Security has been a design requirement since 2003.
SOC 2 Type II Attestation
Audited annually, monitored continuously.
- SOC 2 Type II attestation, renewed through annual audits
- Security controls continuously monitored and published in the Trust Center
- Manual penetration testing by independent security firms
- Automated and manual security testing on every release
Compliance Support
For labs operating under HIPAA and 21 CFR Part 11.
- PHI handling with encryption and restricted access
- Electronic signatures and detailed audit trails
- Validation services for GxP environments
Access Control
Fine-grained control over data access.
- Group- and role-based permissions for every record in the system
- Duo two-factor authentication
- Audit logging of who accessed which records and when
Managed Cloud Security
Secure & compliant hosting in LabKey Cloud
- Managed network firewall and web application firewall
- Encryption at rest, TLS encryption in transit
- Intrusion detection and prevention with continuous application monitoring
- Managed backups with retention up to 7 years