One place to find every compliance artifact for AMC procurement, IT-security review, and NIH program officers.
For AMC InfoSec reviewers: every HECVAT 4.0 domain is mapped to the applicable SOC 2 Trust Service Criteria, with the section of the audit report that contains the supporting evidence.
/hecvat-crosswalk →For federal and NIH program officers, and IT-security teams: Baseshift implementation references for each NIST SP 800-53 control family relevant to clinical genomic data processing.
/nist-mapping →For AMC procurement and contracting teams: a pre-publishable DUA addendum template covering permitted use, prohibited re-identification, breach notification, and termination clauses.
/sales/dua-addendum →