Security Overview
We take the security of your lab data seriously. This page describes the technical and organisational measures we implement to protect your information.
Security at a glance
Encryption
All data encrypted in transit via TLS 1.2+
All data encrypted at rest (AES-256)
Private file storage with signed URLs
Access control
Role-based access control (RBAC)
Row-level security enforced at database level
Multi-tenant org isolation
Infrastructure
Hosted on Vercel (SOC 2 Type II)
Database on Supabase in London (UK)
Storage and application servers both in London
Auditability
Audit log of key actions
Supabase Auth session management
Per-org data isolation
Multi-tenant data isolation
Every piece of data in LevelSixLabs is scoped to an organisation. Database Row-Level Security (RLS) policies are enforced at the database level — not just in application code — ensuring that one organisation cannot access another's data, even in the event of an application bug.
Organisation isolation is enforced by a SQL helper function (auth_organisation_id()) that verifies the caller's identity on every query.
Access control
LevelSixLabs implements a four-tier role hierarchy:
| Role | Capabilities |
|---|---|
| Super Admin | Full access to all data and settings within their organisation |
| Admin | Manage users, equipment, chemicals, bookings |
| Staff | Create and manage their own records within permitted modules |
| Student | View-only access to permitted modules |
Permissions can be further customised per user at a module and action level (view / create / edit / delete / verify / manage). Training-gated equipment bookings enforce additional safeguards.
Encryption
- All data in transit is encrypted using TLS 1.2 or higher
- All data at rest is encrypted using AES-256 by Supabase (managed PostgreSQL on AWS)
- Uploaded files (SDS documents, service certificates) are stored in private Supabase Storage buckets with per-organisation access controls
- Files are served via short-lived signed URLs (a minute to an hour, depending on the file) — never via public URLs
- Authentication tokens are httpOnly, Secure cookies managed by Supabase Auth
Authentication
- Email/password authentication with Supabase Auth
- Google OAuth SSO available. Microsoft/Entra SSO and SAML are not supported today — if your institution requires federated sign-in, tell us before you evaluate us
- Two-step sign-in with an authenticator app (TOTP) is available to every person from Settings, and is asked for at every sign-in once turned on. An admin can reset it for a colleague who loses their phone. It is opt-in per person — there is no organisation-wide enforcement switch yet
- Sessions are automatically refreshed and expired by Supabase
- Password reset via email with time-limited secure tokens
- Email invitations with single-use links
File upload safety
- Uploads are restricted to specific MIME types per feature (PDF, JPEG, PNG, WEBP, XLSX)
- File size limits enforced (25 MB for service records, varies by feature)
- Files are stored in private buckets — not accessible without authentication
- Storage paths include organisation ID to enforce org-level isolation
Security headers
- Content-Security-Policy (CSP) — restricts resource loading to trusted origins
- X-Frame-Options: SAMEORIGIN — prevents clickjacking
- X-Content-Type-Options: nosniff — prevents MIME-sniffing attacks
- Strict-Transport-Security (HSTS) — enforces HTTPS for 2 years
- Referrer-Policy: strict-origin-when-cross-origin
- Permissions-Policy — disables access to camera, microphone, geolocation at the browser level
Incident response
In the event of a data breach affecting personal data, we will notify affected customers and, where required by UK GDPR, the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach.
Compliance
- UK GDPR compliant data handling and processing
- Registered with the Information Commissioner's Office (registration ZC213132)
- Your lab's data — database records and uploaded files — is stored and processed in the UK (London region), application servers included
- Data Processing Agreement (DPA) published in full, no request needed
- Annual security review planned
Read the Data Processing Agreement and the full list of subprocessors — which names every third party involved and where each one processes data, including those outside the UK. For anything else, contact privacy@levelsixlabs.com.
Infrastructure security
| Provider | Certification |
|---|---|
| Vercel (hosting) | SOC 2 Type II, ISO 27001 |
| Supabase (database + auth) | SOC 2 Type II |
| Stripe (payments) | PCI DSS Level 1 |
| Cloudflare (bot protection) | SOC 2 Type II, ISO 27001 |
These certifications are held by the providers we build on. Each provider publishes its own trust page, and the underlying audit reports are theirs to release — several require a non-disclosure agreement or a higher-tier plan before they will hand one over, so if your institution needs a specific report we will tell you honestly whether we can obtain it. To be explicit about our own position: LevelSixLabs Ltd is a young company and does not itself hold SOC 2 or ISO 27001 certification. What we can evidence today is the architecture described on this page — per-organisation isolation enforced in the database, encryption in transit and at rest, audit logging, and certified infrastructure underneath.
LevelSixLabs Ltd
Registered in England and Wales (company number 17377648). Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.
For any questions about this document, contact us at privacy@levelsixlabs.com