iLab Technical Security Measures

© Agilent Technologies, Inc. 2026

1. Scope and security objectives

iLab Operations Software is a web-based laboratory operations and resource management service used by research institutions, shared resource facilities, laboratories, and related organizations. This public overview describes security practices for the iLab service and supporting operational safeguards at a high level.

Agilent designs and operates iLab security practices to support three primary objectives:

2. Security management approach

Agilent applies a layered, risk-based security approach that combines governance, technical safeguards, operational procedures, and monitoring. Security practices are aligned with recognized industry frameworks and are reviewed as part of Agilent's broader information security and risk management activities.

Security functionHow it is applied
IdentifySecurity-relevant systems, data, integrations, vendors, and regulatory expectations are assessed to understand risk and define appropriate safeguards.
ProtectAdministrative, technical, and operational controls are applied to reduce unauthorized access, misuse, service disruption, and data exposure.
DetectMonitoring and logging are used to identify suspicious activity, operational issues, and potential security events.
RespondSecurity concerns are assessed and managed through defined incident response and escalation processes.
RecoverBackup, restoration, continuity, and disaster recovery capabilities are maintained to support service resilience.

3. Infrastructure, hosting, and service resilience

iLab is hosted using reputable cloud infrastructure and service providers that maintain security and availability controls appropriate for enterprise cloud services. Physical data center controls are managed by the hosting provider and are supplemented by Agilent security governance and operational oversight.

4. Identity, authentication, and access control

Access to iLab is controlled through authentication and authorization mechanisms designed to ensure that users can access only the functions and information appropriate to their roles and permissions.

MeasureCustomer-facing description
Unique user accessUser access is associated with unique login identifiers or customer-managed single sign-on where configured.
Single sign-on supportCustomers may integrate institutional identity providers with iLab using standard federated authentication methods.
Role-based authorizationPermissions are assigned based on role, business need, and customer or administrator configuration.
Least privilegeAdministrative and support access is limited to authorized personnel with a defined business need.
Session protectionSession controls help reduce risk when a user leaves an active session unattended.
Provisioning and deprovisioningAccess management processes support onboarding, account changes, and access removal when access is no longer required.

5. Application security and secure development

Agilent integrates security into the iLab software development lifecycle. New and changed functionality is reviewed, tested, and deployed through controlled processes intended to reduce risk and preserve service reliability.

6. Data protection and encryption

Agilent applies technical and operational safeguards to protect customer data processed by iLab. Controls are designed to protect information during transmission, storage, processing, and support activities.

AreaPublic description
Encryption in transitWeb traffic and administrative connections use encrypted protocols where applicable.
Encryption at restData protection mechanisms are applied to backups and storage consistent with Agilent security requirements and service design.
Data segregationCustomer and user permissions support logical separation of information within the application.
Data handlingAgilent personnel access customer-generated content only for authorized business purposes, such as providing support or operating the service.
Retention and recoveryBackup and recovery processes are designed to support continuity while aligning to documented operating requirements.

7. Monitoring, logging, and auditability

Agilent uses logging and monitoring to support service operation, security assessment, troubleshooting, and investigation. Logs are protected from unauthorized modification and reviewed or analyzed based on operational and security needs.

8. Vulnerability, patch, and threat management

Agilent maintains processes for identifying, evaluating, prioritizing, and addressing vulnerabilities that could affect iLab or supporting environments. Vulnerability management activities are informed by internal security processes, vendor notifications, security tooling, and threat intelligence.

9. Incident response and reporting

Agilent maintains incident response processes to assess and respond to suspected or confirmed security events. Response activities may include triage, investigation, containment, remediation, communication, and lessons learned, depending on the nature and impact of the event.

Reporting security concerns

If you identify or suspect a security issue related to Agilent products, services, or websites, notify your Agilent representative or use the appropriate Agilent security reporting channel. Include the product or service name, a description of the issue, and the potential impact to support timely assessment.

10. Third-party and supplier safeguards

Agilent evaluates suppliers and third-party services with access to systems or data based on risk and applicable security requirements. Supplier security controls, assurance reports, and contractual obligations are reviewed where appropriate for the services used to deliver or support iLab.

11. Customer responsibilities

Security is shared between Agilent and each customer organization. Customers are responsible for managing their own users, institutional identity systems, local devices, network access, and configuration choices that affect access to their iLab environment.

12. Summary of technical security measures

Control areaPublic security measure
GovernanceRisk-based policies, industry-aligned security practices, periodic review, and defined ownership.
Access controlUnique user access, role-based permissions, least privilege, SSO support, and controlled administrative access.
Application securitySecure development lifecycle, code review, testing, validation, vulnerability management, and controlled releases.
Data protectionEncryption in transit, data segregation, backup protection, controlled support access, and appropriate retention practices.
AvailabilityCloud resilience, monitoring, backups, restoration processes, and disaster recovery planning.
Monitoring and auditAuthentication logging, application activity logging, infrastructure monitoring, and security event review.
Incident responseDefined escalation, investigation, containment, remediation, and post-incident improvement activities.
Supplier securityRisk-based review of third parties and cloud providers that support iLab services.

13. Important note

This document is provided for general informational purposes and does not create or modify any contractual obligation unless expressly incorporated into a written agreement signed by Agilent. The security controls described may vary based on product configuration, customer-selected integrations, hosting region, regulatory requirements, and service updates.

Agilent may update this overview from time to time to reflect changes in security practices, technology, legal requirements, or service operations.