Trust, Security & Compliance

LabArchives is a secure ELN with FedRAMP Moderate authorization, SOC 2 Type II, and ISO 27001:2022 certification, plus HIPAA, GDPR, and FERPA alignment. Data is encrypted in transit and at rest, hosted on AWS, with documented disaster recovery plans.

Compliance and Data Support by Product

LabArchives offers two product environments built for different compliance requirements. LabArchives for Commercial/Academic supports the certifications and data types most research and education programs need day to day, while LabArchives for Government adds FedRAMP® Moderate authorization and additional federal controls for programs handling regulated or federally funded data. The table below compares both environments side by side across compliance standards, encryption, hosting, and data support, so you can quickly identify which environment fits your project. Compliance requirements are often set by your specific contract, grant terms, or institutional policy, so we recommend confirming your exact requirements with our team before finalizing a data management plan.

Category

LabArchives for Commercial/Academic

LabArchives for Government

Compliance and Accessibility

ISO 27001; SOC2® Type 2, PCI DSS; CMMC Level 1; GDPR, HIPAA, GovRAMP™; FERPA, VPAT®

FedRAMP® Moderate Authorization; NIST 800-53 Rev5; NIST 800-171, CMMC Level 2; GDPR, HIPAA, GovRAMP; FERPA, VPAT

Cryptography and Encryption

Data Encrypted in Transit (TLS 1.3+); Data Encrypted at Rest (AES-256)

Data Encrypted in Transit (TLS 1.3+); Data Encrypted at Rest (AES-256)

DoD Impact Level

IL2

IL2

AWS Regions

US, AU, UK, EU and Canada

US

Single Sign-On (SSO) via SAML

Yes, Optional

Yes, Required

100% FIPS Validated Cryptographic Modules

No

Yes

PII Data Support

Yes, De-identification optional

Yes, De-identification optional

PHI Data Support

Yes, Must be de-identified or covered by BAA

Yes, Must be de-identified or covered by BAA

Non-DoD CUI Data Support

Limited, Not recommended. Insufficient for any CUI

Yes, FedRAMP Moderate covers non-DoD CUI requirements

DoD CUI Data Support

No, DoD CUI requires IL4 or greater

No, DoD CUI requires IL4 or greater

Could Additional Details Impact Data Support?

Yes, Customers should always confirm that their own requirements for their data do not exceed the details noted above.

Yes, Customers should always confirm that their own requirements for their data do not exceed the details noted above.

All company names, product names, program names, standards, certifications, trademarks, service marks, certification marks, and registered marks referenced herein are the property of their respective owners.

FedRAMP Moderate authorization badge

LabArchives for Government

LabArchives for Government are the same great LabArchives products but are customized to meet additional NIST 800-53 requirements, approved by federal government agencies, and placed within an authorized environment. Our cloud hosted, secure solution is an excellent option for those needing to move from locally hosted solutions to meet specific federal security requirements. LabArchives is officially "Authorized" with the FedRAMP® Project Management Office.

To learn more, click here.

SOC 2 Type II certified

SOC 2 TYPE II Audit

LabArchives has received a SOC2 TYPE II audit from an independent third party auditor. This audit provides an independent, third-party validation that a service organization’s information security practices meet industry standards stipulated by the AICPA. The report shows LabArchives has an established framework for internal controls that facilitates accountability and a commitment to security.

To request access to SOC reports, contact us.

ISO 27001:2022 certified

ISO 27001:2022 Audit

LabArchives has been awarded ISO 27001:2022 certification by Schellman, following an external review of our Information Security Management System (ISMS). ISO 27001 requires a systematic, ongoing approach to managing risks to company and customer data. The audit covered ELN operations, software development, and cloud hosting, finding LabArchives meets or exceeds the standard, with effective controls in place and actively monitored.

To request access to ISO reports, contact us.

Physical Security and Redundancies

  • LabArchives primary and disaster recovery systems exist in physically secure and separate data centers that are provided by Amazon Web Services (AWS). Read complete AWS facility details.
  • LabArchives customer cloud services are separate from any corporate networks as well as development, accounting, email, support, contact, sales, and marketing systems.
  • Any access to production systems is limited to LabArchives staff who require the access for systems maintenance with access via 2FA or better with principle of least privilege in mind.
  • LabArchives ELN, Inventory and Scheduler customer data or backups do not leave AWS data centers or their geographical region without the consent of the data owner or site administrator.
  • LabArchives ELN, Inventory and Scheduler customer data is owned by the customer and is not accessed, classified, or shared with others without consent.
  • All LabArchives ELN and Inventory data, backups and systems reside exclusively in the AWS regions of the United States, Australia or Europe depending on customer preference.
  • All Scheduler data, backups and systems reside exclusively in AWS regions in the United States with customer SSO-based authentication routed through LabArchives systems in the United States, Australia, or Europe.
  • Any retired or replaced disk storage devices or systems used for customer data are securely destroyed and are not stored, reused, or sold.

Network Security

  • All data is encrypted in transit with fulltime HTTPS over TLS 1.3 with HSTS enabled.
  • LabArchives servers are protected by redundant, industry standard firewalls and security devices.
  • LabArchives runs intrusion detection and protection systems (IDS/IPS) to analyze and block malicious traffic.
  • All network traffic is logged and monitored for any suspicious or unusual activity that impacts security and availability with response by LabArchives staff 24/7/365.

Data and Application Security

  • All LabArchives customer data and backups are encrypted at rest with AES-256.
  • Bi-hourly backups and/or real-time replicas of data are available in physically redundant locations.
  • LabArchives adheres to secure coding practices by design and a strict development and deployment process with separate development, testing and production environments and staff with decades of experience writing secure, data driven web applications.
  • LabArchives ELN and Inventory have application security vulnerability scans performed by an independent security firm quarterly.
  • Each LabArchives ELN notebook's data is logically isolated from other notebooks’ data with its own internal database.
  • LabArchives supports both a proprietary login option and allows for integration with a customer’s SSO systems via SAML (Shibboleth, Azure, ADFS, Okta, and others).
  • For proprietary logins, account passwords are stored in encrypted form with a unique salt token for each password. SSO integrations utilize user authentication data in a customer’s SSO system only.
  • LabArchives only stores data provided by its customers and has no control over what types of data they store or its classification. This depends solely on the customers’ policies for LabArchives use.
  • LabArchives itself does not store any private user information such as social security numbers, driver’s license numbers, bank information, credit cards, etc. All credit cards are processed and stored by a PCI-compliant vendor.
  • All access to LabArchives is logged and application logs are monitored regularly for malicious or unusual traffic.

High Availability

  • Critical server statistics and accessibility details are monitored from multiple locations worldwide continuously.
  • LabArchives Systems staff are ready to respond when monitoring thresholds for performance and availability are reached with paging 24/7/365.
  • LabArchives has detailed Incident Response, Disaster Recovery and Business Continuity policies and procedures that are reviewed and tested at least annually.

LabArchives Compliance Standards

  • LabArchives utilizes Amazon Web Services (AWS) for all its infrastructure needs including networks, firewalls, computing, storage, database, etc. Read all AWS compliance details.
  • LabArchives ELN and Corporate Processes have completed SOC2 certification by a qualified accounting firm. Report details can be requested by contacting us.

LabArchives Aligns with Many Other Compliance Standards and Guidelines

  • HIPAA (Health Insurance Portability and Accountability Act)
  • FERPA (Family Educational Rights and Privacy Act)
  • GDPR (General Data Protection Regulation)
  • Federal Funding Agency Data Management Policy
  • FDA – 21 CFR Part 11 (ELN when using built-in page signing/witnessing feature)
  • ADA (Americans with Disabilities Act) ELN only
  • Section 508 of the Rehabilitation Act (29 U.S.C. § 794d) ELN only
  • Level A and AA of the WAI Web Content Accessibility Guidelines 2.0. ELN only
  • NIST 800-171
  • Australian Modern Slavery Act 2018

Continuity and Contingency Details

LabArchives has contingency plans in place to ensure operations run smoothly. No regional, national or other office restrictions will impact LabArchives’ ability to securely serve its users around the globe. LabArchives is ready to assist as you prepare a response plan for your remote work at your lab, company, institution, or in your lab course. If you need help taking your research or lab course online, we are here to help.

  • LabArchives is a cloud service provider and a cloud service consumer.
  • LabArchives is a serverless office with all business systems including phones provided by major cloud providers.
  • Due to federal, state, and local directives, all LabArchives staff are operating from isolated, remote offices with full access to email, phones and business systems required for their jobs.
  • No LabArchives customer data or backups reside in any corporate offices.
  • LabArchives systems, databases, networks and security systems in the United States, Australia and Europe (UK) are running in Amazon Web Services (AWS).
  • All services in all regions are running at full power with available capacity to support the anticipated increase in our customer’s needs to provide remote research and learning.
  • Business Continuity plans account for extreme situations like an office closure to ensure that our global services remain online, fully functional, and fully supported by staff.
  • All business-related travel has been temporarily halted. Business is conducted electronically including via remote, online meetings.
  • LabArchives has standards of performance guarantees and verified business continuity with all its major service providers.

Learn More…

To request access to all documents (SOC 2, SOC 3, and ISO reports) visit our Trust Center. SOC 2 and ISO access will require a signed NDA and special handling by requesters.

Frequently Asked Questions

Security & compliance, answered directly
1. Is LabArchives FedRAMP authorized?

