Solia Direct DocsControl Plane
⌘K

Security & ProductionGuide

Shared responsibility

What Solia does and what you do.

Division

  • Solia: platform isolation, authorization enforcement, credential storage, delivery and audit records.
  • Laboratory: catalog accuracy, mappings, clinical release decisions, member access, and validation of its own interfaces.
  • Partner: protecting its API keys, verifying webhook signatures, deduplicating deliveries, and handling data lawfully in its own systems.

Identifiable-data boundary

  • A partner registers subjects using its own opaque identifier. Names, dates of birth and clinical detail are not part of that reference.
  • Events and webhook deliveries carry allow-listed identifiers and coarse state only — never analyte values, demographics or report documents.
  • Report documents are retrieved per request through the governed report endpoint; no permanent or signed document URL is issued.
  • Released results are the only results exposed externally; an unreleased version is reported as pending or not found regardless of its internal state.

This documentation describes implemented platform controls. It is not a certification or regulatory attestation, and it does not replace a laboratory's own compliance program or a partner's own obligations.