Biosystems One Trust Center

Security and privacy, stated precisely.

Review how Biosystems One products handle data, identity, access, incidents, and assurance—plus what is implemented, still under review, or planned before commercial release.

Least privilegeData minimizationProduct-specific disclosureNo unsupported certification claims

Scope and evidence

One company. Different product boundaries.

The corporate website and five Biosystems One products do not collect or process the same information. This center reports their controls separately so a safeguard in one product is never implied to exist in another.

“Implemented” describes a control present in the current product code or architecture. It does not mean independently certified. Roadmap items are clearly labelled and should not be relied upon as current controls.

Public website

Biosystems One

Informational website and inquiry forms. Do not submit confidential, regulated, clinical, financial, or proprietary records.

Corporate privacy scope →
Open beta

MotionLab

Source video and images are processed on the device. Optional sync stores project JSON, not source media.

Product trust details →
Launch preparation

ErgoThrive

Tenant isolation and private media/report storage are implemented. Domain, accessibility, security, and operational reviews remain launch gates.

Product maturity →
Invite-only closed beta

HF Studio

Authentication, TOTP MFA, controlled records, organizations, memberships, and tenant authorization are implemented. Production-readiness review remains open.

Beta boundary →
Catalogue foundation

B1 Ergonomics

Public non-commercial fixtures are separated from governed evidence and claims. Accounts, assessment uploads, checkout, and supplier integrations are not represented as live.

Catalogue boundary →
Validation stage

MotionLab Performance

Analysis and session history are local to the iPhone. Raw video is processed on device and is not retained or uploaded.

Privacy boundary →

01 / Security

Defense in depth, matched to product maturity.

Controls are designed around access boundaries, safe defaults, and the sensitivity of the product’s data.

ACCESS

Least privilege

Product data access is scoped to authenticated users and, where applicable, an organization and explicit project context.

TENANCY

Database-enforced isolation

ErgoThrive uses PostgreSQL row-level security and organization-prefixed storage paths. HF Studio uses default-deny authorization and tested membership boundaries.

SECRETS

Server-side credentials

Service credentials belong in managed environment stores. Browser-exposed variables and responses must not contain service-role, payment, email, or deployment secrets.

WEB

Application safeguards

Current applications use input validation, safe redirects, security headers, protected routes, origin controls where applicable, and restrictive cookie settings.

RELEASE

Verification before launch

Known critical tenant-isolation, authorization, secret, uncontrolled data-loss, or upload/render defects are release blockers for products handling customer data.

LIMIT

No certification implied

Biosystems One does not currently claim SOC 2, ISO 27001, HIPAA, FedRAMP, or other security certification for these products.

02 / Privacy

Collect less. Explain the purpose.

Privacy starts with defining what each product should not receive.

Corporate inquiry boundary

Contact forms are for non-confidential inquiries. They validate and limit submitted fields, use bot controls when configured, and route messages to Biosystems One support. Sensitive or confidential records should not be submitted.

  • Purpose limitation. Information is used to provide access, operate the selected product, respond to support, or protect the service.
  • Data minimization. Products should not place media, project content, participant information, or proprietary records into analytics or ordinary operational logs.
  • Product notices. Specialized products provide or will provide additional privacy terms for their distinct data and workflows.
  • Requests. Access, correction, and deletion requests may be sent to support@biosystemsone.com, subject to applicable law and necessary retention.

03 / Data storage

Where data lives depends on the product.

Storage statements below describe current architecture—not a promise that all products share the same backend or retention schedule.

SurfaceStored dataLocation and boundaryCurrent state
Corporate siteInquiry details and basic technical logsEmail delivery/support workflow and hosting infrastructureOperational
MotionLabAccount data; optional project JSON; billing identifiersSource media stays on device. Synced JSON is user-scoped. Stripe retains payment records.Open beta
ErgoThriveOrganizations, projects, assessments, workplace media, reportsSupabase database and private storage with organization scope and signed accessPre-launch
HF StudioOrganizations, controlled records, evidence files, reports, and authentication dataSupabase database and private storage with tenant authorization; invite-only closed-beta boundaryClosed beta
B1 ErgonomicsPublic catalogue fixtures and evidence-state metadataPublic catalogue foundation; no customer assessment or purchasing data is representedFoundation
MotionLab PerformanceLocal preferences, session history, baselines, and derived metricsStored on device; raw video is not retained or uploadedValidation

Enterprise regional hosting, customer-managed encryption keys, and dedicated tenancy are not currently offered or implied.

04 / Encryption

Transport protection and credential handling.

  • Production web traffic is served over HTTPS through managed hosting providers.
  • MotionLab passwords use PBKDF2-SHA-256 with a unique salt; sessions and one-time tokens are stored as hashes.
  • ErgoThrive and HF Studio use managed Supabase authentication rather than custom password databases.
  • Provider encryption at rest is the baseline for managed product data.
Not claimedEnd-to-end encryption, customer-managed keys, or per-tenant encryption keys.

05 / Browser and device processing

Local processing where it materially reduces exposure.

MotionLab opens source videos and images directly from the user’s device. Analysis, tracking, measurement, graphing, and most exports run in the browser.

