Security & Privacy
Lifebit Trust Center
At Lifebit, we secure the information of more than 270M patient data worldwide with security-by-design and 24/7 support
Lifebit Assurance package
We’ve created a comprehensive package that details the security information and documentation you want to know most, all in one place.
To see which documentation is included, get started by opening the form below.
Go the extra mile to safeguard sensitive health data and enable secure, compliant research with Lifebit TRE Essentials
Lifebit’s TRE Essentials package enhances security, governance, and auditability across your data estate. Built around the Five Safes Framework and aligned to IL-compliant standards, it ensures your researchers can access sensitive data securely—without compromising compliance or control.
Included in TRE Essentials:
Federated access controls with full workspace isolation
Airlock security gateway for data ingress and egress review
Firewall & tenant-level policy enforcement
Role-based access with SSO integration and audit trail visibility
Lifebit enables organizations to federate everything and move nothing, maintaining total control over their data while enabling secure collaboration across agencies and research partners.
Security is in our DNA
We are committed to keeping our customers’ data secure by aligning with the strictest security measures available on the market, so you can stay assured that your data is kept safe.
Privacy is more than just a policy
Our privacy program is not about long docs and fancy words, nor is it for mere legal compliance. It’s about genuinely caring about your privacy and doing right by you and your data.
Transparency is key
Transparency is the guiding force behind our security and privacy principles. We share selected policies with our customers, so that you always know how we’re keeping your information secure.
What’s new on Lifebit security
10 Best Practices for Building Trusted Research Environments
Trusted Research Environments (TREs) are critical to secure, compliant, and scalable research in healthcare and life sciences. To support your organization in designing or procuring a best-in-class TRE, we’ve developed this resource outlining the top 10 best practices, informed by real-world deployments across national health systems. These insights provide practical guidance and reference Lifebit’s proven frameworks for building robust, future-proof, federated research platforms.
Compliance & Certifications
Lifebit follows strict international standards and regulations in order to keep your data safe

FedRAMP a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by the U.S. federal government

ISO/IEC 27001 the globally recognized standard for information security management systems (ISMS)

ISO 9001 the international standard for quality management systems (QMS)

G-Cloud 13 is a UK Government framework that enables public sector bodies to procure cloud solutions that meet strict compliance requirements.

SOC 2 Type II verifies that our systems and processes meet high standards for security, availability, and confidentiality over time.

HIPAA establishes standards to protect sensitive health information and ensure the privacy and security of electronic health data in the U.S.

The General Data Protection Regulation (GDPR) sets guidelines for the lawful handling of personal data for organizations operating in the EU.

EHDEN certification confirms alignment with FAIR principles and readiness to support standardised health data infrastructure in Europe.

Cyber Essentials Plus is a UK Government-backed certification that validates protection against common internet-based threats.

AWS Advanced Consulting Partner status recognizes expertise in building secure, scalable cloud solutions on Amazon Web Services.

Microsoft Azure is a secure and compliant cloud platform used to deliver enterprise-grade infrastructure and services.

The NHS Data Security and Protection Toolkit (DSPT) ensures compliance with national data protection standards for health and care providers.

Google Cloud provides a secure, scalable platform for running privacy-focused, high-performance data solutions.
Frequently asked questions
How does Lifebit ensure compliance with federal security standards like IL4, FedRAMP, and HIPAA?
Lifebit’s Trusted Research Environment (TRE) is deployed within AWS GovCloud (US) and architected to meet IL4/NIST 800-53, HIPAA, and FedRAMP High control baselines. Our infrastructure-as-code deployment model allows for rapid ATO alignment and auditability. All data remains within the customer’s environment, ensuring zero data movement and full compliance with agency-specific governance policies.
What security frameworks and certifications does Lifebit follow?
Lifebit adheres to globally recognized security standards including ISO/IEC 27001, Cyber Essentials Plus, and SOC 2-aligned controls. Our Trust Center offers visibility into our policies, audit status, vulnerability disclosures, data encryption practices, and ongoing penetration testing schedules. All security documentation is centralized and accessible via our Trust Center.
How does Lifebit protect sensitive health data in federated environments?
Lifebit uses a zero data movement model: data stays within the originating organization’s secure boundary, while computation and analysis are federated across participating entities. We implement multi-layered security—including role-based access controls, encryption at rest and in transit, Airlock, and workspace-level isolation—to ensure complete data confidentiality and integrity.
What is a Trusted Research Environment (TRE)?
A Trusted Research Environment (TRE) is a secure digital workspace that allows approved researchers to access and analyze sensitive data — such as health or genomic information — without moving or downloading it. TREs are designed to meet strict privacy, security, and compliance standards by ensuring safe data access, secure user authentication, and auditable research workflows. Commonly used in healthcare and life sciences, TREs protect patient data while enabling high-impact research.
Which Lifebit plans support OMOP data harmonization?
OMOP Data ETLs start in the Scale plan.
Enterprise expands this with AI-powered OMOP mapping, cleaning, and full federated data network capabilities.
The Start and Launch plans do not include OMOP support.
Can Lifebit support on-premise deployment or hybrid cloud environments?
Yes. Lifebit’s Enterprise plan supports fully customizable deployment models, including on-premise, hybrid cloud, and multi-cloud setups. This includes VDI, firewall services, and advanced billing infrastructure designed for pharma and national programs.
What is included in Lifebit’s Trusted Research Environment (TRE)?
Every Lifebit TRE includes:
Airlock (controlled data export)
Firewall (role-based access and VDI)
Federation (run analysis where data lives)
From Launch upward, TRE tools are built-in. Enterprise clients also receive tokenization, EHR connectors, and audit controls.
What is a Workspace?
A workspace in Lifebit is a secure, permission-controlled environment where users can access, analyze, and manage sensitive data without moving it. It supports safe collaboration, workflow execution, and cohort analysis — all within a compliant Trusted Research Environment (TRE).
Each workspace can be dedicated to an internal team or an external organization, housing all of its users and data access configurations in one isolated space. This makes it ideal for federated research, multi-institution collaborations, or partner onboarding at scale.
Are Lifebit the only truly Federated platform?
Yes — Lifebit is the only platform that offers true federated analytics across any data, cloud, or geography without ever moving the data.
Unlike most SaaS platforms that require you to centralize data in their environment, Lifebit’s patented federated architecture lets you run analyses directly where the data resides — whether it’s on-premise, in your own cloud, or across multiple sites.
Other platforms might offer “controlled access,” but still require data or compute to be moved into their system. Lifebit enables secure, in-situ computation and analytics — without compromising sovereignty, compliance, or performance.