Skip to content

Security

Security and data

How ConductLaboratory protects accounts, booking records, and cost details.

Last updated October 7, 2026

Sign-in

Everyone signs in with a ConductScience account. ConductLaboratory accepts only accounts with a verified email address. Passwords, password resets, and email verification are handled by ConductScience Auth, not by this app.

Sessions use secure, HTTP-only cookies. A session ends after 7 days or when you sign out.

Who can see and change what

  • Owners and managers set equipment rules, rates, training access, and approvals, and see every booking in their core.
  • Researchers book for themselves and see their own costs.
  • Viewers can see the schedule but cannot change it.

The paying account, purpose, and cost of a booking are visible only to the person who booked and the core's managers. Other members see when a resource is taken and by whom.

Records of changes

Scheduling changes are recorded with who made them and when, in the same database transaction as the change. Usage corrections require a reason, and the original reservation times stay on record.

Hosting and storage

Data is stored in a managed PostgreSQL 17 database from Neon in the AWS US East (N. Virginia) region. The database can be restored to any point in the previous 24 hours.

The app runs on Vercel and is served only over HTTPS, with HTTP Strict Transport Security turned on.

Service providers

ProviderWhat it does
VercelHosts the application
NeonManaged PostgreSQL database
ResendSends notification emails from noreply@conductscience.com
ConductScience AuthSign-in, email verification, and password resets, operated by Conduct Science, Inc.

Your data

Managers on the Core plan can export each month's charges as a CSV file. For a full export of a workspace, or to report a security concern, contact us or email info@conductscience.com.