A proposed GeneticSecurity.org analytical concept. These levels are not an external standard, validated risk model, or industry certification. Version 1.0 was prepared on September 19, 2026; an earlier public publication date has not been established.

Why it matters

Genetic security is not only about keeping data secret. A genomics system also has to answer:

  • Is this the correct specimen?
  • Did the sample remain associated with the correct subject?
  • Was contamination detected?
  • Which sequencer produced the data?
  • Which software version processed it?
  • Which reference genome or reference database was used?
  • Were pipeline inputs or dependencies modified?
  • Who transformed the data?
  • Is the reported result traceable back to the original sample?
  • Can unauthorized changes be detected?

GPI is therefore a chain-of-trust concept spanning the biological and digital domains.

Proposed levels

GPI-0

Unknown

No reliable provenance chain exists.

GPI-1

Partial / Manual

Some origin or handling information exists, but major stages cannot be independently verified.

GPI-2

Traceable

Major stages are documented, but integrity controls are incomplete or inconsistently enforced.

GPI-3

Controlled

Custody, processing, versions, operators, and major transformations are recorded and subject to defined controls.

GPI-4

Verified

Strong technical and procedural verification exists across sample custody and digital processing, including integrity checks, access controls, versioning, and reproducibility.

GPI-5

Cryptographically And Operationally Auditable

Where practical, critical digital artifacts are hash-verified or signed; custody and transformations are logged; software/reference versions are pinned; reproducibility is tested; and an independent reviewer can reconstruct the processing history.

The provenance chain

  1. Subject / Source
  2. Specimen Collection
  3. Labeling / Identifier
  4. Custody / Transport
  5. Sample Preparation
  6. Sequencer / Instrument
  7. Raw Output
  8. Transfer
  9. Bioinformatics Pipeline
  10. Reference Data
  11. Variant / Derived Data
  12. Interpretation
  13. Report / Decision

Controls across the chain

Physical: - tamper-evident sample packaging - chain-of-custody logs - controlled storage - unique specimen identifiers - contamination controls

Digital: - cryptographic hashes - signed manifests - immutable audit logging - role-based access - version-pinned pipelines - container digests - software bills of materials - reference-dataset versioning - reproducible workflow definitions - integrity-checked backups

Analytical: - documented thresholds - interpretation versioning - analyst identity - review/approval history - confidence and uncertainty reporting

How to use the scale

Score verifiability, not biological truth. An auditable history can still contain a mistaken interpretation. Where public evidence is insufficient, leave the level unassigned instead of treating missing documentation as a failed control.

Worked example: a matching hash answers one question

In a hypothetical workflow, a receiving team checks a file against a trusted checksum recorded at transfer. A successful comparison supports the claim that the received bytes match that recorded artifact. It does not establish that the original specimen was correctly labeled or that the analysis used an appropriate reference.

This is why provenance needs a chain of evidence. A technical check should be connected to the person or process that created the record, the artifact it describes, and the stage it verifies. An impressive collection of logs is difficult to use if no one can connect those logs to a particular result.

Review the weak connection, not the paperwork volume

For a practical exercise, choose a report and try to trace it back to its source. At each handoff, ask what establishes the association. If the answer depends on an undocumented assumption, record the gap and its possible consequences for the result.

GPI should reflect what can be reconstructed and checked. It should not reward a team merely for producing many records, nor should missing public documentation prove that internal controls are absent. An external case review and an internal operational audit have access to different evidence; their conclusions should acknowledge that difference.

Sources and provenance

The definition, levels, and scoring rationale originate in the GeneticSecurity.org implementation brief, version 1.0, dated September 19, 2026. External sources support the examples, not endorsement of this scale.

Classification methodology