Trust and security
Last updated: July 2026
BioCoda holds evidence that organisations rely on for a 30-year obligation, so it is built to be trustworthy from the ground up. This page summarises how we protect your data. For the full security overview or a Data Processing Agreement, contact misi@biocoda.uk.
Where your data lives
Our primary datastore is a managed PostgreSQL database in the United Kingdom (London). Data is encrypted in transit (Transport Layer Security) and at rest, and the database is backed up with point-in-time recovery.
Separation between organisations
Every organisation's data is isolated in the database by Row-Level Security. The application connects with a least-privilege role that cannot bypass that isolation, so one organisation can never see another's data, even in the unlikely event of an application fault.
Who can get in
- Invite-only. There is no self-registration. Access is granted only to people an administrator has provisioned, and their organisation and role are fixed to their account.
- Single sign-on with Google and Microsoft, as well as email and password.
- Password users must set a new password at first login, and can reset it themselves.
- Administrative keys are held server-side only and never exposed to the browser.
Our providers
We keep our supply chain small and reputable: Supabase (UK-hosted database and sign-in), Vercel (application hosting), Brevo (transactional email), Cloudflare (domain), and Web3Forms (enquiry form). Each operates under a Data Processing Agreement with appropriate transfer safeguards. A full sub-processor list is available on request.
Data protection
BioCoda is provided by Astragrid Technologies Ltd, registered with the Information Commissioner's Office (registration ZB992067). We process the minimum personal data needed to run the service, and never sell it. Read our privacy policy for the detail, and our terms of use and accessibility statement.
Responsible disclosure
If you believe you have found a security issue, please tell us at misi@biocoda.uk so we can address it. We appreciate reports made in good faith and will work with you on a fix.
Certifications
Astragrid Technologies Ltd is Cyber Essentials certified across the whole organisation, under the United Kingdom government-backed scheme assessed by IASME (certificate 18afe630-9161-49f6-999e-e0f287b70f27, certified 3 December 2025, recertification due 3 December 2026). We can provide the certificate on request, and are happy to discuss our security roadmap with your team.