NO CLAIMS WE HAVEN'T EARNED MEDICAL PRIVACY MODE · FAILED RUNS AUTO-DELETED · INFRASTRUCTURE ATTESTATIONS BELONG TO GROQ · GOOGLE · RAZORPAY NO CLAIMS WE HAVEN'T EARNED MEDICAL PRIVACY MODE · FAILED RUNS AUTO-DELETED · INFRASTRUCTURE ATTESTATIONS BELONG TO GROQ · GOOGLE · RAZORPAY
TRUST & SECURITY

Security & Data Handling

What we do, what we don't, and what infrastructure providers cover. We do not claim certifications we haven't earned. Infrastructure attestations belong to Groq, Google Cloud, and Razorpay — not to OmniBioFex.

omnibiofex/1.0-47b TLS 1.2+ · AES-256 No training on your data
Security Mesh LIVE 32 × 8 CONTROLS
Move your cursor across the grid — every cell that lights is a security control we've mapped.
🔐 Encryption
🔒

TLS 1.2+

All traffic encrypted in transit; 1.3 negotiated wherever the client supports it.

🛡️

AES-256 AT REST

Firestore + Cloud Storage encrypted with AES-256 by Google default.

🛂 Identity & Access
🔑

GOOGLE OAUTH 2.0

Identity via Google. Zero passwords stored on our servers.

🎫

SHORT-LIVED JWT

Session tokens issued and auto-rotated by Firebase Auth.

🚫

DEFAULT-DENY RULES

Firestore blocks all reads/writes unless explicitly permitted by rule.

🛂

PER-USER SCOPING

Users may read only their own reports and wallet data.

🧠 Data Handling — Honest Summary
📁

UPLOADS ARE STORED

Uploaded images are stored in your private Cloud Storage folder so they appear in your report history. You can request deletion at any time.

🧠

NO TRAINING

Your uploads are never used to train or fine-tune any model.

🗑️

30-DAY DELETION

Account and history deletion completed within 30 days of a verified request.

🚫

NO PHI REQUIRED

Do not upload identifiable PHI. Use de-identified images unless you have independent legal authority.

🔒 Privacy Controls in the App
🔒

MEDICAL PRIVACY MODE

Toggle that redacts history previews and signs you out after 15 min idle. Client-side only; no server-side tracking of the toggle.

🗑️

FAILED RUNS CLEANED UP

If the inference step fails, the uploaded image is deleted immediately and the wallet charge is refunded automatically.

🛂

PER-USER STORAGE FOLDER

Every uploaded image lives under users/{uid}/chat/{sessionId}/. Firestore rules deny cross-user reads.

🔑

API KEYS PER WALLET

One Bearer key per wallet. Rotate any time from the API panel. Never exposed to the browser bundle.

⚡ Inference — Groq

HIGH-THROUGHPUT INFERENCE

OmniBioFex 1.0 47B served on Groq's LPU stack; up to ~450+ tps.

☁️

GROQ — SOC 2 TYPE II

Attestation held by Groq, not OmniBioFex.

🛡️

GROQ DATA POLICY

See groq.com/privacy for their current inference data-retention policy.

💳 Payments — Razorpay
💳

PCI-DSS L1

Held by Razorpay, our payment processor.

💳

ISO 27001:2022

Held by Razorpay.

🇮🇳

RBI-AUTHORISED PA

Razorpay holds a Reserve Bank of India Payment Aggregator license.

☁️ Infrastructure — Google Cloud
☁️

SOC 1 / 2 TYPE II / 3

Held by Google Cloud.

☁️

ISO 27001 / 27017 / 27018

Held by Google Cloud.

🤖 AI Governance — Design Alignment
🤖

NIST AI RMF

Design aligned. No independent audit.

🇪🇺

EU AI ACT — ART. 4

Literacy obligations considered in product design. No independent audit.

🌍

WHO AI ETHICS

Design aligned. No independent audit.

HOW TO READ THIS — Infrastructure certifications are held by Groq, Google Cloud, and Razorpay. "Aligned" or "design-aligned" means we mapped our design to the framework's principles. It does not mean we are independently audited or certified. OmniBioFex is not a medical device.

Read the fine print

Full privacy policy and terms of service — written plainly, no hand-waving.