Enterprise Privacy Policy
This Privacy Policy governs the collection, utilization, and architectural protection of technical telemetry by Genix BaseScale™, an enterprise genomics FinOps and compute orchestration middleware owned and operated by Radiome Health Private Limited ("Radiome Health", "we", "us", or "our").
1. The HIPAA § 164.312 Zero-Payload Commitment
Unlike traditional cloud APM or monitoring tools, Genix BaseScale does not collect, inspect, store, or transmit raw genomic sequences or Protected Health Information (PHI).
Our eBPF kernel agent operates at the Linux OS layer (cgroup v2 and kernel scheduler tracepoints). The software architecture strictly prevents reads from biological data formats, including but not limited to:
- • FASTQ / .fq
- • BAM / CRAM
- • VCF / BCF
- • Clinical EHR / PHI
Kernel probes are cryptographically gated. Any byte stream matching raw biological ASCII/binary sequences is architecturally dropped at the kernel boundary before socket egress.
2. Categories of Information We Process
To compute container right-sizing recommendations, spot pre-warming wave triggers, and FinOps audit savings, BaseScale collects strictly non-PHI machine telemetry:
ALIGN_STAR, HAPLOTYPE_CALLER), task attempt indices, container image digests, and process return codes. 3. Purpose of Processing Telemetry Data
Radiome Health Private Limited processes technical telemetry strictly for legitimate enterprise infrastructure objectives:
- Automated Right-Sizing: Calculating P95 actual memory utilization plus 25% safety headroom buffer to eliminate overprovisioned container RAM costs.
- Predictive Node Pre-Warming: Analyzing DAG task dependencies to pre-spin Spot instance pools T-120 seconds in advance, eliminating cold-start queuing delay.
- Preemption Checkpointing: Orchestrating memory snapshots to customer-controlled S3/GCS buckets when Spot evictions are intercepted.
- Immutable SOC 2 Audit Chaining: Creating SHA-256 cryptographic audit blocks recording all provisioning adjustments.
4. Cryptographic Wire Security (mTLS 1.3)
All telemetry flowing between worker node agents and the centralized FinOps control plane is encrypted in transit using pure-Rust hardware-accelerated mTLS 1.3 with ephemeral X.509 certificates.
Telemetry is framed using our proprietary binary codec (GENX) with fixed 10-byte packet headers. Any attempt to pass unauthorized payloads triggers immediate connection termination and an automated security audit alert.
5. Multi-Tenant Isolation & Sovereign Clouds
Radiome Health enforces strict multi-tenant isolation. Telemetry is partitioned by customer tenant ID and encrypted at rest with customer-managed AWS KMS keys (SSE-KMS) or Cloud KMS keys. Customers may configure on-premises control plane deployments or VPC-peered private links (AWS PrivateLink) where telemetry never touches the public internet.
6. HIPAA Compliance & Business Associate Agreements (BAA)
While BaseScale's architecture does not access or store PHI, Radiome Health Private Limited routinely executes standard HIPAA Business Associate Agreements (BAA) with enterprise biopharma, clinical genomics diagnostics labs, and academic medical centers to formalize technical safeguards under 45 CFR § 164.312.
7. Data Protection Officer & Corporate Entity
For questions, data subject requests under GDPR/CCPA, or BAA execution, contact: