Security
Where your data lives, and who can reach it
Laboratory inventory is commercially sensitive and occasionally regulated. This page sets out where your data lives, how it is protected and who can reach it.
3
EU data centres
4 hours
Backup interval
7
Access roles
Residency
Where the servers are
Labnize is hosted on Hetzner Online GmbH infrastructure. Customer data is stored in three data centres, all inside the European Union, and it is not moved outside it.
Nuremberg, Germany
Falkenstein, Germany
Helsinki, Finland
Certification
Held by the hosting provider
These certificates are held by the infrastructure provider and describe the environment your data runs in.
- ISO/IEC 27001:2022
- The international standard for an information security management system.
- BSI C5 Type 2
- The German federal audit framework for cloud services, at its higher assurance level.
- Section 8a BSI-KritisV
- Compliance with the German critical infrastructure regulation.
- EMAS and ISO 14001
- Environmental management system certification for the data centre estate.
- TUV Rheinland annual audit
- An independent audit carried out every year.
GDPR and the processing agreement
Processing is covered by a standard data processing agreement offered through the hosting provider. Data stays within the European Union for the entire life of the account.
Facility
Physical security at the data centre
- High-security perimeter fencing around the whole data centre park.
- Camera surveillance and logged entry, around the clock.
- Electronic and biometric access control at every entrance.
- Redundant power, cooling and emergency generators.
- Early warning fire detection with gas-based suppression.
- Decommissioned disks securely wiped or physically destroyed.
Continuity
Backups
- The database is backed up automatically every four hours.
- Backups are encrypted and held in separate EU storage, away from the application server.
- Recent cycles are always retained, and every run is checked.
Application
What Labnize does on top
Encrypted transport
All traffic between users and the platform runs over HTTPS with TLS.
Passwords never stored in the clear
Passwords are kept as one-way cryptographic hashes. No system holds a readable password.
Role-based access
Roles from owner down to editor, each reaching only the data its job needs.
Organisation isolation
Each organisation is separated from every other, and cannot see another organisation data.
Audit log
Significant actions are recorded with who performed them and when.
Stock movement log
Every use, transfer and write-off can be traced backwards through the ledger.
Private file links
Uploaded certificates and safety data sheets are served over links that expire, never public addresses.
Response
If something goes wrong
| Situation | Response |
|---|---|
| Data corruption or accidental deletion | Restore from the most recent backup, with at most four hours of data at risk. |
| Loss of a server | Rebuild onto new hardware from the off-server backups. |
| Data centre level incident | Bring the service back up from the backup held in a different region. |
| Suspected unauthorised access | Investigate through the audit log and suspend the affected accounts. |
Security
References
The provider certificates and official documents behind the statements on this page.
Ready to modernise your laboratory?
Join the labs that swapped the shared spreadsheet for a system of record.