Questions asked on every demo call, answered in one place.
Baseshift is deployed on Render backed by AWS us-east-1 and us-west-2. All data at rest (Postgres metadata, R2 object storage for BAM/CRAM files, and application logs) stays within AWS US regions. No data is written to EU or APAC regions.
Baseshift is not FedRAMP authorized. For programs that require FedRAMP, we can discuss a FISMA-low posture conversation and point to Render’s and AWS’s existing ATOs, which satisfy many AMC procurement committees when paired with the institution’s own controls overlay.
Common NIH-funded procurements accept AWS SOC 2 Type II (available under NDA from sales@baseshift.io) with the institution’s own risk acceptance for cloud-hosted de-identified genomic data.
The institution is responsible for de-identifying uploads per HIPAA §164.514 before submission. This means removing or replacing: names, dates of birth, MRNs, SSNs, geographic data smaller than state, and any other 18-category Safe Harbor identifiers from VCF headers, BAM/CRAM RG tags, and filenames.
After de-identification, Baseshift’s AI annotation pipeline transmits only variant coordinates (chr:pos), ref/alt alleles, gene symbols, and computed annotation fields — no patient identifiers of any kind enter or leave the de-identified dataset within Baseshift systems.
A Business Associate Agreement is available on request. The Genomic Data Use Agreement Addendum (template) commits to 72-hour breach notification, written subprocessor disclosure, and 90-day post-delivery retention with secure deletion on request. Email sales@baseshift.io for a BAA.
Baseshift supports NIH GDS-compatible workflows. The NIH GDS Policy requires institutions (not vendors) to act as data steward and submit consented data to controlled-access repositories like dbGaP or AnVIL. Baseshift fits into the “data preparation” step: you run annotation and classification on de-identified data through Baseshift, then the institution submits the consented dataset to dbGaP/AnVIL as the GDS Policy requires.
Baseshift does not submit data to dbGaP or AnVIL on your behalf — that remains the institution’s obligation. What we provide: a SOC 2-aligned annotation platform, a signed BAA, and a DUA addendum that satisfies most IRB and GDS data-flow documentation requirements.
For programs under an NIH Institutional Certification, our DUA addendum (template) can be adapted to reference your IC number and data-sharing plan.
The Baseshift BAA includes the following key terms:
Breach notification: 72-hour notification to the covered entity following discovery of a breach of unsecured PHI, consistent with HIPAA §164.410.
Subprocessor disclosure: Written list of named subprocessors provided at execution and updated annually or on change. Current subprocessors: AWS/Render (hosting), Neon Postgres (metadata), Cloudflare R2 via Polsia proxy (BAM/CRAM storage), Polsia AI proxy (variant annotation), Stripe (payments), Polsia Email proxy (notifications).
Retention and deletion: 90-day post-delivery retention of PHI-adjacent data, followed by cryptographic secure deletion. Written deletion confirmation available on request.
The full template is at Genomic DUA Addendum. To execute a BAA, email sales@baseshift.io.
Data return: At engagement close, client data (VCF files, annotated variant JSON, and clinical PDF reports) is returned in original format via secure download link. We do not convert or reformat your data.
Retention window: Data is held for 90 days post-delivery, then deleted with cryptographic secure deletion (AES-256 key destruction + disk overwrite). Written confirmation of deletion is available on request.
No lock-in: There is no minimum engagement term. The 30-day pilot and any subsequent quarterly engagement can be terminated with 30 days’ written notice. Your annotation outputs belong to you.
These terms are codified in the DUA Addendum. For a custom exit clause or a data-destruction certificate requirement, email sales@baseshift.io.
For institutional pilots (10+ samples) and NIH-program rollouts, Baseshift requires the following before first upload:
1. IRB documentation: An IRB approval letter or exemption determination covering the use of de-identified genomic data through a cloud-based annotation platform. Most institutions have a standing exemption for de-identified secondary research data under 45 CFR 46.104(d)(4).
