
Security & data handling
Last updated: 6 August 2026. Enterprise buyers need clarity: customer formulation data is never used to train shared models without a written agreement.
Purpose
This page describes how Lavoisier Labs protects information assets related to the marketing website, demo intake, and — where a customer agreement exists — product environments. It complements our Privacy Policy and Integrated Management Systems Policy.
Encryption
Data is encrypted in transit using TLS. Data at rest uses industry-standard cloud provider encryption controls for databases and object storage used by our systems.
Access control
- Least-privilege roles for production systems
- Access limited to authorized personnel
- Audit logging of administrative access where available
- Separation of marketing-site data from customer workspaces
Technical measures (summary)
- Access controls
- Encryption
- Logging systems
- Firewalls / edge protections
- Abuse rate limits on public forms
Customer data isolation & model training
Customer workspaces are logically isolated. Customer formulation data is never used to train shared models without an explicit written agreement. Default is no. This removes a common enterprise objection to AI chemistry tooling.
Hosting & compliance orientation
We host on reputable cloud infrastructure and align controls with common enterprise expectations, including practices oriented toward ISO/IEC 27001 (information security) and privacy management principles akin to ISO/IEC 27701 — as we mature formal certifications. Current certification status is available on request; we do not overclaim certificates we have not obtained.
Incident response
Suspected security incidents affecting personal or customer data should be reported to security@lavoisierlabs.com. We investigate and notify affected parties as required by law and contract.
Questionnaires
Security questionnaires and DPAs: security@lavoisierlabs.com.
