LDB LIMS IT security: protection against third-party access | Data backups | Availability
A web application firewall (WAF) protecting the LDB cloud ensures that LDB can only be accessed through encrypted connections. Access to the firewall is controlled by a load balancer, which distributes incoming requests across multiple application servers in different availability zones and permits only encrypted HTTPS connections with RSA encryption and a key length of 2,048 bits.
Users sign in to LDB with a login, password and an additional security factor (MFA, multi-factor authentication), using authenticator apps such as Google Authenticator, Microsoft Authenticator, Authy or KeePassXC, or security keys such as YubiKeys, SoloKeys or Google Titan. Passwords are hashed using the Argon2id algorithm, which remains unbroken according to the current state of the art.
LDB supports signing in with a passkey. Passkeys provide a new way to sign in without a password, offering greater security than a password plus MFA and a faster, more convenient sign-in experience.
LDB also supports single sign-on (SSO). In this case, authentication is handled by an identity provider such as Microsoft Azure AD or Okta. Users can sign in to LDB quickly and securely using their existing company account.
Every sign-in attempt is logged with its IP address and time. If someone repeatedly attempts to sign in with an incorrect password, LDB blocks sign-in for a defined period.
Data is stored encrypted in the LDB cloud in a MySQL-compatible database (Aurora). Each LDB instance uses its own database and separate database accounts, technically preventing access to another LDB customer’s data.
All databases are stored encrypted. This prevents unauthorised parties from reading the data or changing it without detection; changing individual bytes would render the entire database unreadable.
Databases are encrypted with AES-256-GCM, a symmetric algorithm based on the Advanced Encryption Standard (AES-256) and Galois/Counter Mode (GCM), using a 256-bit key.
LDB is continuously backed up in full to Amazon S3. To provide our customers with complete security, LDB creates an incremental backup every second. A full backup is also created every day.
All daily backups are retained for one week. After one week, one full backup per week is retained until further notice, for at least the next 10 years.
The backup system is designed for 99.999999999% data durability over one year. This reliability level corresponds to an expected annual data loss of 0.000000001%. This durability is achieved by distributing each backup redundantly across three independent data centres.
All backups are stored encrypted, with a separate key for each backup. All keys are encrypted with a dedicated master key that is regularly changed. Backups are also encrypted using the 256-bit Advanced Encryption Standard (AES-256). No practically feasible attack against this method is known.
The LDB cloud is distributed across three independent availability zones and designed for availability greater than 99.95%. This corresponds to less than 5 hours of downtime per year.
Availability zones are independent data centres separated by many kilometres, with redundant power supplies, networking and connectivity. They are designed to be isolated from failures in other availability zones.
The LDB cloud runs in Amazon AWS’s Frankfurt data centre region, distributed in parallel across the eu-central-1a, eu-central-1b and eu-central-1c availability zones. It is designed to withstand the simultaneous failure of two availability zones and remain available.
Laboratory software processes sensitive data. At LDB, security is an integral part of the architecture.
A German-Austrian company governed by European law.
Three independent availability zones in Frankfurt.
All data is encrypted at rest and in transit, with clearly defined access controls.
MFA, SSO and passkeys for secure authentication.
Regular internal and external security audits and penetration tests.
Every activity is documented with user details and a timestamp.
As a LIMS provider, we are certified to the current ISO 27001 standard for data security, availability, processing integrity, confidentiality and data protection. We also meet the requirements of the NIS2 Directive.