SOPHiA GENETICS
Cloud native genomics analysis company (NASDAQ: SOPH). The SOPHiA DDM platform applies machine learning with patented algorithms to call, annotate, and pre classify variants from next generation sequencing data, technology agnostic across sequencing instruments, with genomics, radiomics, and multimodal analytics modules. Deployed as software that hospitals and labs run themselves: at Mount Sinai, for example, SOPHiA provides the analytical software while the health system runs it as a laboratory developed test in its own CLIA certified, CAP accredited lab.
The platform reports a network of more than 750 hospitals, academic centers, and labs and a federated learning model across participating institutions. Certain applications are research use only and regional clearance varies.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
The product is the AI: SOPHiA DDM uses machine learning with patented algorithms to call, annotate, and pre classify genomic variants from raw sequencing data, distinguishing clinically relevant alterations from sequencing noise. Analysis is the deliverable.
A real external control exists because of how the product is deployed, and the internal design is undescribed.
The control is the customer's own laboratory. This platform is analytical software that institutions run themselves, and where it is used clinically the result is issued by that institution's accredited laboratory under its own quality system and signed out by its own director. In at least one health system the platform is the analytical component of a test that laboratory validated and owns. Responsibility therefore sits with a qualified professional employed by the customer, which is a stronger arrangement than a vendor issuing results directly.
What is not described is what that professional is working from. The platform calls, annotates and pre classifies variants, and pre classification is a filtering decision: it determines which of many thousands of variants reach a scientist's attention and in what order. A variant deprioritised before review is not reviewed, and its absence leaves no trace in the report. Nothing published states what the pre classification excludes, on what basis, whether excluded candidates can be recovered, or what confidence information accompanies a classification.
The federated element adds a second question. If classification behaviour improves from network learning, the system a laboratory validated may not behave identically six months later.
Ask what pre classification filters and how a reviewer can see past it, and how behavioural changes from network learning are surfaced to laboratories.
The architecture is named at a high level and nothing beneath it is described.
What is public: machine learning applied to variant calling, annotation and pre classification from sequencing data, described as resting on patented algorithms, operating technology agnostically across instruments, and organised as a federated learning model across the institutional network. Naming federated learning is a genuine architectural disclosure rather than a marketing term, because it commits the company to a specific claim about where computation happens.
What is absent: any description of the models themselves, the features used, the training data and its provenance, validation design, performance figures, versioning practice, or how a model change is communicated to laboratories running the platform as part of their own validated test.
That last point carries particular weight for this deployment model. Institutions run this software inside their own accredited laboratories, in at least one case as the analytical component of a laboratory developed test they validated themselves. A laboratory that has validated a test is responsible for it, and an update to the analytical software beneath that test is a change to a validated system. The laboratory needs to know when the model changed, what changed, and whether revalidation is required, and it needs that in a form its own quality system can consume.
Ask how model versions are identified in results, what change notification laboratories receive, and what evidence accompanies an update.
Strong instruments, a clearly stated role, and one architectural question the instruments do not reach. Certification to the cloud personal information protection standard is the one specifically concerned with handling personal data as a cloud processor, and it sits alongside encryption and redundant storage in secured private data centres.
More useful than either is the stated allocation of roles: the hospital is the controller and this company is the processor, which is the correct allocation for a platform computing on data belonging to an institution and is something very few vendors in this index state at all. It matters because it settles who decides, who must be asked, and who a patient's rights run against, before any specific term is negotiated.
The product is also positioned around institutions retaining control of their own samples and data through in house analysis, a design choice consistent with that role rather than bolted onto it. The chief executive has stated the company can only compute the data and cannot sell it, which is the right commitment and was made in a press interview years ago rather than published as a standing term, so ask for it in the contract. The question the instruments do not reach is the network.
Federated learning means the model travels to the data rather than the reverse, which genuinely reduces movement and does not eliminate flow: the updates a model returns are derived from that institution's patients, and inference against model updates is an active research area rather than a solved problem. Ask what leaves under the federated arrangement, and what protects it.
Scale is well documented (reported 1.8 million plus genomic profiles analyzed, roughly 30,000 analyses per month, 750+ institutions). Analytical validation studies exist including a clinical trial assay validation with a research partner; independent performance figures per application were not compiled this pass.
Strong instruments, a clearly stated role, and one architectural question that the instruments do not reach.
