Introduction to Lyra LIMS

Lyra LIMS is the governed operating system clinical laboratories run on. It replaces the 15+ fractured vendors a lab stitches together (LIMS, provider and patient portals, billing, integrations, and audit tooling) with one platform where governance is structural, evidence is automatic, and responsible AI is built into the core.

At the center sits the Lyra Engine, a governed-AI kernel that enforces policy, records every action to a tamper-evident ledger, and grounds every model call on the lab's own sealed events. Lyra is proprietary and AWS-hosted, and it runs in production at a working lab today.

Every surface in Lyra inherits the same first principles: enforce policy server-side, hash-chain every action into an append-only ledger, redact PHI on every model call, and keep a human accountable for every release.

The Lyra Engine

The Lyra Engine is the governed-AI kernel every portal runs on. It combines server-side policy control, a set of governed registries, and a Learning AI grounded on the ledger.

Policy Control

Roughly 238 governed policies span 20+ compliance frameworks, each with a dry-run mode so a change can be evaluated before it takes effect.

Registries

Integration, instrument, and method registries define what Lyra connects to, which analyzers it trusts, and how each assay is run, all versioned and governed.

Learning AI

A Learning AI grounded on the ledger reasons over the lab's real, sealed events, cites the record, and surfaces policy gaps. It never acts outside policy or takes an irreversible action on its own.

The Five Portals

Lyra is one platform with five portals. Every stakeholder in the lab works in the same governed system, on the same ledger.

  • LIMS: the bench, QC, and governance core.
  • Clinic / Provider: order intake and results for ordering providers.
  • Client Services: billing, marketing, and support.
  • Direct-to-Patient: patient results and direct-to-consumer sales.
  • Admin Console: run the engine and the fleet of labs.

The Tamper-Evident Record

Every action in Lyra is SHA-256 hash-chained into an append-only ledger. The ledger is the source of truth. Every UI view is a projection of it, never an independent source.

The ledger is externally anchored to immutable S3 Object-Lock storage, so a record cannot be silently altered after the fact. When an inspector or auditor asks what happened and when, the answer comes straight from the record, and the lab can prove a result was never modified.

Governed AI

Every model call is policy-injected, PHI-redacted, and hash-chain audited.

Responsible AI in Lyra is not a bolt-on. The assistant reasons over the lab's real sealed events and cites the record. It never acts outside policy and never takes an irreversible action on its own. It learns from the ledger and surfaces policy gaps for a human to resolve.

Analytical Science

Lyra runs the analytical pipeline end to end, with each step recorded to the ledger:

find450 background subtraction → 5PL calibration → Westgard QC (80% to 120% recovery gate) → IgE class 0 to 6 / tiered classification

Instrument results come in through the BioTek Gen5 XPT instrument bridge, which produces an immutable evidence manifest for every run.

Governance & Access

Release is governed by a four-eyes rule: approval and release require two distinct authenticated actors, aligned to CLIA (42 CFR §493.1281). The system cannot record a release without two operators on the record.

Access is controlled by RBAC, which intersects explicit per-user grants with the user's persona. A user can only do what both their grants and their persona allow.

Interoperability

Lyra speaks the standards a clinical lab already runs on, projected from the same governed ledger:

  • HL7 v2 for orders and results.

  • FHIR R4, with LOINC-coded observations and UCUM units.

  • NPPES / CMS for provider and payer data.

Infrastructure & Security

Lyra is proprietary and AWS-hosted, on a single EC2 instance running Docker Compose, behind an ALB with ACM-managed TLS and nginx.

Four Layers of Encryption at Rest
  • KMS-encrypted EBS volumes.

  • S3 SSE-KMS for object storage.

  • Application-layer Fernet encryption for stored credentials.

  • Object-Lock, signed backups.

Authentication

bcrypt / PBKDF2 password hashing with TOTP multi-factor authentication.

Backups & Recovery

Signed backups every four hours, with an RPO and RTO of four hours or less.

Compliance

Lyra is built for the frameworks clinical labs are held to: CLIA, CAP, HIPAA, and 21 CFR Part 11. Governed policy, four-eyes release, PHI redaction, and the tamper-evident ledger map directly to those requirements.

What's Next

This page is an overview of how Lyra is built. The full documentation library (portal guides, integration manuals, deployment patterns, and compliance mappings) is in active development.

To arrange a walk-through of Lyra LIMS in action, discuss an integration, or talk about the founding cohort, reach our team at

One platform. The whole lab. Governed by design.