Security & compliance
Your account
Section titled “Your account”- Passwords are hashed with scrypt; we never see them. Sessions are signed cookies.
- Each client sees only its own orders, products, documents and ledger. Search and every page enforce this on the server.
- LabShipped staff can open a client view to help you; those actions are logged.
Documents you upload
Section titled “Documents you upload”Signer ID and EIN documents are stored in our database, encrypted at rest by the provider, and are only viewable by LabShipped compliance staff through an authenticated, non-cached endpoint. They are never shared with third parties and are deleted on request after the account closes and the retention period ends.
We never hold your bank credentials. Bank accounts are linked through a bank-link provider that returns a token; we store the institution and the last four digits. Card details go to the card processor; we store the brand, last four and expiry.
Your customers
Section titled “Your customers”We receive the name, address and email needed to ship an order. We use them for fulfillment, tracking write-back and carrier claims only. We do not market to your customers or share their data.
Products
Section titled “Products”We handle lyophilized, research-use-only peptides and related supplies. We do not handle controlled substances, reconstituted liquids, or products making therapeutic claims, and we’ll ask you to change label wording that does.
Records
Section titled “Records”Lot, batch and shipment records are kept for at least three years and are available to you on request. Agreement signatures are stored with version, time, IP and a hash of the signed text.
Questions: [email protected].