For: both sides.
Security and data
Where things live
| Held by | |
|---|---|
| Identity of the customer for results | Atlas |
| Laboratory data, sequence files, reports | Atlas |
| Result content shown in the surface | Atlas, rendered in your app |
| App accounts, engagement, uploads | You |
Atlas never sends raw laboratory data to a partner's systems. Partners never hold an Atlas key in a client.
In the client
No API key, no token minting, no user mapping. The surface runs its own sign-in.
Embedding
The surface sets a content-security policy that allows framing only from your registered domains. Everything else on Atlas refuses to be framed.
Data protection
Atlas is the controller for laboratory and result data and processes it in the EU. Consent is captured at order and recorded on the order. Customers can request access, correction and deletion through Atlas; Atlas informs you when an order is cancelled so your app can reflect it.
Medical pathway
Layers that constitute a genetic examination for a medical purpose are ordered and communicated by a physician, as German law requires. Atlas builds this into the product so that partners in any market get the same release logic.
Markets
Shipping and analysis are available for the EU and the United Kingdom. Additional markets are assessed individually for legal, data-protection and logistics requirements before go-live.