Trust & security

Security, compliance and data residency — built into the platform.

CosmicIris handles protected health information for iridology and sclerology clinics worldwide. Security isn't a settings page bolted on afterward — it's the shape of the deployment: identity-based access, per-continent data residency, and passwordless authentication from the database to the clinician. It is built and maintained by a team with 15+ years of experience in both technology and security.

Standards

The standards clinics are held to — covered out of the box.

CosmicIris is designed around the medical-data standards iridology and naturopathic practitioners answer to — HIPAA in the US, GDPR across the EU — with our infrastructure controls undergoing a SOC 2 Type II audit.

HIPAA compliant ● Compliant
HIPAA

Protected health information handled to US healthcare standards.

GDPR compliant ● Compliant
GDPR

EU data-protection rights, processing records and residency.

SOC 2 — In progress ○ In progress
SOC 2

Type II controls audit underway for the CosmicIris platform, built on Google Cloud’s compliant infrastructure.

Data residency

Your clinical data stays on its home continent.

CosmicIris runs a separate database in each region. A clinic's records are served from — and stored in — the continent it belongs to, never pooled into a single global store.

Multi-region
Europe

EU clinics are served from and stored inside the EU, across multiple European regions.

Multi-region
Americas

US and Americas clinics are served from and stored in the United States, across multiple US regions.

Singapore
Asia-Pacific

APAC clinics are served from and stored in Singapore.

Identity-based access

No passwords to steal — anywhere in the stack.

From the database connection to the clinician's login, CosmicIris replaces shared secrets with verified identity using OpenID Connect (OIDC). Credentials that don't exist can't be leaked.

Application service
workload identity
OIDC token
short-lived · scoped
Regional database
verifies · no password
OIDC
Passwordless database access

Each service authenticates to its regional database with short-lived OpenID Connect (OIDC) tokens issued to its cloud workload identity. No database password is ever stored in code, baked into an image, or sent over the wire, so there is nothing to leak, rotate by hand, or steal.

ZERO-TRUST
Verified service-to-service calls

Internal workers — like the image-processing pipeline — expose no public endpoint. They accept a request only when it carries a valid OIDC identity token authorized by IAM, so background jobs run on proven identity rather than a shared secret.

MAGIC LINK
Passwordless sign-in

Practitioners sign in through one-time magic links sent to their verified email. There are no user passwords to phish, reuse, or breach — and access can be revoked per account at any time.

Infrastructure

A hardened deployment, end to end.

The platform is engineered so that the secure path is the only path — private networking, runtime secrets, and encryption are defaults, not options.

Built on Google Cloud

The site, app and services run on Google Cloud’s managed infrastructure, behind a global HTTPS load balancer and CDN.

Encrypted in transit & at rest

All traffic is served over TLS; live collaboration runs over secure WebSockets (wss). Data is encrypted at rest by default on Google Cloud.

Private networking

Service instances have no external IP. Egress is routed through a private VPC and Cloud NAT, keeping the database reachable only over Google’s private network.

Secrets never in source

Credentials and connection strings resolve from Google Secret Manager at runtime — they are never committed to the codebase or container images.

Multi-region resilience

Services run in three continents; the load balancer routes each clinic to its nearest healthy region for low latency and redundancy.

Point-in-time rollback

The site bucket uses object versioning, so any deploy can be restored to a previous known-good state within minutes.

Security or procurement question?

We're happy to walk security and compliance teams through our architecture, residency and data-handling in detail — and to share our full privacy policy and terms of use on request.

Contact our team

Bring the oldest science of the eye into the next decade of medicine.

Start free, in any of 10+ launch languages.

Start free Book a demo →

30-day free trial. No credit card required.