Security – The BioChain
Security & Trust

Security built by an engineer, not a checklist.

The BioChain's security posture is led by John Henderson, our CTO and an experienced network security engineer — not outsourced to a template. We don't apply one fixed security profile to every deployment; we design it around what each organisation actually needs to protect.

Led By an Engineer

Security is architecture, not an afterthought.

John Henderson, The BioChain's CTO, is a security-cleared, experienced network security engineer. He leads our infrastructure and technology decisions directly — security isn't a policy document bolted on afterwards, it's built into how our systems are designed from the start.

We run our own virtual servers rather than handing that responsibility to a shared, third-party platform we don't control. That means we're directly accountable for how our environments are configured, patched, monitored and isolated from one another.

Tailored, Not Templated

Your security profile is based on your needs.

We start with what you're protecting
A research dataset, a regulated supply-chain record and a clinical sample don't carry the same risk profile. Rather than applying one fixed security configuration to every engagement, we architect access controls, encryption and isolation around what your specific data actually requires — and around your own existing infrastructure and governance, not just ours. Where an organisation already has systems and controls in place, we design to work within them rather than asking you to route everything through a new environment.
Controlled, not indiscriminate, linkage
The infrastructure we build is designed to separate the existence of a relationship between records from permission to resolve it — so connecting data across systems doesn't mean exposing everything to everyone who can see part of it.
Where We Are Honest

We are not yet formally certified.

We have not yet completed a formal third-party security certification such as SOC 2, ISO 27001 or Cyber Essentials. That's a genuine gap, not a hidden one. As the platform matures, working towards recognised certification is on our roadmap — not a claim we're making today.

If formal compliance evidence is a hard requirement for your organisation right now, tell us directly and we'll have that conversation honestly. Our Advisory team can also help you understand what your own systems would need to show a regulator or auditor, independent of anything we build.

Report a Concern

Found a security issue?

If you believe you've found a security vulnerability in our systems, please email info@thebiochain.com with details. We'll acknowledge reports as quickly as we can and treat them seriously.