LabPi trust
Security and compliance
Last updated 3 October 2026
LabPi gives a laboratory the records, access controls, and signatures an assessor expects to see. The standards on this page apply to the lab. LabPi supports them. A subscription does not accredit the lab, certify the software, or replace the quality system you run.
How to read this page
Each name below is a requirement on the laboratory, or on the way health information is handled. LabPi supplies the records, access controls, and signatures that support an assessment. Accreditation and certification stay with the laboratory.
A signed order, data-processing addendum, or business associate agreement controls if it conflicts with this page. Personal information on the website is covered in the Privacy Policy.
ISO/IEC 17025
ISO/IEC 17025 is the international standard for the competence of testing and calibration laboratories. Accreditation bodies assess the laboratory against it. In India, NABL is one of those bodies. NABL is not a second standard beside ISO/IEC 17025.
LabPi supports that assessment with:
- Sample traceability from accession through report
- Method records and uncertainty of measurement
- QC rules, proficiency-testing records, and training records
- An audit trail of changes to regulated records
Using LabPi does not accredit the laboratory. The lab still validates methods, calibrates equipment, trains people, and hosts the assessment.
FDA 21 CFR Part 11
21 CFR Part 11 is the FDA rule for electronic records and electronic signatures. It applies when a lab keeps or submits records electronically under an FDA requirement. The official name is “Electronic Records; Electronic Signatures.”
LabPi includes controls that support those requirements:
- Time-stamped audit trails with user and reason
- Role-based access and authority checks
- Electronic signatures linked to the record, with the meaning of the signature
Part 11 compliance is the laboratory’s, after the system is validated for the way that lab uses it. LabPi does not complete that validation by itself.
CLIA, CAP, and HIPAA
CLIA certifies clinical laboratories in the United States. CAP, the College of American Pathologists, accredits clinical laboratories. Both look at the lab’s quality system, not at a software vendor’s certificate. LabPi supports those programs with order and result records, QC, competency records, and an audit trail.
HIPAA is the US health-privacy law for protected health information. When a lab is a covered entity or a business associate, LabPi provides access control, encryption in transit, and logging designed for that data. A business associate agreement is part of the customer agreement when the lab needs one. Those safeguards do not, by themselves, make a laboratory HIPAA compliant.
GLP and GMP
Good Laboratory Practice and Good Manufacturing Practice are different FDA regimes. GLP covers nonclinical laboratory studies. GMP covers manufacturing, including QC laboratories that release product. LabPi’s audit trail, access control, and electronic signatures support the record expectations in both. LabPi is not a GMP-certified manufacturer, and the product is not a substitute for the lab’s quality system.
Platform security
LabPi is a multi-tenant cloud platform. The measures below match what the product and the Privacy Policy already describe:
- Logical isolation of each customer tenant
- Role-based access, with SSO and MFA available at the tenant level
- Encryption in transit
- Logging of security-relevant activity
- Administrative and organizational controls around who on our side can access production
No method of transmission or storage is perfectly secure. Customers administer their own users, including who they invite and how passwords are protected. Details of personal-information handling are in the Privacy Policy.
What stays with your lab
Across these programs, the laboratory still owns:
- Method validation and ongoing quality control
- Equipment calibration and personnel competency
- User administration and approval of who may sign
- Computer-system validation for the lab’s intended use, where Part 11 or GxP requires it
- The relationship with the accreditor, the FDA, or the clinical certification agency
Contact
Security questions: security@labpi.io
Privacy requests: privacy@labpi.io
LabPi Technologies, Inc. Product controls for signatures, audit trails, and quality records are also described under Quality, Compliance & Smart Search.