LabArchives for Government holds a FedRAMP Moderate authorization, officially listed on the FedRAMP Marketplace. This is a Marketplace listing verified through an independent federal review process, not a self-asserted claim.

2. What does a FedRAMP Moderate authorization mean?

FedRAMP Moderate authorization means a system has passed an independent security assessment against NIST 800-53 controls for moderate-impact federal data, backed by an authorizing agency sponsor and ongoing continuous monitoring. It is a higher bar than stating an intention to pursue authorization.

3. Is LabArchives SOC 2 certified?

LabArchives for Commercial/Academic has completed a SOC 2 Type II audit performed by an independent third-party auditor. The audit validates that LabArchives' security practices meet the AICPA's Trust Services Criteria over a sustained period rather than at a single point in time.

4. Is LabArchives ISO 27001 certified?

Yes. LabArchives holds ISO 27001:2022 certification, awarded by Schellman after an external audit of its Information Security Management System. The audit covers LabArchives ELN operations and support, software development, and cloud hosting.

5. How can I request LabArchives' SOC 2 or ISO 27001 audit reports?

SOC 2, SOC 3, and ISO 27001 reports can be requested through the Dotmatics Trust Center. Access to the full SOC 2 and ISO reports requires a signed NDA and follows special handling procedures.

6. Is LabArchives HIPAA compliant?

LabArchives aligns both product environments with HIPAA requirements. LabArchives can provide a Business Associate Agreement (BAA) on request, which can cover PHI handling under HIPAA depending on your institution's own policies.

7. Does LabArchives support 21 CFR Part 11 electronic signatures?

LabArchives ELN supports FDA 21 CFR Part 11 requirements when using its built-in page signing and witnessing feature. This applies specifically to ELN with that feature enabled, not to the full LabArchives product suite by default.

8. Is LabArchives GDPR compliant?

LabArchives aligns with the General Data Protection Regulation for customers hosting data in European Union regions. LabArchives for Commercial/Academic offers EU-based AWS hosting to support GDPR obligations, and both product environments align with GDPR overall.

9. Is LabArchives FERPA compliant?

LabArchives aligns with FERPA, the Family Educational Rights and Privacy Act, across both product environments. This supports schools that need to protect student education records.

10. Does LabArchives align with NIST 800-171 or CMMC requirements?

LabArchives for Commercial/Academic supports CMMC Level 1, while LabArchives for Government supports CMMC Level 2 along with NIST 800-171 and NIST 800-53 Rev 5. Both product environments run on AWS Commercial infrastructure certified at DoD Impact Level 2.

11. Is LabArchives compliant with the Australian Modern Slavery Act?

LabArchives aligns with the Australian Modern Slavery Act 2018 as part of its broader compliance and corporate governance program.

12. Is LabArchives accessible for users with disabilities?

LabArchives ELN meets Level A and AA of the WCAG 2.0 accessibility guidelines, along with ADA and Section 508 requirements. Both product environments also align with VPAT, the Voluntary Product Accessibility Template.

13. Where is LabArchives customer data hosted?

LabArchives for Commercial/Academic hosts data on AWS in the United States, Australia, the United Kingdom, the European Union, and Canada. LabArchives for Government hosts data on AWS in the United States only. All hosting is managed by LabArchives staff on AWS Commercial infrastructure.

14. Is LabArchives data encrypted?

Yes. Data in transit is protected with HTTPS over TLS 1.3 and HSTS enabled, and data at rest is encrypted with AES-256. LabArchives also runs bi-hourly backups and real-time replication across physically redundant locations.

15. Who owns the data stored in LabArchives?

Customers own their own data. LabArchives does not access, classify, or share customer data without consent, and data does not leave its designated AWS region without the owner's authorization.

16. Does LabArchives support single sign-on?

Yes. LabArchives integrates with SAML-based single sign-on systems including Shibboleth, Azure AD, ADFS, and Okta, in addition to its own proprietary login option. SSO is optional for LabArchives for Commercial/Academic and required for LabArchives for Government.

17. What happens to LabArchives data during a disaster or outage?

LabArchives maintains documented Incident Response, Disaster Recovery, and Business Continuity plans reviewed and tested at least annually. Primary and disaster recovery systems run in physically separate AWS data centers, with continuous monitoring and 24/7 staff response.

18. What is the difference between LabArchives and LabArchives for Government?

LabArchives for Government runs the same core ELN, Inventory, and Scheduler products, hosted in a FedRAMP Moderate authorized environment with NIST 800-53 Rev 5 controls, CMMC Level 2, and 100% FIPS validated cryptographic modules. LabArchives for Commercial/Academic uses the same products with SOC 2 Type II, ISO 27001:2022, PCI DSS, and CMMC Level 1, but without FedRAMP authorization or FIPS validated modules.

Get started with LabArchives today

Start for free and upgrade as your team grows