Security has been a design requirement since 2003.
Secure Development & Verification
Independent audits and testing behind every release.
- Developers train on secure coding practices before shipping features
- Each release passes automated and manual security testing along with vulnerability scanning
- Independent security firms conduct manual penetration tests, with fixes delivered in maintenance releases based on severity, including for older production versions in active use
- SOC 2 Type II attestation renewed through annual audits, with controls continuously monitored and published in the Trust Center
Access Control & Compliance
Fine-grained permissions and audit-ready records.
- Group- and role-based permissions govern who can view and modify every record in the system
- LDAP, SAML, and CAS single sign-on plus Duo two-factor authentication with Premium Editions
- Audit logging records who accessed which records and when
- Electronic signatures and controlled user access support labs operating under HIPAA and 21 CFR Part 11, with validation services available for GxP work
Managed Cloud Security
Compliant hosting in LabKey Cloud.
- Managed network firewall and web application firewall on every environment
- Databases and file systems encrypted at rest; traffic encrypted with TLS in transit
- Intrusion detection and prevention with continuous application monitoring
- Managed backups with retention up to 7 years