SOPHiA DDM
SOPHiA DDM™ is a Software-as-a-Service platform that enables users to perform bioinformatics analysis, quality assurance, result visualization, and data storage for next-generation sequencing (NGS) runs. Users upload raw NGS data, which is transmitted to hosted IT infrastructure for processing and storage; results are then made available for visualization on platform.
Features
- Automated bioinformatics analysis
- Result visualization, and secure data storage for genomic data
- The platform supports the analysis of Next-Generation Sequencing (NGS) data
- Allows users to visualize and interpret genetic variants
- SNP/INDEL detection, gene amplification analysis, and BRCA. Service benefits
Benefits
- Accelerate confident decision-making in Oncology and Rare & Inherited Disorders
- Streamline sequencing data analysis and interpretation
- Accurate variant detection, simplified variant prioritization, and expedited reporting
- Overcome bottlenecks and increase confidence in results
- Detect challenging variants with high confidence
- Integrate analytical platform into your existing laboratory setup
- Streamline your genomics workflow
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 0 3 4 2 6 2 4 4 6 2 9 2 5 6
Contact
SOPHIA GENETICS LIMITED
Simona Sevdina
Telephone: +44 7395 594261
Email: sales_ops@sophiagenetics.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- No
- System requirements
-
- Microsoft Windows 7(64 bit) or later
- MacOSX 10.0 or later
- Microsoft Windows 10(64 bit) or later
- No additional plugins or software needed
User support
- Email or online ticketing support
- Yes
- Support response times
- SG and/or its Affiliates offers support from Monday through Friday during regular business hours (in Central European Time / Eastern Standard Time) except during banking holidays.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- SG and/or its Affiliates will use reasonable commercial efforts to resolve Customer’s request as soon as practicable. Consistent with industry standards, requests are classified based on the following priority order for internal purposes only: • P1 - Critical • P2 - High • P3 - Moderate • P4-Low The priority will drive the response frequency and resolution efforts per applicable internal guidelines.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- SOPHiA GENETICS assists users in getting started with the SOPHiA DDM™ platform by providing a sign-up process where users select "Sign-up now," enter their email address, receive a verification code, and then complete their profile with their name and a new password. Detailed instructions for accessing the platform and performing a genomic analysis request are available in the SOPHiA DDM™ Dx mode User Manual. For additional support, users can consult the troubleshooting section or contact support via phone, email, or the customer support portal.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- The customers retain full ownership of their data and can request the return or deletion of personal data at the end of processing, as outlined in the SOPHiA GENETICS Data Protection Addendum.
- End-of-contract process
- At the end of a SOPHiA GENETICS contract, customers lose access to the platform and services. SOPHiA GENETICS will delete all personal data processed on behalf of the customer or, if requested, return the data and then delete any existing copies, including anonymization as per GDPR. Until deletion or return is complete, SOPHiA GENETICS continues to ensure compliance with contractual data protection obligations.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding instructions for the SOPHiA DDM™ platform are provided through user manuals, support documents accessible directly via the platform, and email communications with links and instructions. For onboarding, users receive detailed steps for account setup and access, and support is available via email, phone, or web request from the platform dashboard.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- MacOS
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- SOPHiA GENETICS provides a service interface through the SOPHiA DDM™ platform, which is delivered in a Software-as-a-Service (SaaS) mode. Users can access the platform to launch bioinformatics analyses, visualize results, and manage data within an integrated workflow.
- Accessibility standards
- None or don’t know
- Description of accessibility
- SOPHiA DDM™ is accessible via a web application and a locally installed agent, with instructions provided for account setup and browser compatibility.
- Accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
- SophiaDDM offers a CLI client or API that can be enable under customer request
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- The bundle solution can be customised through the number of genes that are part of a panel. They can be adjusted depending of client's need, this will need to be discussed on the case by case basis and will come with cost adjustment.
Scaling
- Independence of resources
- SOPHiA GENETICS ensures that the performance and availability of the SOPHiA DDM™ platform has no negatively impacted by the demand or usage levels of other users, by leveraging Microsoft Azure's robust, scalable cloud infrastructure, which generally supports resource isolation and high availability.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The platform includes dynamic dashboards that offer real-time insights into system performance, application health, and business metrics.
