IT security

Data security has the highest priority

Protection against access by third parties | Data backup | Availability

Protection against access by third parties

A web application firewall (WAF) around the LIMS.eu cloud ensures that only encrypted access to LIMS.eu is possible. Access to the firewall is controlled by a load balancer that distributes the load of requests across several application servers in different availability zones and only allows encrypted connections via HTTPS with RSA encryption and a key length of 2,048 bits.

Login to LIMS.eu is done via user authentication with login, password and an additional security factor (MFA - multifactor authentication) with authenticator apps such as Google Authenticator, Microsoft Authenticator, Authy, KeePassXC, etc. or with security keys such as YubiKeys, SoloKeys, Google Titan, etc. Passwords are encrypted using the Argon2ID algorithm, which is unbroken according to the current state of the art.

LIMS.eu supports login with Passkey. Passkey is a new option for logging in without a password with a higher level of security than password + MFA and allows a faster and more convenient login.

LIMS.eu also supports single sign-on (SSO). In this case, login takes place via an identity provider such as Microsoft Azure AD, Okta, etc. This allows users to log in to LIMS.eu more quickly and securely with their existing company account.

Each login attempt is logged with the IP address and time. If someone attempts to log in several times in succession with an incorrect password, the login to LIMS.eu is blocked for a defined period of time.

The data is stored in encrypted form in the LIMS.eu cloud on a MySQL-compatible database (Aurora). Each LIMS uses its own database with separate database accounts for each instance, so that access to data from another LIMS.eu customer is technically impossible.

All databases are stored in encrypted form. This prevents an unauthorized party from reading or changing the data unnoticed (changing individual bytes would make the entire database unreadable).

AES-256-GCM, a symmetrical algorithm based on Advanced Encryption Standard (AES-256) and Galois Counter Mode (GCM) with a 256-bit key, is used to encrypt the databases.


Data backup

  • Redundant database cluster on 3 availability zones
  • Incremental backups every second for 3 days
  • Daily full backups on S3 for 7 days
  • Weekly backups on S3 for unlimited runtime
  • Additional backups at an AWS independent backup system in the Netherlands with object locking compliance mode for 90 days
  • Optional: automated daily backup on site at the customer's premises

A complete data backup of LIMS.eu is carried out continuously on Amazon S3. In order to guarantee our customers absolute security, an incremental backup of LIMS.eu is created every second. In addition, a complete backup is created daily.

All daily backups are kept for one week. After one week, one complete backup per week is kept until revoked, for at least the next 10 years.

The data backup is designed for data stability of 99.999999999% over one year. This reliability level corresponds to an expected annual data loss of 0.000000001%. This data stability is achieved by distributing each backup redundantly across three independent data centers.

All backups are stored in encrypted form, with each backup being encrypted with its own key (all keys are encrypted with their own master key, which is changed on an ongoing basis). The 256-bit Advanced Encryption Standard (AES-256) is also used to encrypt the backups. No practically feasible attack is known for this procedure.


LIMS.eu cloud availability of the last years:
  • 2025 - 99,99%
  • 2024 - 100%
  • 2023 - 99,99%
  • 2022 - 100%
  • 2021 - 99,99%
  • 2020 - 100%

Availability

The LIMS.eu cloud is distributed across two independent availability zones and designed for an availability of > 99.95%. This corresponds to a downtime of less than 5 hours per year.

Availability Zones are self-contained data centers separated by many miles, with redundant power, networking and connectivity, designed to be isolated from failures in other Availability Zones.

The laboratory database cloud runs in the Amazon AWS data center in Frankfurt and is distributed there in parallel to the availability zones eu-central-1a, eu-central-1b and eu-central-1c. The laboratory database cloud is structured in such a way that it can withstand the simultaneous failure of two availability zones and remain available.

Architektur

User call on the topic of data security
General Data Security Guidelines (ADSR)
NIS 2 - Annex 3
TÜV-zertifizierte Sicherheit für Ihr LIMS

Sicherheit ist Teil unseres Betriebs.

Laborsoftware verarbeitet sensible Daten – Sicherheit ist bei der Labordatenbank daher kein Zusatzfeature, sondern integraler Bestandteil der Architektur.

EU-Datensouveränität TLS 1.3 + AES-256 SSO & MFA inklusive 99,99 % Uptime Backups jede Sekunde

Europäischer Anbieter

Deutsch-österreichisches Unternehmen nach europäischem Recht.

Redundante Cloud-Infrastruktur

Drei unabhängige Verfügbarkeitszonen am Standort Frankfurt.

Verschlüsselung & Zugriffsschutz

Alle Daten verschlüsselt – at rest und in transit, mit klar geregelten Zugriffen.

Sichere Anmeldung

MFA, SSO und Passkeys für eine sichere Authentifizierung.

Audits & Pentests

Regelmäßige interne und externe Sicherheitsaudits sowie Penetrationstests.

Vollständiger Audit-Trail

Alle Aktivitäten lückenlos mit Nutzer- und Zeitstempel dokumentiert.

Als LIMS-Anbieter sind wir nach der aktuellen ISO 27001 zertifiziert – für Datensicherheit, Verfügbarkeit, Verarbeitungsintegrität, Vertraulichkeit & Datenschutz – und erfüllen zudem die Anforderungen der NIS2-Richtlinie.

