers involved, and what each receives, are named on the subprocessors page. If you would rather no result content left our infrastructure at all, contact us before you upload and we will tell you which analyses can run without this step.

Deletion

You can delete individual files, projects and results at any time, and the underlying stored objects go with them. Deleting your account from Settings erases the projects, files and outputs associated with it. We keep only what the law requires afterwards, such as the record of which policy version you accepted, with your identity removed, and invoices needed for tax purposes.

If something goes wrong

If a security incident affects personal data, we will act to contain it, notify the affected customers without undue delay, and notify Autoriteit Persoonsgegevens (the Dutch Data Protection Authority) within 72 hours of becoming aware of it where the law requires. To report a vulnerability, write to svalenzuela@questomics.app. We will acknowledge your report and will not pursue anyone who investigates in good faith and gives us a reasonable chance to fix the issue before disclosing it.

Certifications

We are not currently certified against SOC 2 or ISO 27001, and we would rather say so than imply otherwise. QuestOmics is a small operation, and the measures on this page are the ones we can evidence today. If your institution needs a completed security questionnaire, a signed data processing agreement, or a formal certification on a timeline, write to us and we will tell you honestly where we stand.