Skip to content

Security

Where your data lives, and who can reach it

Laboratory inventory is commercially sensitive and occasionally regulated. This page sets out where your data lives, how it is protected and who can reach it.

3

EU data centres

4 hours

Backup interval

7

Access roles

Residency

Where the servers are

Labnize is hosted on Hetzner Online GmbH infrastructure. Customer data is stored in three data centres, all inside the European Union, and it is not moved outside it.

Nuremberg, Germany

Falkenstein, Germany

Helsinki, Finland

Certification

Held by the hosting provider

These certificates are held by the infrastructure provider and describe the environment your data runs in.

ISO/IEC 27001:2022
The international standard for an information security management system.
BSI C5 Type 2
The German federal audit framework for cloud services, at its higher assurance level.
Section 8a BSI-KritisV
Compliance with the German critical infrastructure regulation.
EMAS and ISO 14001
Environmental management system certification for the data centre estate.
TUV Rheinland annual audit
An independent audit carried out every year.

GDPR and the processing agreement

Processing is covered by a standard data processing agreement offered through the hosting provider. Data stays within the European Union for the entire life of the account.

Facility

Physical security at the data centre

  • High-security perimeter fencing around the whole data centre park.
  • Camera surveillance and logged entry, around the clock.
  • Electronic and biometric access control at every entrance.
  • Redundant power, cooling and emergency generators.
  • Early warning fire detection with gas-based suppression.
  • Decommissioned disks securely wiped or physically destroyed.

Continuity

Backups

  • The database is backed up automatically every four hours.
  • Backups are encrypted and held in separate EU storage, away from the application server.
  • Recent cycles are always retained, and every run is checked.

Application

What Labnize does on top

  • Encrypted transport

    All traffic between users and the platform runs over HTTPS with TLS.

  • Passwords never stored in the clear

    Passwords are kept as one-way cryptographic hashes. No system holds a readable password.

  • Role-based access

    Roles from owner down to editor, each reaching only the data its job needs.

  • Organisation isolation

    Each organisation is separated from every other, and cannot see another organisation data.

  • Audit log

    Significant actions are recorded with who performed them and when.

  • Stock movement log

    Every use, transfer and write-off can be traced backwards through the ledger.

  • Private file links

    Uploaded certificates and safety data sheets are served over links that expire, never public addresses.

Response

If something goes wrong

If something goes wrong
SituationResponse
Data corruption or accidental deletionRestore from the most recent backup, with at most four hours of data at risk.
Loss of a serverRebuild onto new hardware from the off-server backups.
Data centre level incidentBring the service back up from the backup held in a different region.
Suspected unauthorised accessInvestigate through the audit log and suspend the affected accounts.

Security

References

The provider certificates and official documents behind the statements on this page.

Ready to modernise your laboratory?

Join the labs that swapped the shared spreadsheet for a system of record.