Frequently asked questions

We operate your laboratory database in the Amazon AWS data center in Frankfurt. With the distribution across the availability zones (AZ) eu-central-1a, eu-central-1b and eu-central-1c, we provide you with a redundant and secure environment for the most sensitive data. In the MySQL-compatible database (Aurora), your data is encrypted and stored separately from other customers using separate accounts. Your files are stored encrypted on Amazon S3. Encryption is done at-rest and in-transit using Advanced Encryption Standard (AES-256). Data residency for all data is EU.
Your data is backed up according to the following backup routine: Incremental backups every second for 3 days Daily full backups on S3 for 7 days Daily full backups to Wasabi with Object Locking Compliance Mode for 90 days Weekly full backups to S3 backups to S3 for unlimited runtime As this routine applies to each of the two availability zones, these four backups are performed twice.
In addition to our comprehensive backup routine, we recommend that you also back up all data locally on your infrastructure. We offer you the following additional backup options for this purpose: Manual backup: Authorized users have the option of initiating and downloading a complete backup at any time. Additional external backup: A complete backup is created daily at a defined time and transferred to a system provided by your IT department.
The off-boarding of customers is carried out according to an established and regularly externally certified checklist. This also includes the secure provision of all your data and the complete deletion of your data from our systems. In this case - as at any other time - you can download a complete backup including all uploads and created documents. Once you have confirmed that you have successfully downloaded this (usually large) backup, we will irrevocably delete all data from our systems 90 days after the end of your use of the laboratory database. You will receive a log of the deletion for your documentation.
The laboratory database is certified by TÜV Rheinland in accordance with ISO 27001, ISO 9001 and TISAX.
Yes. You can find our NIS-2 guide at https://lims.eu/de/nis2, as well as detailed documentation at https://labordatenbank.com/crm/documents/public/185/e850146a55
Yes. LDB Labordatenbank GmbH acts as your data processor within the meaning of the GDPR and the Austrian Data Protection Act, and is committed to complying with all applicable national and European data protection regulations.
No, the Labordatenbank is offered exclusively as a cloud SaaS solution — hosted on AWS in Frankfurt, distributed across three availability zones. This completely removes the operational burden of updates, backups and security from you.
We operate a certified ISMS with a dedicated information security officer, annual risk workshops, external penetration tests at least once a year, mandatory multi-factor authentication for security-critical systems, and a documented supplier management process — we provide the corresponding evidence to customers affected by NIS-2.
Access is granted strictly on a need-to-know basis, is fully logged (audit trail), and is subject to regular internal and external security audits as part of our ISO 27001 certification.
No. We only use AI models that contractually guarantee not to use customer data for training, to encrypt data at rest and in transit, and to hold their own ISO 27001 or SOC 2 Type 2 certification. For the Query Explorer, only the data structure and the question are transmitted — never the data itself.
The Labordatenbank cloud is designed for >99.95% availability (less than 5 hours of downtime per year) and is automatically checked for functionality every 10 minutes. Actual figures between 2020 and 2025 ranged from 99.99% to 100%.
At least once a year, by an external provider. The results are passed directly to our developers and documented in the internal QM directory under "Security Audits".
Every update goes through a change management process with automated validation against defined test cases before rollout. Highly critical vulnerabilities are patched promptly, critical ones are fixed in the next update; customers are informed via update notices.
TLS 1.2/1.3 for data in transit, AES-256-GCM for data at rest, RSA with at least 3,000 bits for asymmetric encryption, and Argon2ID for passwords — aligned with the German BSI's Technical Guideline TR-02102.
MFA is mandatory for security-critical applications — via authenticator app, security key (e.g. YubiKey) or passkey. Alternatively, single sign-on via your existing identity provider is available.
Yes. Sign-in can be handled via single sign-on with your existing identity provider — most commonly Microsoft Entra ID (formerly Azure AD), as well as Okta. Your users log in with their familiar company account, access is managed centrally by your own IT department, and if someone leaves the company, they automatically lose access as soon as their company account is deactivated.
Detected incidents are reported immediately to management and the information security officer, handled according to a defined incident response plan, and finally documented and evaluated in an 8D report.
Yes. All employees receive security-relevant training during onboarding and take part in a cybersecurity training session at least once a year; in the event of acute threats, all employees are additionally informed promptly.
Through a documented supplier management process including NDA, contract review and risk classification. For our external IT/cloud provider, its own ISO 27001 certification additionally satisfies the corresponding ISO 17025 requirement for externally provided services.
Yes, by default all internal and external transmissions run encrypted over HTTPS. An exception is only possible at the customer's explicit request.
Yes. Fixed secure coding guidelines apply (including prepared statements against SQL injection, secure password hashing, CSRF protection), along with regular code reviews and automated checks of all dependencies for known vulnerabilities.
We are. Responsibility for operations, updates, backups and security lies entirely with the Labordatenbank — not with your own IT department. This is verifiably documented, not just claimed — through our own information security officer, annual external audits, and continuous ISO 27001 certification since 2023.
Because information security is our core business here, not a side project alongside daily lab work: more than 15 years of continuous operation, certified to ISO 27001, ISO 9001 and TISAX, annual external penetration tests, and an infrastructure that can withstand the simultaneous failure of two of the three availability zones — an effort that a single lab's IT department realistically cannot deliver on the side.
Through verifiability instead of self-declaration: TÜV Rheinland certification to ISO 27001 and ISO 9001, a passed TISAX assessment, publicly accessible data security policies (ADSR), and a NIS-2 guide with concrete, verifiable measures instead of general statements.