iLab Technical Security Measures
© Agilent Technologies, Inc. 2026
1. Scope and security objectives
iLab Operations Software is a web-based laboratory operations and resource management service used by research institutions, shared resource facilities, laboratories, and related organizations. This public overview describes security practices for the iLab service and supporting operational safeguards at a high level.
Agilent designs and operates iLab security practices to support three primary objectives:
- Confidentiality — information is disclosed only to individuals and systems with an authorized business need.
- Integrity — information is protected from unauthorized or unintended modification.
- Availability — the service and related information are available for authorized use when required.
- Accountability — access and changes are logged where appropriate to support monitoring, investigation, and audit needs.
2. Security management approach
Agilent applies a layered, risk-based security approach that combines governance, technical safeguards, operational procedures, and monitoring. Security practices are aligned with recognized industry frameworks and are reviewed as part of Agilent's broader information security and risk management activities.
| Security function | How it is applied |
|---|---|
| Identify | Security-relevant systems, data, integrations, vendors, and regulatory expectations are assessed to understand risk and define appropriate safeguards. |
| Protect | Administrative, technical, and operational controls are applied to reduce unauthorized access, misuse, service disruption, and data exposure. |
| Detect | Monitoring and logging are used to identify suspicious activity, operational issues, and potential security events. |
| Respond | Security concerns are assessed and managed through defined incident response and escalation processes. |
| Recover | Backup, restoration, continuity, and disaster recovery capabilities are maintained to support service resilience. |
3. Infrastructure, hosting, and service resilience
iLab is hosted using reputable cloud infrastructure and service providers that maintain security and availability controls appropriate for enterprise cloud services. Physical data center controls are managed by the hosting provider and are supplemented by Agilent security governance and operational oversight.
- Cloud-hosted architecture uses resilient design patterns to support availability and continuity.
- Hosting providers maintain documented security controls and independent assurance reports or certifications, as applicable to the services used.
- Network access is restricted using segmented environments, access control rules, and controlled administrative pathways.
- Backup and recovery practices are maintained to support restoration of data and services following disruption.
- Operational monitoring is used to identify service health issues and backup or infrastructure exceptions.
4. Identity, authentication, and access control
Access to iLab is controlled through authentication and authorization mechanisms designed to ensure that users can access only the functions and information appropriate to their roles and permissions.
| Measure | Customer-facing description |
|---|---|
| Unique user access | User access is associated with unique login identifiers or customer-managed single sign-on where configured. |
| Single sign-on support | Customers may integrate institutional identity providers with iLab using standard federated authentication methods. |
| Role-based authorization | Permissions are assigned based on role, business need, and customer or administrator configuration. |
| Least privilege | Administrative and support access is limited to authorized personnel with a defined business need. |
| Session protection | Session controls help reduce risk when a user leaves an active session unattended. |
| Provisioning and deprovisioning | Access management processes support onboarding, account changes, and access removal when access is no longer required. |
5. Application security and secure development
Agilent integrates security into the iLab software development lifecycle. New and changed functionality is reviewed, tested, and deployed through controlled processes intended to reduce risk and preserve service reliability.
- Secure development practices include code review, testing, and evaluation of security considerations before production deployment.
- Development, test, staging, and production environments are separated to reduce the risk of unintended access or change.
- Application input validation and output handling are used to reduce common web application risks such as injection and cross-site scripting.
- Security and quality tooling may include dependency review, static analysis, automated tests, and vulnerability scanning as part of the build and release process.
- Changes are tracked through defined engineering workflows to support traceability, review, and controlled release management.
