A proposed GeneticSecurity.org analytical concept. These levels are not an external standard, validated risk model, or industry certification. Version 1.0 was prepared on September 19, 2026; an earlier public publication date has not been established.

Why it matters

Traditional security commonly assumes that compromised credentials can be changed. Passwords can be rotated. Tokens can be revoked. Credit cards can be replaced.

A genome is different.

An individual's inherited genome is substantially persistent across life. Genetic relationships also persist. A leaked genotype may therefore retain identity, kinship, ancestry, or inference value far beyond the normal life of a conventional credential.

GPR measures the durability of the security consequence, not merely the sensitivity of the original dataset.

Proposed levels

GPR-0

Ephemeral

The exposed genetic-related information has little durable value or is readily superseded.

GPR-1

Short-Lived Derivative

The information is derived from genetics but is likely to lose practical value quickly or is weakly identifying.

GPR-2

Durable Derivative

The information is persistently useful but does not itself constitute a high-fidelity genetic identifier.

Examples: - A stable ancestry assignment. - A long-lived derived genetic trait report.

GPR-3

Persistent Genetic Profile

The exposed data contains genetic markers useful for identification, kinship, or repeated future comparison.

Examples: - SNP profile. - forensic genotype. - consumer raw genotype file.

GPR-4

High-Fidelity Genomic Data

The exposed asset contains broad genomic information with long-term analytical reuse potential.

Examples: - whole-genome sequence; - high-coverage sequence dataset; - rich variant dataset with substantial identity and health inference potential.

GPR-5

Persistent + Network Amplified

The exposed genetic asset is both highly persistent and connected to relatives, populations, longitudinal records, or other datasets in ways that can repeatedly create new inferences over time.

Examples: - a rich genomic dataset permanently linked to identity and family relationships; - a genomic profile connected to a genealogy graph and demographic records; - a strategic breeding-genetics dataset whose value persists across generations.

Assessment questions

For every case: 1. Can the underlying biological identifier be changed? 2. Can the leaked data be meaningfully revoked? 3. Could future analytical advances extract more information from the same old data? 4. Does the asset retain kinship or identification value over decades? 5. Can the asset be repeatedly linked to future datasets? 6. Does the asset affect descendants, relatives, pedigrees, or breeding lines?

How to use the scale

Score the information actually present, not the size of the database. A trait report, identifying genotype, and whole-genome dataset have different reuse potential. Not every disclosure warrants GPR-5.

Worked example: access can end while information persists

Imagine that a service closes an exposed download link. That action can stop future retrieval from the service, but it does not establish whether someone already kept a copy. The access problem and the continued usefulness of the information are separate questions.

Next ask what the copy contains. A limited derived report may support fewer future uses than a detailed identifying profile. The assessment should follow those contents, not assume that every file associated with genetics has the same lasting value. If retention or content is unknown, say so before assigning a level.

Persistence is not a prediction of inevitable harm

A durable asset may remain useful for later analysis without anyone actually performing that analysis. GPR describes the possibility of a continuing security consequence; it does not forecast who will exploit it, when, or with what result. Those claims require additional evidence.

This distinction also leaves room for meaningful controls. Restricting access, limiting unnecessary copies, and documenting retention can still matter even when the underlying biological source cannot be replaced. The aim is to reduce opportunities for misuse and preserve accountable handling, rather than promising that inherited information can be made new after a disclosure.

Sources and provenance

The definition, levels, and scoring rationale originate in the GeneticSecurity.org implementation brief, version 1.0, dated September 19, 2026. External sources support the examples, not endorsement of this scale.

Classification methodology