IT security

Security for your most sensitive data

LDB LIMS IT security: protection against third-party access | Data backups | Availability

Protection against third-party access

A web application firewall (WAF) protecting the LDB cloud ensures that LDB can only be accessed through encrypted connections. Access to the firewall is controlled by a load balancer, which distributes incoming requests across multiple application servers in different availability zones and permits only encrypted HTTPS connections with RSA encryption and a key length of 2,048 bits.

Users sign in to LDB with a login, password and an additional security factor (MFA, multi-factor authentication), using authenticator apps such as Google Authenticator, Microsoft Authenticator, Authy or KeePassXC, or security keys such as YubiKeys, SoloKeys or Google Titan. Passwords are hashed using the Argon2id algorithm, which remains unbroken according to the current state of the art.

LDB supports signing in with a passkey. Passkeys provide a new way to sign in without a password, offering greater security than a password plus MFA and a faster, more convenient sign-in experience.

LDB also supports single sign-on (SSO). In this case, authentication is handled by an identity provider such as Microsoft Azure AD or Okta. Users can sign in to LDB quickly and securely using their existing company account.

Every sign-in attempt is logged with its IP address and time. If someone repeatedly attempts to sign in with an incorrect password, LDB blocks sign-in for a defined period.

Data is stored encrypted in the LDB cloud in a MySQL-compatible database (Aurora). Each LDB instance uses its own database and separate database accounts, technically preventing access to another LDB customer’s data.

All databases are stored encrypted. This prevents unauthorised parties from reading the data or changing it without detection; changing individual bytes would render the entire database unreadable.

Databases are encrypted with AES-256-GCM, a symmetric algorithm based on the Advanced Encryption Standard (AES-256) and Galois/Counter Mode (GCM), using a 256-bit key.


Backups

  • Redundant database cluster across 3 availability zones
  • Incremental backups every second, retained for 3 days
  • Daily full backups on S3, retained for 7 days
  • Weekly backups on S3, retained indefinitely
  • Additional backups in an AWS-independent backup system in the Netherlands, with Object Lock in Compliance mode for 90 days
  • Optional: automated daily backups on the customer’s premises

LDB is continuously backed up in full to Amazon S3. To provide our customers with complete security, LDB creates an incremental backup every second. A full backup is also created every day.

All daily backups are retained for one week. After one week, one full backup per week is retained until further notice, for at least the next 10 years.

The backup system is designed for 99.999999999% data durability over one year. This reliability level corresponds to an expected annual data loss of 0.000000001%. This durability is achieved by distributing each backup redundantly across three independent data centres.

All backups are stored encrypted, with a separate key for each backup. All keys are encrypted with a dedicated master key that is regularly changed. Backups are also encrypted using the 256-bit Advanced Encryption Standard (AES-256). No practically feasible attack against this method is known.


LDB cloud availability in recent years:
  • 2025 - 99.99%
  • 2024 - 100%
  • 2023 - 99.99%
  • 2022 - 100%
  • 2021 - 99.99%
  • 2020 - 100%

Availability

The LDB cloud is distributed across three independent availability zones and designed for availability greater than 99.95%. This corresponds to less than 5 hours of downtime per year.

Availability zones are independent data centres separated by many kilometres, with redundant power supplies, networking and connectivity. They are designed to be isolated from failures in other availability zones.

The LDB cloud runs in Amazon AWS’s Frankfurt data centre region, distributed in parallel across the eu-central-1a, eu-central-1b and eu-central-1c availability zones. It is designed to withstand the simultaneous failure of two availability zones and remain available.

Architecture

User call on data security
General Data Security Guidelines (ADSR)
NIS2 – Annex 3
TÜV-certified security for your LIMS

Security is part of our LIMS.

Laboratory software processes sensitive data. At LDB, security is an integral part of the architecture.

EU data sovereignty TLS 1.3 + AES-256 SSO & MFA included 99.99% uptime Backups every second

European provider

A German-Austrian company governed by European law.

Redundant cloud infrastructure

Three independent availability zones in Frankfurt.

Encryption & access protection

All data is encrypted at rest and in transit, with clearly defined access controls.

Secure sign-in

MFA, SSO and passkeys for secure authentication.

Audits & penetration tests

Regular internal and external security audits and penetration tests.

Complete audit trail

Every activity is documented with user details and a timestamp.

As a LIMS provider, we are certified to the current ISO 27001 standard for data security, availability, processing integrity, confidentiality and data protection. We also meet the requirements of the NIS2 Directive.

