Trust Center

Security, privacy and compliance

Bio6 encrypts protected health information (PHI) at rest (AES-256) and in transit (TLS 1.3), segregates clinical attachments from public assets across two storage stores, redacts PHI from logs, and documents every cross-border transfer under Loi 25 art. 17.

Privacy Officer (Personne responsable de la protection des renseignements personnels)

Per Loi 25 art. 8 and the public-disclosure requirement of art. 3.1, Bio6 designates:

Name
John-Frederick Davidson
Title
Privacy Officer (RPRP)
Email
Privacy@bio6health.com
Access & rectification requests (DSAR)
Privacy@bio6health.com
Mailing address
[mailing address — to be added]

Restricted

Detailed security & compliance documentation

Our full Trust Center — the sub-processor register, data-residency and cross-border transfer details, encryption architecture, certification status, and audit artifacts — contains sensitive infrastructure and compliance information. We share it with qualified parties (prospective clinics, procurement teams, and privacy counsel) under NDA rather than publishing it openly.

Available on request

  • Sub-processor register — vendors, processing regions, DPA / BAA status
  • Data residency & cross-border transfer disclosures (Loi 25 art. 17)
  • Encryption & data-architecture summary
  • Certification & attestation status with target dates
  • Audit artifacts — MSSS crosswalk, CyberSecure Canada, SOC 2 readiness

Request access

Tell us who you are and we'll share the detailed documentation under NDA.

Please include your organization and role. Verified clinic, procurement, and counsel contacts are prioritized.

By submitting, you agree we may contact you about your request.

Vulnerability disclosure

Bio6 welcomes responsible vulnerability reports. Researchers who follow our policy are covered by safe-harbor.

Public bug-bounty program coming Q3 2026.

Last refreshed
12 July 2026
Procurement contact
security@bio6health.com