6. Data protection and encryption
Agilent applies technical and operational safeguards to protect customer data processed by iLab. Controls are designed to protect information during transmission, storage, processing, and support activities.
| Area | Public description |
|---|---|
| Encryption in transit | Web traffic and administrative connections use encrypted protocols where applicable. |
| Encryption at rest | Data protection mechanisms are applied to backups and storage consistent with Agilent security requirements and service design. |
| Data segregation | Customer and user permissions support logical separation of information within the application. |
| Data handling | Agilent personnel access customer-generated content only for authorized business purposes, such as providing support or operating the service. |
| Retention and recovery | Backup and recovery processes are designed to support continuity while aligning to documented operating requirements. |
7. Monitoring, logging, and auditability
Agilent uses logging and monitoring to support service operation, security assessment, troubleshooting, and investigation. Logs are protected from unauthorized modification and reviewed or analyzed based on operational and security needs.
- Successful and failed authentication activity may be logged to support detection of suspicious access patterns.
- Application actions and relevant administrative activity are logged where appropriate.
- Infrastructure and service monitoring help identify availability, capacity, backup, and connectivity issues.
- Security monitoring capabilities are used to identify indicators of compromise, unexpected behavior, or unauthorized activity.
8. Vulnerability, patch, and threat management
Agilent maintains processes for identifying, evaluating, prioritizing, and addressing vulnerabilities that could affect iLab or supporting environments. Vulnerability management activities are informed by internal security processes, vendor notifications, security tooling, and threat intelligence.
- Security patches and updates are evaluated and applied through controlled operational processes.
- Application and infrastructure vulnerabilities are reviewed and prioritized based on risk and severity.
- Third-party components and open-source dependencies are assessed through established engineering and security practices.
- Security exceptions, where required, are reviewed and managed through defined governance processes.
9. Incident response and reporting
Agilent maintains incident response processes to assess and respond to suspected or confirmed security events. Response activities may include triage, investigation, containment, remediation, communication, and lessons learned, depending on the nature and impact of the event.
Reporting security concerns
If you identify or suspect a security issue related to Agilent products, services, or websites, notify your Agilent representative or use the appropriate Agilent security reporting channel. Include the product or service name, a description of the issue, and the potential impact to support timely assessment.
10. Third-party and supplier safeguards
Agilent evaluates suppliers and third-party services with access to systems or data based on risk and applicable security requirements. Supplier security controls, assurance reports, and contractual obligations are reviewed where appropriate for the services used to deliver or support iLab.
11. Customer responsibilities
Security is shared between Agilent and each customer organization. Customers are responsible for managing their own users, institutional identity systems, local devices, network access, and configuration choices that affect access to their iLab environment.
- Maintain appropriate user roles, permissions, and administrative oversight within iLab.
- Manage customer single sign-on and institutional authentication policies where integrated.
- Remove or update customer-controlled access when users change roles or no longer require access.
- Use secure local devices and networks when accessing iLab.
- Report suspected security concerns promptly through established support or security channels.
12. Summary of technical security measures
| Control area | Public security measure |
|---|---|
| Governance | Risk-based policies, industry-aligned security practices, periodic review, and defined ownership. |
| Access control | Unique user access, role-based permissions, least privilege, SSO support, and controlled administrative access. |
| Application security | Secure development lifecycle, code review, testing, validation, vulnerability management, and controlled releases. |
| Data protection | Encryption in transit, data segregation, backup protection, controlled support access, and appropriate retention practices. |
| Availability | Cloud resilience, monitoring, backups, restoration processes, and disaster recovery planning. |
| Monitoring and audit | Authentication logging, application activity logging, infrastructure monitoring, and security event review. |
| Incident response | Defined escalation, investigation, containment, remediation, and post-incident improvement activities. |
| Supplier security | Risk-based review of third parties and cloud providers that support iLab services. |
13. Important note
This document is provided for general informational purposes and does not create or modify any contractual obligation unless expressly incorporated into a written agreement signed by Agilent. The security controls described may vary based on product configuration, customer-selected integrations, hosting region, regulatory requirements, and service updates.
Agilent may update this overview from time to time to reflect changes in security practices, technology, legal requirements, or service operations.