Regulatory compliance and data protection
How LabKey applies GDPR principles and the requirements of the NIS2 Directive in the design of the platform.
LabKey is not just a physical access control system (door and gate entry hardware) — not to be confused with IT/cybersecurity access control (IAM) — it is a platform designed from the ground up (“by design”) to meet the security, traceability, and regulatory compliance requirements demanded by the most demanding contexts — from facilities handling sensitive personal data to organizations subject to digital infrastructure security obligations.
This section brings together, in a concise and verifiable form, the technical and organizational measures that characterize the platform:
| Area | Measure |
|---|---|
| Badge identifiers | Never exposed in plain text: encryption starting from the tag’s physical UID |
| Communications | Exclusively over encrypted HTTPS channel |
| Network infrastructure | Own Autonomous System, no third-party connectivity intermediaries |
| Data center | Company-owned infrastructure, no third-party cloud providers |
| Attendance log retention | 90 days, automatic deletion |
| System log retention | 6 months, automatic rotation |
| Business continuity | Documented Business Continuity Plan and Disaster Recovery Plan |
| Certifications | ISO 9001:2015 · ISO/IEC 27001:2022 · ISO/IEC 27017:2015 · ISO/IEC 27018:2025 |

📄 Certificates and technical test reports (including electromagnetic compatibility tests) are available on request. Write to info@labkey.io indicating the document you are interested in: we will reply with the requested documentation.
How LabKey applies GDPR principles and the requirements of the NIS2 Directive in the design of the platform.
LabKey’s network architecture, system resilience, physical device security, and the ISO certifications obtained by LabKey.