What is documented. Certification to the cloud personal information protection standard, which is the one specifically concerned with handling personal data as a cloud processor. Encryption of uploaded data with redundant storage in secured private data centres. And a clearly stated position under European data protection law: the hospital is the controller and this company is the processor, which is the correct allocation for a platform that computes on data belonging to an institution. The product is also positioned around institutions retaining control of their own samples and data through in house analysis, which is a design choice consistent with that role rather than a claim bolted onto it.
The company's chief executive has stated plainly that it can only compute the data to help hospitals diagnose and treat, and cannot sell it. That is the right commitment. It was made in a press interview some years ago rather than published as a standing term, and a buyer should ask for it in the contract rather than relying on it.
The question the instruments do not reach is the network. The platform is described as operating a federated learning model across participating institutions. Federated learning means the model travels to the data rather than the data travelling to the model, which genuinely reduces movement. It does not eliminate flow: the updates a model returns are derived from that institution's patients, and inference against model updates is an active area of research rather than a solved problem.
Ask what leaves an institution under the federated arrangement, and what protects it.
Both frameworks are named and one role is stated precisely, with the contracting detail unpublished.
The company states compliance with both the United States health privacy rule and European data protection law on its platform pages, and describes ensuring compliance with those and other local regulations across the profiles it processes each week. Under the European framework it states the allocation explicitly: the hospital is the controller, the company is the processor. That is the correct structure for a platform computing on an institution's data, and stating it plainly saves a buyer the analysis.
The United States side is necessarily different in kind rather than in degree. Where a hospital runs the platform to analyse its own patients' sequencing data, the company is receiving protected health information on that hospital's behalf and a business associate agreement is the operative instrument. A single platform therefore stands in two distinct legal relationships depending on which customer is using it, and the obligations, breach notification timelines and permitted uses differ between them.
What was not located: a business associate availability statement, the contracting entity, the subprocessor register, or the terms governing what the company may do with data it processes.
One question follows from the corporate structure. This is a Swiss headquartered company with United States operations serving institutions in more than seventy countries. Which entity contracts with a United States hospital, and whether staff outside the United States can access that hospital's data during support, are the practical questions.
Ask which entity signs, and where support access originates.
A comprehensive, long standing and independently audited certification portfolio, and the duration is part of what earns the grade.
The company first certified its information security management system to the international standard in 2014 and has since recertified to the current 2022 revision, which means more than a decade of continuous certification with annual surveillance and periodic full reaudit rather than a recent push before a funding round. In January 2025 it added the cloud specific pair, covering cloud security controls and the protection of personal information in cloud services, which are the standards that speak directly to what a cloud native genomics platform actually does. It holds the medical device quality management standard alongside them, and maintains an entry in the cloud security alliance registry, which publishes a completed control questionnaire a counterparty can read rather than request. Certification is by an internationally recognised body.
The technical description is specific rather than general: data uploaded to the platform is encrypted, held redundantly in secured private data centres, and the company has described a patented approach to genomic data encryption.
What is not published, and is the only real gap: penetration testing results or a vulnerability disclosure programme.
One scope question worth asking despite the strength here. The company also holds European in vitro diagnostic certification for specific diagnostic solutions while most of the platform is research use only, so confirm which certificates cover the modules being deployed and in which territory.
Positioning is stated with appropriate care: the platform is IVDR certified for certain applications in the EU, while some applications are labeled Research Use Only and clearance varies by country. Deployments such as Mount Sinai run DDM as a laboratory developed test in the customer's own CLIA certified, CAP accredited lab, with SOPHiA providing software and not performing diagnostic testing. Graded on clarity of regulatory positioning, not on possession of a specific US clearance.
No governance framework, model documentation, evaluation methodology or subgroup performance analysis was located, on a record where security and quality certification is otherwise exemplary. That contrast is the same one this index has found at every mature platform vendor: strong disclosure in the established domains, nothing extended to the models.
Two domain questions apply.
The first is the one this lane puts to all clinical genomics. Variant calling, annotation and pre classification depend on reference population data drawn disproportionately from people of European ancestry, so classification confidence and uncertain variant rates differ across populations. A platform serving more than seventy countries encounters that unevenness more directly than a single country laboratory does, and the company publishes nothing on how performance varies or how it is monitored across its network.
