Security
Security and data
How ConductLaboratory protects accounts, booking records, and cost details.
Last updated October 7, 2026
Sign-in
Everyone signs in with a ConductScience account. ConductLaboratory accepts only accounts with a verified email address. Passwords, password resets, and email verification are handled by ConductScience Auth, not by this app.
Sessions use secure, HTTP-only cookies. A session ends after 7 days or when you sign out.
Who can see and change what
- Owners and managers set equipment rules, rates, training access, and approvals, and see every booking in their core.
- Researchers book for themselves and see their own costs.
- Viewers can see the schedule but cannot change it.
The paying account, purpose, and cost of a booking are visible only to the person who booked and the core's managers. Other members see when a resource is taken and by whom.
Records of changes
Scheduling changes are recorded with who made them and when, in the same database transaction as the change. Usage corrections require a reason, and the original reservation times stay on record.
Hosting and storage
Data is stored in a managed PostgreSQL 17 database from Neon in the AWS US East (N. Virginia) region. The database can be restored to any point in the previous 24 hours.
The app runs on Vercel and is served only over HTTPS, with HTTP Strict Transport Security turned on.
Service providers
| Provider | What it does |
|---|---|
| Vercel | Hosts the application |
| Neon | Managed PostgreSQL database |
| Resend | Sends notification emails from noreply@conductscience.com |
| ConductScience Auth | Sign-in, email verification, and password resets, operated by Conduct Science, Inc. |
Your data
Managers on the Core plan can export each month's charges as a CSV file. For a full export of a workspace, or to report a security concern, contact us or email info@conductscience.com.