2. Executed DUA Addendum: The Genomic Data Use Agreement Addendum (template) signed by an authorized institutional signatory. This covers data handling, subprocessors, breach notification, and deletion terms.
3. Sample-transfer SOP: A brief agreed-upon protocol covering de-identification steps, file naming conventions, and point-of-contact. This is finalized on the kickoff call with your dedicated onboarding engineer.
Single-sample exploratory uploads (the 5-sample free pilot) do not require IRB documentation — those are intended for feasibility review only, using publicly shareable or synthetic data.
Free 30-day pilot: No contract, no credit card. Upload up to 5 samples to evaluate annotation accuracy, report format, and pipeline speed against your internal pipeline. A dedicated onboarding engineer is assigned for institutional pilots (10+ samples) with a signed BAA + DUA before first upload.
Accuracy wrap-up: At the end of the pilot, we compare Baseshift ACMG verdicts and gnomAD frequencies against your lab’s internal calls and discuss any discrepancies. See the full scope at 30-Day Pilot.
Paid engagement: Quarterly billing, per-sample pricing ($15/exome, $40/WGS). No annual commitment required. The same onboarding engineer continues through the first paid quarter.
Launch promo: If the 100-sample launch promotion is still active, the first 100 samples are automatically billed at 50% off ($7.50/exome, $20/WGS) — applies to pilot graduates without requiring a promo code.
Questions about institutional volume pricing or multi-program discounts: sales@baseshift.io.
Baseshift’s current named subprocessors, updated as of 2026:
AWS / Render — application hosting and compute (us-east-1, us-west-2). Render SOC 2 Type II; AWS SOC 2 / ISO 27001.
Neon (Postgres) — relational metadata storage (variant records, upload state, user accounts). Neon is AWS-backed, US regions.
Cloudflare R2 via Polsia proxy — BAM/CRAM binary file object storage. R2 stores data at rest with AES-256 encryption.
Polsia AI proxy — variant annotation inference (OpenAI-compatible endpoint). Only variant coordinates, alleles, and gene symbols are transmitted — no patient identifiers.
Stripe — payment processing. Stripe does not receive genomic data; it handles only payment metadata.
Polsia Email proxy — transactional email (report-ready notifications, welcome emails). Email contains upload status only, no variant data.
The written subprocessor list is updated annually and on material change per the DUA Addendum. To receive the current signed list, email sales@baseshift.io.
Notification: Baseshift will notify the covered entity within 72 hours of discovery of a breach of unsecured PHI or PHI-adjacent data, consistent with HIPAA §164.410 and the executed DUA Addendum.
Named security contact: A named security point-of-contact is designated at contract execution and reachable at sales@baseshift.io for incident escalation.
Written incident report: A written post-incident report covering scope, affected data, timeline, root cause, and remediation steps is provided within 30 days of breach resolution.
Immediate mitigation: On discovery, affected data paths are isolated, credentials are rotated, and a containment summary is sent to the covered entity within 24 hours alongside the 72-hour formal notification.
For security inquiries outside of an active incident, email sales@baseshift.io.
Audit log retention: Application-level audit logs (API access, upload events, report generation, authentication) are retained for 12 months. Logs are available to the institution on written request for compliance review or incident investigation.
Institution access: Your institution can request a log extract for your organization’s uploads and events at any time by emailing sales@baseshift.io. Logs are provided in JSON format.
Law enforcement requests: Baseshift requires a valid legal process (subpoena, court order, or warrant) before disclosing any data to law enforcement or government agencies. Absent a legal prohibition, Baseshift will notify the affected institution promptly upon receipt of such a request, consistent with the DUA Addendum terms.
Third-party access: No data is sold, licensed, or disclosed to third parties for commercial purposes. Subprocessor access is limited to what is necessary to operate the service, as documented in the subprocessor list.