Skip to main content

Security

How Ouro Labs protects access and data.

A straightforward overview of our security approach. Ouro Labs does not claim SOC 2, HIPAA, ISO 27001, or similar certifications unless and until they are formally achieved and published.

Authentication with Auth0

Ouro Labs uses Auth0 for identity and sign-in flows. Users authenticate through established identity patterns; Ouro Labs does not store raw passwords for the Auth0-managed login experience.

Role-based access control

Permissions inside a workspace are enforced with role-based access control. Institutional and laboratory roles receive only the visibility and actions appropriate to their responsibilities.

Tenant and workspace separation

Customer data is organized by tenant boundaries. Workspaces belong to organizations; membership and authorization determine which workspace data a signed-in user can access.

Secure sessions

Sessions are established through the authentication provider and application session handling designed for web workspace access — with sign-out and workspace discovery flows that respect organizational boundaries.

Encryption in transit

Traffic to Ouro Labs web properties and the application is served over HTTPS, encrypting data in transit between clients and our services.

Controlled workspace access

Access to operational data requires both successful authentication and verified workspace membership. Users with multiple memberships choose the appropriate workspace after sign-in.

Security questions?

For security-specific questions during evaluation or procurement, contact Ouro Labs with your environment and requirements. We answer honestly about what is implemented today versus what is on the roadmap.