Skip to content
Trust & Security

Built for university and laboratory procurement.

One page summarising LevelSixLabs's security posture, data protection commitments, AI transparency, and the documents your procurement team needs.

At a glance

Four pillars that underpin every line of code we ship.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest. Files served via short-lived signed URLs only.

UK-resident data

Records, files and backups all in London, and the servers that read them run there too.

Row-level security

Database-level isolation between organisations. Enforced regardless of application bugs.

Audit logging

Significant actions logged and kept for the life of your organisation by default; admins can set a retention period of 12 months or longer, after which older entries are pruned. Admins can review their org's history.

Compliance status

We are honest about where we are. Here is what is in place today and what we are working towards. For live availability, see the service status page.

Live

UK GDPR aware

Lawful basis tracked, data subject rights honoured, retention defined.

Live

Encryption in transit & at rest

TLS 1.2+ and AES-256 across the stack.

Live

RBAC + multi-tenant isolation

4 roles, 12 modules × 6 actions, RLS-enforced.

Live

DPA published

Article 28 DPA published in full at /dpa, with a Word version. Executable on your institution's own paper on request.

Live

Audit logging

Significant actions captured and kept for the life of the organisation by default; an admin can set a retention period of 12 months or longer, after which older entries are pruned.

Live

ICO registered

LevelSixLabs Ltd is registered with the UK Information Commissioner's Office, reference ZC213132.

Planned

ISO 27001 readiness

Policy framework alignment planned as our customer base grows.

Planned

SOC 2 Type I

Planned once customers need an attested report.

Planned

External penetration test

Planned with an accredited (CREST) tester before the first paid contract; the report will be available to customers on request.

Service commitments

What you can rely on day to day. We keep these deliberately plain — no padded promises we can't keep at this stage.

Support response

Email support answered within one business day. Issues that stop a lab working are prioritised the same day during UK business hours.

Data residency

Your lab's records and uploaded files live in the UK (London region) via Supabase, any backups stay there, and the application servers run in London as well. Payments, email delivery, error monitoring, usage analytics and the optional AI label scan are handled by providers outside the UK, each named — with what it sees — on our Subprocessors page.

Vendor continuity

Any admin can self-serve a complete export of the organisation's records — 22 sheets in one Excel workbook — at any time, without asking us. Individual modules also export to CSV and PDF. Uploaded files (SDS PDFs, certificates) are not yet included in the bulk export and are retrieved separately on request. Should the service wind down, you receive notice and an export window.

Documents

Everything your IT, compliance, and procurement teams might ask for.

Frequently asked by procurement

If your question isn't here, just ask.

Where is our data stored?

In the UK. Your lab's records and uploaded files are stored in Supabase's London region, and the application servers that read and write them run in London too (Vercel's lhr1 region). Any backups stay in that same region. Note that London is a UK region, not an EU one — the provider region code reads "eu-west-2" for historical reasons, but the data centre is in Britain. A handful of named support services operate outside the UK and each only ever sees a narrow slice of data: Stripe for payments, Resend for email delivery, Sentry for error reports and PostHog for usage analytics (both in Germany), and — only if you use the optional label scan — Anthropic. Our content delivery also runs on a global edge network, so a request may pass through a server near you before reaching London. Each provider is listed, with what it processes and where, on our Subprocessors page.

Do you train AI models on our data?

No. Anthropic does not use LevelSixLabs customer data to train its models, and we do not train any AI models on customer data ourselves. AI features are optional and explicit — see our AI Transparency Statement.

Can we get a DPA?

Yes — it is published in full at /dpa, so your DPO can read it before you ever contact us. Email privacy@levelsixlabs.com if your institution needs it executed on their own paper.

Is LevelSixLabs ISO 27001 / SOC 2 certified?

Not yet — we are an early-stage platform. Our infrastructure providers (Vercel, Supabase, Stripe) are SOC 2 Type II or equivalent. We are happy to share what we have today and our roadmap for formal certification.

Can our IT team review your security setup?

Absolutely — and most of it is already public. The security overview, DPA, Article 30 record of processing, subprocessor list and incident-response procedure are all published in full, so your IT team can read them before contacting anyone. For a completed security questionnaire, an architecture walkthrough, or anything on your institution's own template, email security@levelsixlabs.com and we will turn it around.

How do you handle a data breach?

We notify affected customers without undue delay. Where required by UK GDPR, we notify the ICO within 72 hours of becoming aware of a breach.

Talk to our security team

Procurement review? Security questionnaire? Architecture diagram? Email us — we typically respond within one working day.