gene.zip · Run in your own cloud

Your data never leaves your network.

Run the gene.zip compression engine on a hardened, confidential-compute instance inside your own AWS, Azure or GCP account. It reads and writes your buckets directly — nothing is ever sent to us.

How it works

Compression that comes to your data

Deploy a pre-built, right-sized image from your cloud's marketplace. It launches in your VPC, processes data in place, and tears down when finished — you pay your provider for the compute, plus your gene.zip tier for stored data.

1

Deploy in your account

One click from your cloud marketplace launches the image inside your own VPC / subscription / project.

2

Process in place

It reads and writes your object storage (s3://, gs://, az://) directly — data stays in your account.

3

Confidential by design

Runs inside a hardware-isolated enclave with remote attestation. Even the host OS can't read your data in memory.

4

Tear down

Spin it up for a job, shut it down after. No standing infrastructure, no egress to gene.zip.

Available on

Pick your cloud

Each listing is a confidential-compute image you launch in your own account. Marketplace listings are rolling out — links go live as each is published.

AWS Nitro Enclaves

Confidential compute · EC2

An isolated, attested enclave with no persistent storage, no interactive access and no external networking — the strongest isolation for processing PHI/regulated genomic data inside your VPC.

AWS Marketplace Coming soon

Azure Confidential

Confidential VMs / Containers

Hardware-based trusted execution (AMD SEV-SNP / Intel TDX) keeps your data encrypted in use. Runs in your subscription and VNet, reading directly from your blob storage.

Azure Marketplace Coming soon

GCP Confidential

Confidential VMs / Confidential Space

Confidential Space gives a hardened, attested workload that even your own admins can't peek into — ideal for sharing genomic data across parties without exposing it. Runs in your project, on your buckets.

Google Cloud Marketplace Coming soon
Why it's safe

Built for data that can't leave

No egress to gene.zip. The engine runs in your account; your genomic data never traverses our network.
Encrypted in use. Confidential compute keeps data encrypted in memory — invisible to the host OS and the cloud provider.
Remote attestation. Cryptographic proof that only the unmodified gene.zip image is running before any key is released.
Your keys, your buckets. Reads and writes your object storage with your own KMS keys and IAM — no shared credentials.
No standing footprint. Launch per job, tear down after. Nothing to leave running or to breach.
Compliance-friendly. Helps satisfy HIPAA/GDPR data-residency and BAA requirements by keeping PHI inside your boundary.

Talk to us about a private-cloud deployment →