Compliance and Data Support by Product
LabArchives offers two product environments built for different compliance requirements. LabArchives for Commercial/Academic supports the certifications and data types most research and education programs need day to day, while LabArchives for Government adds FedRAMP® Moderate authorization and additional federal controls for programs handling regulated or federally funded data. The table below compares both environments side by side across compliance standards, encryption, hosting, and data support, so you can quickly identify which environment fits your project. Compliance requirements are often set by your specific contract, grant terms, or institutional policy, so we recommend confirming your exact requirements with our team before finalizing a data management plan.
Category | LabArchives for Commercial/Academic | LabArchives for Government |
Compliance and Accessibility | ISO 27001; SOC2® Type 2, PCI DSS; CMMC Level 1; GDPR, HIPAA, GovRAMP™; FERPA, VPAT® | FedRAMP® Moderate Authorization; NIST 800-53 Rev5; NIST 800-171, CMMC Level 2; GDPR, HIPAA, GovRAMP; FERPA, VPAT |
Cryptography and Encryption | Data Encrypted in Transit (TLS 1.3+); Data Encrypted at Rest (AES-256) | Data Encrypted in Transit (TLS 1.3+); Data Encrypted at Rest (AES-256) |
DoD Impact Level | IL2 | IL2 |
AWS Regions | US, AU, UK, EU and Canada | US |
Single Sign-On (SSO) via SAML | Yes, Optional | Yes, Required |
100% FIPS Validated Cryptographic Modules | No | Yes |
PII Data Support | Yes, De-identification optional | Yes, De-identification optional |
PHI Data Support | Yes, Must be de-identified or covered by BAA | Yes, Must be de-identified or covered by BAA |
Non-DoD CUI Data Support | Limited, Not recommended. Insufficient for any CUI | Yes, FedRAMP Moderate covers non-DoD CUI requirements |
DoD CUI Data Support | No, DoD CUI requires IL4 or greater | No, DoD CUI requires IL4 or greater |
Could Additional Details Impact Data Support? | Yes, Customers should always confirm that their own requirements for their data do not exceed the details noted above. | Yes, Customers should always confirm that their own requirements for their data do not exceed the details noted above. |
All company names, product names, program names, standards, certifications, trademarks, service marks, certification marks, and registered marks referenced herein are the property of their respective owners.