Frequently asked questions

We operate your LDB instance in Amazon AWS’s Frankfurt data centre. Distribution across the eu-central-1a, eu-central-1b and eu-central-1c availability zones provides a redundant, secure environment for highly sensitive data. Your data is stored encrypted in the MySQL-compatible Aurora database, separated from other customers by individual accounts. Your files are stored encrypted on Amazon S3. Encryption at rest and in transit uses the Advanced Encryption Standard (AES-256). All data resides in the EU.
Your data is protected by the following backup routine: incremental backups every second retained for 3 days, daily full backups on S3 retained for 7 days, daily full backups on Wasabi with Object Lock in Compliance mode retained for 90 days, and weekly full backups on S3 retained indefinitely. Since this routine applies to each of the two availability zones, each of these four backups is performed twice.
In addition to our comprehensive backup routine, we recommend backing up all data locally on your own infrastructure. We offer the following additional backup options: Manual backup: authorised users can initiate and download a full backup at any time. Additional external backup: a full backup is created daily at a defined time and transferred to a system provided by your IT department.
Customer offboarding follows an established checklist that is regularly externally certified. This includes securely providing all your data and completely deleting your data from our systems. In this situation, as at any other time, you can download a full backup including all uploads and generated documents. Once you confirm that you have successfully downloaded this usually large backup, we permanently delete all data from our systems 90 days after your use of LDB ends. You receive a deletion report for your records.
LDB is certified by TÜV Rheinland to ISO 27001, ISO 9001 and TISAX.
Yes. You can find our NIS2 guide at https://lims.eu/en/nis2 and detailed documentation at https://labordatenbank.com/crm/documents/public/185/e850146a55
Yes. LDB Labordatenbank GmbH acts as the processor of your data under the GDPR and the Austrian Data Protection Act and undertakes to comply with all applicable national and European data protection requirements.
No. LDB is offered exclusively as a cloud SaaS solution, hosted on AWS in Frankfurt and distributed across three availability zones. This fully relieves you of the operational work involved in updates, backups and security.
We operate a certified information security management system (ISMS) with a dedicated information security officer, annual risk workshops, external penetration tests at least once a year, mandatory multi-factor authentication for security-critical systems and a documented supplier management process. We provide evidence of these measures to customers affected by NIS2.
Access is granted strictly on a need-to-know basis, fully recorded in the audit trail and included in regular internal and external security audits as part of ISO 27001 certification.
No. We use only AI models whose providers contractually commit not to use customer data for training, to encrypt data at rest and in transit, and to hold ISO 27001 or SOC 2 Type 2 certification themselves. The Query Explorer also never transmits the data itself, only the data structure and the question.
The LDB cloud is designed for availability greater than 99.95%, corresponding to less than 5 hours of downtime per year, and is automatically checked for functionality every 10 minutes. Actual availability between 2020 and 2025 ranged from 99.99% to 100%.
At least annually, by an external provider. Results are passed directly to the developers and stored as documented records under “Security Audits” in the internal QM directory.
Every update goes through change management with automated validation against defined test cases before rollout. Highly critical vulnerabilities are patched promptly; critical vulnerabilities are resolved in the next update. Customers are informed through update notices.
TLS 1.2/1.3 for data in transit, AES-256-GCM for data at rest, RSA with at least 3,000 bits for asymmetric encryption and Argon2id for passwords, guided by the BSI Technical Guideline TR-02102.
MFA is mandatory for security-critical applications, using an authenticator app, a security key such as a YubiKey, or a passkey. Alternatively, single sign-on through your existing identity provider is available.
Yes. Users can sign in through single sign-on with your existing identity provider, particularly Microsoft Entra ID (formerly Azure AD), as well as Okta. Your users sign in with their familiar company account, and your own IT team centrally manages access. When an employee leaves the company, access is automatically revoked as soon as their company account is deactivated.
Detected incidents are reported immediately to management and the information security officer, handled according to a defined incident response plan, and then documented and evaluated in an 8D report.
Yes. All employees receive security-related training during onboarding and participate in cybersecurity training at least annually. All employees are also informed promptly when acute threats arise.
Through a documented supplier management process, including non-disclosure agreements, contract reviews and risk classification. For external IT and cloud service providers, their own ISO 27001 certification also fulfils the corresponding ISO 17025 requirement for externally provided services.
Yes. By default, all internal and external transfers are encrypted using HTTPS. An exception is possible only at the customer’s explicit request.
Yes. Defined secure coding guidelines apply, including prepared statements to prevent SQL injection, secure password hashing and CSRF protection, alongside regular code reviews and automated checks of all dependencies for known vulnerabilities.
We are. Responsibility for operation, updates, backups and security lies entirely with LDB, rather than your own IT department. This is verifiably documented through a dedicated information security officer, annual external audits and continuous ISO 27001 certification since 2023.
Because information security is a core business activity here, rather than a side project alongside daily laboratory work: more than 15 years of continuous operation, ISO 27001, ISO 9001 and TISAX certification, annual external penetration tests and infrastructure that withstands the simultaneous failure of two of the three availability zones. This is a level of effort that an individual laboratory’s IT team cannot realistically provide alongside its other work.
Through verifiable evidence rather than self-declaration: TÜV Rheinland certification to ISO 27001 and ISO 9001, a successfully completed TISAX assessment, publicly accessible General Data Security Guidelines (ADSR) and an NIS2 guide with specific, verifiable measures rather than general statements.

Our customers

Certified to

LDB LIMS is ISO 27001-certified laboratory software

Preferred LIMS partner

VUP - Verband unabhängiger Prüflabore