Physical security, infrastructure, and certifications

LabKey’s network architecture, system resilience, physical device security, and the ISO certifications obtained by LabKey.

Physical security of the devices

The access point’s electric release contact is integrated inside the control unit, which must be installed in premises not accessible to the public. Authorization logic is governed exclusively by the control unit and never by the peripheral interface device (keypad, NFC reader, QR code reader): this means that tampering with a peripheral device does not make it possible to unlock the access point.

Physical Security

For additional reinforcement, it is possible to:

  • activate a dedicated exit reader, which requires the event to be logged on the way out as well, making it possible to detect anomalous entry/exit sequences;
  • structurally disable any possibility of remote opening via the mobile app, even if an operator mistakenly enables the corresponding flag — ensuring that every logged event stems from an actual physical presence at the reader.

Service continuity, even offline

In the event of a network connectivity interruption, the control unit retains up to a maximum of 2,000 events in local memory, which are automatically transmitted to the cloud platform once the connection is restored, with no data loss.

Network infrastructure under direct control

Unlike solutions that rely on third-party cloud and connectivity providers, LabKey owns its own Autonomous System, registered with RIPE NCC, and directly manages the routing of traffic to its own systems. Data is stored in company-owned data centers, without relying on third-party cloud providers: control of the infrastructure — and of the data it holds — is therefore exclusive and entirely in-house.

All communications between peripheral devices and the cloud platform take place exclusively over the encrypted HTTPS protocol. Access to the management panel is protected by named credentials, with access-point authorizations configurable per individual operator according to a need-to-know criterion.

These characteristics are also relevant for supply chain risk management as required by the NIS2 Directive: fewer third-party intermediaries mean a smaller risk surface.

Business continuity and disaster recovery plans

The technical measures described above are complemented by a documented Business Continuity Plan and Disaster Recovery Plan, which govern service recovery procedures in the event of critical incidents.

Certifications

9001 27001

The LabKey system is developed and operated by an organization — LabKey — certified to the following international standards:

CertificationScope
ISO 9001:2015Quality Management System
ISO/IEC 27001:2022Information Security Management System
ISO/IEC 27017:2015Security of cloud services
ISO/IEC 27018:2025Protection of personal data in cloud services

The certifications are issued by an accredited certification body and represent a solid documentary and organizational safeguard, consistent with the principles of accountability and data protection by design (privacy by design).

In support of this framework, LabKey maintains internal risk management and integrated GDPR/NIS2 compliance documentation (requirements mapping, legal requirements register, risk assessment methodology).

ACN
We are registered with the Italian National Cybersecurity Agency (ACN – Agenzia per la Cybersicurezza Nazionale) and operate in full compliance with the NIS2 Directive, ensuring high standards of security, reliability, and regulatory compliance.

Technical test reports

The LabKey platform and hardware undergo independent technical testing, including electromagnetic compatibility (EMC) tests on the control boards and on the RS-485 communication bus (including line disturbance immunity tests).


Want to review certificates and test reports?

For confidentiality reasons, ISO certificates and technical test reports are not published in full on this site. They are available on request: write to info@labkey.io indicating which documentation you are interested in (e.g., ISO 27001 certificate, RS-485 EMC report, Business Continuity Plan) and we will send it to you.