Security Policy

Version 1.0 Effective: 21 July 2026 Last updated: 21 July 2026

This Security Policy describes AB-Labz's approach to protecting the platform and customer data. For the detailed list of specific controls, see Technical & Organisational Measures.

1. Hosting and Infrastructure

The AB-Labz platform runs on DigitalOcean infrastructure in Frankfurt, Germany (European Union). DigitalOcean maintains SOC 2 Type II and ISO 27001 certifications for its data centers and infrastructure services. Customer data does not leave the EU as a result of hosting.

DigitalOcean's security documentation is available at digitalocean.com/legal/certifications.

2. Encryption

  • All communication between clients and the platform uses TLS 1.2 or higher. Plain HTTP is rejected.
  • Database storage and backup volumes are encrypted at rest using AES-256.
  • API keys and credentials are stored using appropriate cryptographic hashing; plaintext secrets are never stored.

3. Access Controls

  • Access to production infrastructure is restricted to authorized personnel via SSH key authentication; password authentication is disabled.
  • Production access follows the principle of least privilege. Personnel are granted only the minimum access required for their role.
  • All administrative access is logged.
  • Customer Workspaces are logically isolated. Platform users cannot access data belonging to other customers.

4. Vulnerability Management

  • Dependencies are monitored for known vulnerabilities and updated on a regular basis.
  • Operating system and runtime patches are applied promptly.
  • The platform architecture is reviewed periodically to identify and address security risks.

5. Incident Response

AB-Labz maintains documented incident response procedures for detecting, containing, and recovering from security incidents. Customers affected by a personal data breach are notified within 72 hours. See Incident Response.

6. Responsible Disclosure

If you believe you have discovered a security vulnerability in the AB-Labz platform, please report it responsibly:

  • Email [email protected] with a description of the vulnerability, steps to reproduce, and your assessment of impact.
  • Do not publicly disclose the vulnerability until AB-Labz has had a reasonable opportunity to investigate and remediate (typically 90 days).
  • Do not access, modify, or delete customer data as part of your testing.

We will acknowledge receipt within 3 business days and keep you informed of the investigation progress. We appreciate responsible disclosures and will credit researchers who follow this process.

7. Customer Responsibilities

Customers share responsibility for the security of their use of the platform:

  • Use strong, unique passwords for AB-Labz accounts.
  • Protect API keys and license credentials; do not share them externally.
  • Report any suspected unauthorized access to your account promptly.
  • Ensure Experiment Data submitted to the platform is appropriately pseudonymized as required by the Acceptable Use Policy.

8. Contact

For security enquiries or to report a vulnerability, contact [email protected].