  • Source media is not included in optional MotionLab account sync.
  • Synced MotionLab project JSON may contain calibration, markers, coordinates, measurements, events, and settings.
  • ErgoThrive and HF Studio are controlled cloud workspaces; their uploaded files are not described as local-only.
  • MotionLab Performance processes video on the iPhone and does not retain or upload raw video.
  • B1 Ergonomics currently exposes public catalogue fixtures rather than customer media.

06 / Authentication

Identity controls are product-specific.

The corporate website does not create product accounts. Authentication belongs to each specialized application.

ProductAuthenticationSession and access boundaryMFA
MotionLabVerified email/password and Google OAuthSecure, HTTP-only, SameSite=Lax cookies; user-scoped projectsNot currently offered
ErgoThriveSupabase email/password and Google OAuthProtected routes, organization membership, PostgreSQL RLSRoadmap
HF StudioSupabase authenticationOrganizations, roles, explicit project scope, assurance-level checksTOTP implemented
B1 ErgonomicsNo public account workflow representedPublic catalogue foundation onlyNot applicable
MotionLab PerformanceNo server account requiredLocal app and device boundaryNot applicable

07 / MFA

Stronger assurance for privileged HF Studio roles.

MFA support is product-specific and should not be inferred for the rest of the portfolio.

Sign inPolicy checkTOTP challengeAAL2 session

HF Studio supports TOTP enrollment and challenge through Supabase Auth. Organization Owners and Organization Administrators require MFA; organizations can require it for additional roles, and individuals can opt in.

HF Studio remains in invite-only closed beta. MFA implementation is not a statement that the product has completed independent commercial security validation.

08 / Compliance roadmap

Assurance is earned in stages.

No roadmap item is a current certification or guarantee of regulatory acceptance.

  1. NOW
    Implemented foundations

    Secure product architecture

    Input validation, secret separation, secure session patterns, tenant-aware authorization, private storage where applicable, and product-specific privacy boundaries.

  2. NEXT
    Commercial launch gates

    Independent evidence and operations

    Qualified domain review, application-security and accessibility review, monitoring and incident operations, backup/restore exercises, privacy/legal approval, and independent penetration testing for products handling customer data.

  3. LATER
    Evaluation—not commitment

    Enterprise assurance

    Evaluate SOC 2 readiness, enterprise identity, documented subprocessors and DPA materials, regional deployment needs, and customer assurance packages based on product maturity and customer demand.

Current claims boundary

Biosystems One does not claim that its products are SOC 2 certified, ISO 27001 certified, HIPAA compliant, FedRAMP authorized, FDA validated, IEC certified, or guaranteed to meet a customer’s regulatory obligations.

09 / Vulnerability reporting

Report suspected security issues privately.

Do not place vulnerability details in public issues, social media, or ordinary product screenshots.

Security contactsupport@biosystemsone.com
Start a private report

Include

  • Affected product and URL
  • Clear reproduction steps
  • Observed and expected behavior
  • Potential impact
  • Minimal, sanitized evidence

Please avoid

  • Accessing another user’s data
  • Service disruption or denial-of-service testing
  • Social engineering
  • Uploading malware to production
  • Including secrets or sensitive customer data

Reports are triaged by exploitability and impact. Tenant-isolation bypass, authentication bypass, exposed credentials, remote code execution, and uncontrolled data loss receive highest priority. No bug-bounty payment or legal safe-harbor program is currently advertised.

10 / Incident response

A defined response lifecycle.

Detailed internal procedures and evidence mature with each product’s release stage.

  1. 01

    Detect and triage

    Confirm the signal, preserve relevant evidence, assign severity, and identify the potentially affected product and tenants.

  2. 02

    Contain

    Restrict affected access, revoke credentials or sessions, isolate unsafe paths, and prevent further exposure.

  3. 03

    Investigate and remediate

    Determine scope and root cause, deploy a focused fix, and validate the security boundary and adjacent failure paths.

  4. 04

    Communicate and recover

    Notify affected parties when required by applicable obligations, restore safe operation, and provide accurate known facts without speculation.

  5. 05

    Learn

    Document the timeline and root cause, track corrective actions, and update tests, controls, runbooks, and disclosure where appropriate.

11 / System status

Availability information without invented uptime.

Biosystems One does not currently publish an automated public uptime dashboard or contractual SLA.

Public status page planned

Current reporting channel

For access problems or a suspected service disruption, contact support and identify the affected product, approximate time, browser, and non-sensitive error details.

Ask about service status
Corporate websitePublic information service
MotionLabOpen beta; no availability commitment
ErgoThriveLaunch preparation; no SLA
HF StudioInvite-only closed beta
B1 ErgonomicsPublic catalogue foundation
MotionLab PerformanceValidation-stage iOS foundation

12 / Version history

A dated record of public trust disclosures.

Material changes to security, privacy, storage, authentication, incident, or assurance statements will be recorded here.

Version 1.0August 7, 2026
  • Published the initial portfolio-wide Trust Center.
  • Separated implemented controls from launch gates and roadmap items.
  • Documented product-specific storage, browser processing, authentication, and MFA boundaries.
  • Published vulnerability-reporting and incident-response channels.
  • Disclosed that no public uptime dashboard, SLA, or security certification is currently claimed.

Trust questions

Need more context for an evaluation?

Send a non-confidential description of the product, intended use, and security or privacy requirement you are evaluating.

Contact Biosystems Onesupport@biosystemsone.com