Standard · v1.0 · current

GA4GH Genetic Data Encryption

Maintained by GA4GH Data Security Work Stream

What it helps you do

Crypt4GH supports an encrypted genomic file format using envelope encryption and recipient keys while retaining random access to protected data.

  • Omics
  • Clinical
  • Bioinformatics
PlanAcquireHarmonizeExchangeLearn + reuse

01

Where it fits and where it does not

Use these four checks before committing implementation time.

Use it when
Sensitive genomic files that must remain encrypted during storage, transfer, and analysis workflows without always decrypting the entire object.
Limits
Crypt4GH does not manage identity, consent, authorization decisions, key custody, revocation, or audit policy. Authorized users can still create unencrypted copies after decryption.
Best for
Omics and Clinical and Bioinformatics teams working across Acquire → Exchange → Learn + reuse.
Maturity
ScalingUsable now, but adoption or tooling is still developing. Pilot the exact stack first.

02

See it in the workflow

This view shows the input, the change the standard introduces, and the resulting output.

  1. InputWhat starts

    Omics and Clinical and Bioinformatics source data, metadata, and local mappings

  2. Crypt4GHWhat changes

    Use Crypt4GH as a pinned standard across Acquire → Exchange → Learn + reuse

  3. OutputWhat becomes possible

    A handoff the next system or team can validate against the same release

Readiness gateCrypt4GH does not manage identity, consent, authorization decisions, key custody, revocation, or audit policy. Authorized users can still create unencrypted copies after decryption.

03

A concrete example

Encrypt each governed asset for authorized recipient keys, preserve provenance and checksums, control header and recipient updates, test random-access decryption, and audit every decrypted derivative.

Why it matters: Supports secure compute-to-data and controlled model pipelines, but encryption is not evidence of lawful use, privacy protection after decryption, or dataset suitability.

04

What it fits with

Can protect BAM, CRAM, VCF, and other genomic assets; DRS can identify protected objects and htsget can provide authorized retrieval, while identity, policy, and key services remain external.

05

Implementation starter

Start with one bounded handoff. Pin, test, and review it before scaling.

  1. Define one handoff, its accountable owner, and the decision Crypt4GH must support.

  2. Pin the exact version and companion artifacts: v1.0 · current.

  3. Map one representative input to the required standard artifacts.

  4. Test the result against the canonical source and record every exception.

  5. Preserve the source data, mappings, and review evidence before scaling.

06

Test the main limitation

Risk

Crypt4GH does not manage identity, consent, authorization decisions, key custody, revocation, or audit policy. Authorized users can still create unencrypted copies after decryption.

Test

Run one representative end-to-end pilot and record exactly where Crypt4GH loses context, needs an extension, or depends on another standard.

Risk

Machine-readable output may still be unfit for analysis or ML.

Test

Test the output for missing context, provenance, terminology alignment, time leakage, and the intended downstream decision. Supports secure compute-to-data and controlled model pipelines, but encryption is not evidence of lawful use, privacy protection after decryption, or dataset suitability.

07

Official resources

Specifications, diagrams, examples, and guides from the organizations that maintain them.

  • Primary sourcev1.0 · current

    GA4GH Crypt4GH product

    Official publisher or steward guidance for this standard profile.

    Publisher
    GA4GH Data Security Work Stream
    Open official source

Next action

Put this profile in context

Compare its role with adjacent standards or place it inside an end-to-end data pathway before choosing an implementation.