Trust Center
Security, privacy and compliance
Bio6 encrypts protected health information (PHI) at rest (AES-256) and in transit (TLS 1.3), segregates clinical attachments from public assets across two storage stores, redacts PHI from logs, and documents every cross-border transfer under Loi 25 art. 17.
Privacy Officer (Personne responsable de la protection des renseignements personnels)
Per Loi 25 art. 8 and the public-disclosure requirement of art. 3.1, Bio6 designates:
- Name
- John-Frederick Davidson
- Title
- Privacy Officer (RPRP)
- Privacy@bio6health.com
- Access & rectification requests (DSAR)
- Privacy@bio6health.com
- Mailing address
- [mailing address — to be added]
Restricted
Detailed security & compliance documentation
Our full Trust Center — the sub-processor register, data-residency and cross-border transfer details, encryption architecture, certification status, and audit artifacts — contains sensitive infrastructure and compliance information. We share it with qualified parties (prospective clinics, procurement teams, and privacy counsel) under NDA rather than publishing it openly.
Available on request
- Sub-processor register — vendors, processing regions, DPA / BAA status
- Data residency & cross-border transfer disclosures (Loi 25 art. 17)
- Encryption & data-architecture summary
- Certification & attestation status with target dates
- Audit artifacts — MSSS crosswalk, CyberSecure Canada, SOC 2 readiness
Request access
Tell us who you are and we'll share the detailed documentation under NDA.
Please include your organization and role. Verified clinic, procurement, and counsel contacts are prioritized.
Vulnerability disclosure
Bio6 welcomes responsible vulnerability reports. Researchers who follow our policy are covered by safe-harbor.
Public bug-bounty program coming Q3 2026.
- Last refreshed
- 12 July 2026
- Procurement contact
- security@bio6health.com