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Via the SOPHiA DDM platform
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
- Other
- Other data import formats
-
- FASTQ
- BAM
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- SOPHiA DDM Platform has an SLA of 99.5% availability
- Approach to resilience
- SOPHiA GENETICS ensures datacentre resilience by hosting the SOPHiA DDM™ platform on Microsoft Azure, utilizing a hub-and-spoke architecture with paired Azure regions for disaster recovery and data replication. Customer data and compute resources are deployed in specific Azure regions, each paired with a secondary region to provide built-in disaster recovery, coordinated updates, and enhanced service continuity. Additionally, files in active storage are replicated across two data centers, with further copies held in archive and on independent file systems to ensure data preservation and availability.
- Outage reporting
- SOPHiA GENETICS informs customers of major information security incidents, including outages or service disruptions that significantly affect the availability, confidentiality, or integrity of data, without undue delay. If the incident impacts personal data, customers are notified within 48 hours to enable regulatory reporting. Notifications include the nature of the incident, affected services, initial impact assessment, and containment steps, with status updates provided until the incident is resolved.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted through strong authentication methods, including multi-factor authentication (MFA) and role-based access control (RBAC), ensuring only authorized users can access sensitive information based on their job responsibilities. User profiles and permissions are managed via Microsoft Azure Active Directory groups, with requests for additional access rights handled through a dedicated ticketing process. For support channels, access is limited to a restricted number of SOPHiA GENETICS employees, and all access is governed by strict access management procedures and the principle of least privilege.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- SOPHiA GENETICS follows a robust security framework designed to comply with regulatory requirements, including ISO 27001:2022, ISO 27017:2015, and ISO 27018:2019. The company integrates information security considerations into every phase of the software development lifecycle, ensuring security by design. Internal policies and procedures are deployed to keep customer data secure, and regular internal and external audits are conducted to verify compliance and maintain high security standards.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- SOPHiA GENETICS employs a structured change management process, including documented procedures for risk assessment, change control, and configuration management. Changes impacting critical suppliers or systems follow a Change Control Process (CCP) to ensure seamless transitions and risk mitigation. System owners document and periodically review access policies and procedures. Configuration management is supported by policies covering systems administration, vulnerability and patch management, and regular audits. The business continuity program uses the Plan-Do-Check-Act (PDCA) cycle for continuous improvement. All changes are tracked, reviewed, and approved by relevant stakeholders to maintain security and compliance.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We run static analysis of code in every pull request, and Dynamic Security testing in every release.
Systems are patched into every "releases", happening every 3 weeks.
We use JIT as source for the vulnerabilities. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We have a active monitoring of all the services integrated with our SOC provider, with 24/7 monitoring.
Critical incidents have an SLA of less than 4 hours - Incident management type
- Supplier-defined controls
- Incident management approach
- SOPHiA GENETICS employs a structured incident management approach with a dedicated Incident Response Team and 24x7 Security Operations Center. Security incidents are identified via observability and EDR tools, reported through email or ticketing, and managed by a defined workflow: identification, reporting, assignment, assessment, containment, remediation, verification, and closure. Major incidents are escalated to executive leadership and customers are notified as appropriate. All incidents are documented, with evidence retained for 10 years. Regular testing of the process is conducted, and lessons learned are incorporated into ongoing improvements. Notification timelines align with the NIS 2 directive and SEC disclosure obligations.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Same access as full mode with limited duration and number of uploads
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Tuesday 18 November 2014
- What the ISO/IEC 27001 doesn’t cover
- The Information Security Management System (ISMS) applies to the development, production and worldwide distribution of reagents and web-based services for the analysis of genetic data and medical images. The scope of the ISMS includes processes, people and facilities that manage, operate, and deliver products and services. This in accordance with the SG-04588 Statement of Applicability ISO/IEC 27001:2022 version 3.0, as of 20OCT2024.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- ISO27017
- ISO27018
- ACN (Italy)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-