Biosystems One
Informational website and inquiry forms. Do not submit confidential, regulated, clinical, financial, or proprietary records.
Corporate privacy scope →Biosystems One Trust Center
Review how Biosystems One products handle data, identity, access, incidents, and assurance—plus what is implemented, still under review, or planned before commercial release.
Scope and evidence
The corporate website and five Biosystems One products do not collect or process the same information. This center reports their controls separately so a safeguard in one product is never implied to exist in another.
“Implemented” describes a control present in the current product code or architecture. It does not mean independently certified. Roadmap items are clearly labelled and should not be relied upon as current controls.
Informational website and inquiry forms. Do not submit confidential, regulated, clinical, financial, or proprietary records.
Corporate privacy scope →Source video and images are processed on the device. Optional sync stores project JSON, not source media.
Product trust details →Tenant isolation and private media/report storage are implemented. Domain, accessibility, security, and operational reviews remain launch gates.
Product maturity →Authentication, TOTP MFA, controlled records, organizations, memberships, and tenant authorization are implemented. Production-readiness review remains open.
Beta boundary →Public non-commercial fixtures are separated from governed evidence and claims. Accounts, assessment uploads, checkout, and supplier integrations are not represented as live.
Catalogue boundary →Analysis and session history are local to the iPhone. Raw video is processed on device and is not retained or uploaded.
Privacy boundary →01 / Security
Controls are designed around access boundaries, safe defaults, and the sensitivity of the product’s data.
Product data access is scoped to authenticated users and, where applicable, an organization and explicit project context.
ErgoThrive uses PostgreSQL row-level security and organization-prefixed storage paths. HF Studio uses default-deny authorization and tested membership boundaries.
Service credentials belong in managed environment stores. Browser-exposed variables and responses must not contain service-role, payment, email, or deployment secrets.
Current applications use input validation, safe redirects, security headers, protected routes, origin controls where applicable, and restrictive cookie settings.
Known critical tenant-isolation, authorization, secret, uncontrolled data-loss, or upload/render defects are release blockers for products handling customer data.
Biosystems One does not currently claim SOC 2, ISO 27001, HIPAA, FedRAMP, or other security certification for these products.
02 / Privacy
Privacy starts with defining what each product should not receive.
Contact forms are for non-confidential inquiries. They validate and limit submitted fields, use bot controls when configured, and route messages to Biosystems One support. Sensitive or confidential records should not be submitted.
03 / Data storage
Storage statements below describe current architecture—not a promise that all products share the same backend or retention schedule.
Enterprise regional hosting, customer-managed encryption keys, and dedicated tenancy are not currently offered or implied.
04 / Encryption
05 / Browser and device processing
MotionLab opens source videos and images directly from the user’s device. Analysis, tracking, measurement, graphing, and most exports run in the browser.
06 / Authentication
The corporate website does not create product accounts. Authentication belongs to each specialized application.
07 / MFA
MFA support is product-specific and should not be inferred for the rest of the portfolio.
HF Studio supports TOTP enrollment and challenge through Supabase Auth. Organization Owners and Organization Administrators require MFA; organizations can require it for additional roles, and individuals can opt in.
HF Studio remains in invite-only closed beta. MFA implementation is not a statement that the product has completed independent commercial security validation.
08 / Compliance roadmap
No roadmap item is a current certification or guarantee of regulatory acceptance.
Input validation, secret separation, secure session patterns, tenant-aware authorization, private storage where applicable, and product-specific privacy boundaries.
Qualified domain review, application-security and accessibility review, monitoring and incident operations, backup/restore exercises, privacy/legal approval, and independent penetration testing for products handling customer data.
Evaluate SOC 2 readiness, enterprise identity, documented subprocessors and DPA materials, regional deployment needs, and customer assurance packages based on product maturity and customer demand.
Biosystems One does not claim that its products are SOC 2 certified, ISO 27001 certified, HIPAA compliant, FedRAMP authorized, FDA validated, IEC certified, or guaranteed to meet a customer’s regulatory obligations.
09 / Vulnerability reporting
Do not place vulnerability details in public issues, social media, or ordinary product screenshots.
Reports are triaged by exploitability and impact. Tenant-isolation bypass, authentication bypass, exposed credentials, remote code execution, and uncontrolled data loss receive highest priority. No bug-bounty payment or legal safe-harbor program is currently advertised.
10 / Incident response
Detailed internal procedures and evidence mature with each product’s release stage.
Confirm the signal, preserve relevant evidence, assign severity, and identify the potentially affected product and tenants.
Restrict affected access, revoke credentials or sessions, isolate unsafe paths, and prevent further exposure.
Determine scope and root cause, deploy a focused fix, and validate the security boundary and adjacent failure paths.
Notify affected parties when required by applicable obligations, restore safe operation, and provide accurate known facts without speculation.
Document the timeline and root cause, track corrective actions, and update tests, controls, runbooks, and disclosure where appropriate.
11 / System status
Biosystems One does not currently publish an automated public uptime dashboard or contractual SLA.
For access problems or a suspected service disruption, contact support and identify the affected product, approximate time, browser, and non-sensitive error details.
Ask about service status12 / Version history
Material changes to security, privacy, storage, authentication, incident, or assurance statements will be recorded here.
Trust questions
Send a non-confidential description of the product, intended use, and security or privacy requirement you are evaluating.