Technical & Organisational Measures
Version 1.0
Effective: 21 July 2026
Last updated: 21 July 2026
This document describes the technical and organisational security measures (TOMs) implemented by AB-Labz to protect customer and Experiment Data, as required by GDPR Article 32 and the Data Processing Agreement.
Security Measures Overview
Data in Transit
- All connections to the platform and API are encrypted using TLS 1.2 or higher.
- HTTPS is enforced; HTTP connections are automatically redirected.
- HSTS (HTTP Strict Transport Security) headers are applied.
Data at Rest
- Storage volumes are encrypted at rest using AES-256 (provided by DigitalOcean infrastructure).
- Database backups are encrypted.
Infrastructure and Hosting
- All platform data is stored on DigitalOcean infrastructure in Frankfurt, Germany (EU).
- Network access to production systems is restricted by firewall rules to authorized IP ranges.
- The platform runs in isolated compute environments.
Access Control
- Access to production systems follows the principle of least privilege.
- Administrative access is restricted to authorized personnel only and requires strong authentication.
- All administrative access is logged with timestamps and user identity.
- Access credentials are never shared; individual accounts are used for each person with access.
Customer Data Isolation
- Customer Workspaces are logically isolated; one customer cannot access another's data through the platform interface.
- API keys are scoped to individual customer accounts.
- Experiment Data from different customers is stored in separate database records with enforced access controls.
Data Lifecycle and Deletion
- CSV uploads are deleted from active storage at the end of the analysis session.
- API-submitted datasets are automatically deleted after a maximum of 14 days.
- Workspace data is deleted 30 days after license expiry.
- Backup copies are retained on a 30-day rolling basis, then purged.
Backup and Recovery
- Automated database backups are performed daily.
- Backups are stored in an encrypted state for a 30-day rolling window.
- Recovery procedures are tested periodically.
Logging and Monitoring
- Access logs, authentication events, and administrative actions are captured and retained for 12 months.
- Logs are stored separately from production data.
- Anomalous access patterns are monitored.
Incident Response
- Documented incident response procedures are maintained internally.
- Customers are notified within 72 hours of a confirmed personal data breach.
- See Incident Response for the customer-facing notification process.
Data Minimisation and Pseudonymisation
- The platform is designed to operate on pseudonymized or aggregated data.
- The Acceptable Use Policy prohibits submission of directly identifiable personal data or special category data without prior agreement.
- AI features receive aggregated analysis results, not raw Experiment Data.
Updates to TOMs
AB-Labz may update these measures over time to reflect improvements in security practices or infrastructure changes. The Operator will not reduce the overall level of protection provided by these measures without notifying affected customers.
Contact
For questions about security measures, contact [email protected].