The second concerns the network itself. The platform is described as operating federated learning across participating institutions, which means the model improves from what member institutions see. Whether that improvement is distributed evenly, or whether the model is shaped predominantly by the largest and best resourced members and then applied to smaller ones, is a governance question about who benefits from a collective asset. It is answerable and nothing addresses it.
Ask for classification performance by ancestry, how the company monitors drift across a heterogeneous global network, and how federated model improvements are validated before they reach an institution's clinical pipeline.
Naming federated learning is a genuine architectural disclosure rather than a marketing term, because it commits the company to a specific and checkable claim about where computation happens, and the machine learning applied to variant calling, annotation and pre classification is described as operating across instruments rather than tied to one manufacturer.
Beneath that nothing is described: no account of the models, the features used, the training data and its provenance, validation design, performance figures, versioning practice, or how a model change is communicated to laboratories, and no warranty, indemnity or remediation commitment. That last omission carries particular weight for this deployment model and it is the finding on this record.
Institutions run this software inside their own accredited laboratories, in at least one case as the analytical component of a laboratory developed test they validated themselves, and a laboratory that has validated a test is responsible for it. An update to the analytical software beneath that test is a change to a validated system, so the laboratory needs to know when the model changed, what changed, and whether revalidation is required, in a form its own quality system can consume.
A silent update leaves an accredited laboratory formally responsible for a test it can no longer describe. Ask how model versions are identified in results, what change notification laboratories receive, and what evidence accompanies an update.
The domain relevant interoperability claim is real and is the right one for this product.
For a genomics analysis platform the interoperability question is not primarily about the medical record. It is whether the platform can ingest data from whatever sequencing instruments a laboratory already owns, because sequencers are capital equipment with long replacement cycles and a laboratory will not change instrument to suit an analysis vendor. The company states its platform is technology agnostic across sequencing instruments, which is a substantive claim and the reason a network of this size across this many countries is achievable at all: it removes the hardest adoption barrier in the category.
The deployment model reinforces it. Institutions run analysis in house on their own data, which means the platform has to fit into an existing laboratory pipeline rather than replace it.
Held at B rather than A because no named integration with a laboratory information management system or medical record platform was located from the company's own materials, and no interface documentation or supported standard was identified. A third party reference describes record and laboratory system interoperability, which this index does not credit without a vendor source.
Ask which instruments are supported and validated, what file formats are accepted, how results reach the laboratory information system and the chart, and whether variant classifications are delivered as structured data or as a report.
Cloud native and decentralized by design, deployed into hospital and lab workflows across a reported 750+ institution network with a federated learning approach that keeps analysis distributed. Held back from A because specific data residency commitments by region were not retrieved.
No public pricing. Contact the vendor. Enterprise and per analysis models are referenced in third party coverage but no rate card is published.
Broad and clearly stated, with an unusually precise regulatory boundary and one thing left undistinguished.
The scope is a global network of hospitals, laboratories and biopharmaceutical institutions, reported at more than eight hundred across over seventy countries, concentrated on oncology and rare disease, with modules spanning genomics, radiomics, digital pathology and multimodal analytics.
What lifts this above a broad claim is that the company states its regulatory position per product and per territory rather than in general. It marks its products as research use only and not for diagnostic use unless specified otherwise, and names the specific diagnostic solutions that carry European in vitro diagnostic certification and the exact territories in which they hold it. Very few vendors in this index volunteer the limits on where and how their product may be used clinically, and doing it product by product is more useful still.
What is not distinguished is maturity across modalities. Genomics, radiomics, digital pathology and multimodal analysis rest on different evidence bases and are at visibly different stages, and the platform presents them as one offering. A buyer evaluating the radiomics or multimodal modules should not assume the evidence and regulatory status supporting the genomics work transfers to them.
Ask which modules are in routine clinical use rather than research deployment, and for the evidence and regulatory position of each separately.
Compared With
Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.
Announced Deployments
Publicly announced health system deployments and partnerships. This is a record of announcements, not an assessment of deployment success or scale.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Contact the vendor
|
Enterprise and per analysis agreements for the DDM platform | — | — | Third Party Estimated |
Enterprise and per analysis models are referenced in third party coverage; SOPHiA is a public company (NASDAQ: SOPH) so aggregate economics appear in filings, but platform pricing is not published.