Built for university and laboratory procurement.
One page summarising LevelSixLabs's security posture, data protection commitments, AI transparency, and the documents your procurement team needs.
At a glance
Four pillars that underpin every line of code we ship.
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest. Files served via short-lived signed URLs only.
UK-resident data
Records, files and backups all in London, and the servers that read them run there too.
Row-level security
Database-level isolation between organisations. Enforced regardless of application bugs.
Audit logging
Significant actions logged and kept for the life of your organisation by default; admins can set a retention period of 12 months or longer, after which older entries are pruned. Admins can review their org's history.
Compliance status
We are honest about where we are. Here is what is in place today and what we are working towards. For live availability, see the service status page.
UK GDPR aware
Lawful basis tracked, data subject rights honoured, retention defined.
Encryption in transit & at rest
TLS 1.2+ and AES-256 across the stack.
RBAC + multi-tenant isolation
4 roles, 12 modules × 6 actions, RLS-enforced.
DPA published
Article 28 DPA published in full at /dpa, with a Word version. Executable on your institution's own paper on request.
Audit logging
Significant actions captured and kept for the life of the organisation by default; an admin can set a retention period of 12 months or longer, after which older entries are pruned.
ICO registered
LevelSixLabs Ltd is registered with the UK Information Commissioner's Office, reference ZC213132.
ISO 27001 readiness
Policy framework alignment planned as our customer base grows.
SOC 2 Type I
Planned once customers need an attested report.
External penetration test
Planned with an accredited (CREST) tester before the first paid contract; the report will be available to customers on request.
Service commitments
What you can rely on day to day. We keep these deliberately plain — no padded promises we can't keep at this stage.
Support response
Email support answered within one business day. Issues that stop a lab working are prioritised the same day during UK business hours.
Data residency
Your lab's records and uploaded files live in the UK (London region) via Supabase, any backups stay there, and the application servers run in London as well. Payments, email delivery, error monitoring, usage analytics and the optional AI label scan are handled by providers outside the UK, each named — with what it sees — on our Subprocessors page.
Vendor continuity
Any admin can self-serve a complete export of the organisation's records — 22 sheets in one Excel workbook — at any time, without asking us. Individual modules also export to CSV and PDF. Uploaded files (SDS PDFs, certificates) are not yet included in the bulk export and are retrieved separately on request. Should the service wind down, you receive notice and an export window.
Documents
Everything your IT, compliance, and procurement teams might ask for.
Security Overview
Infrastructure, encryption, access controls, incident response.
Privacy Policy
How we collect, use and protect personal data under UK GDPR.
Terms of Service
Contractual terms, AUP, liability, governing law.
Cookie Policy
What cookies we set and how you can control them.
Subprocessor List
Every third party that processes your data.
Data Processing Agreement
Article 28 DPA governing how we process data for you. Word version available.
Record of Processing
Our Article 30 data register — what we process, why, how long. Word version available.
Incident Response
How we detect, contain and report breaches, with 72-hour notification. Word version available.
AI Transparency
How AI label scanning works, its limits, your controls.
Accessibility Statement
WCAG 2.2 AA progress, what we have tested, and the limitations we know about.
Privacy Request
Submit a data access, correction, or deletion request.
Frequently asked by procurement
If your question isn't here, just ask.
Where is our data stored?
In the UK. Your lab's records and uploaded files are stored in Supabase's London region, and the application servers that read and write them run in London too (Vercel's lhr1 region). Any backups stay in that same region. Note that London is a UK region, not an EU one — the provider region code reads "eu-west-2" for historical reasons, but the data centre is in Britain. A handful of named support services operate outside the UK and each only ever sees a narrow slice of data: Stripe for payments, Resend for email delivery, Sentry for error reports and PostHog for usage analytics (both in Germany), and — only if you use the optional label scan — Anthropic. Our content delivery also runs on a global edge network, so a request may pass through a server near you before reaching London. Each provider is listed, with what it processes and where, on our Subprocessors page.
Do you train AI models on our data?
No. Anthropic does not use LevelSixLabs customer data to train its models, and we do not train any AI models on customer data ourselves. AI features are optional and explicit — see our AI Transparency Statement.
Can we get a DPA?
Yes — it is published in full at /dpa, so your DPO can read it before you ever contact us. Email privacy@levelsixlabs.com if your institution needs it executed on their own paper.
Is LevelSixLabs ISO 27001 / SOC 2 certified?
Not yet — we are an early-stage platform. Our infrastructure providers (Vercel, Supabase, Stripe) are SOC 2 Type II or equivalent. We are happy to share what we have today and our roadmap for formal certification.
Can our IT team review your security setup?
Absolutely — and most of it is already public. The security overview, DPA, Article 30 record of processing, subprocessor list and incident-response procedure are all published in full, so your IT team can read them before contacting anyone. For a completed security questionnaire, an architecture walkthrough, or anything on your institution's own template, email security@levelsixlabs.com and we will turn it around.
How do you handle a data breach?
We notify affected customers without undue delay. Where required by UK GDPR, we notify the ICO within 72 hours of becoming aware of a breach.
Talk to our security team
Procurement review? Security questionnaire? Architecture diagram? Email us — we typically respond within one working day.