1. Overview
LISBridge is built around a local-first security model. Laboratory instrument data — including patient samples and test results — is processed entirely on your hardware and never leaves your device. The security measures described on this page protect your account, subscription, and license data on our web platform, and the integrity of the software we deliver to your device.
Lab data never reaches our servers
All WASM downloads authenticated
Licenses tied to machine hardware
Digital signatures on software assets
2. Local-First Architecture
The desktop application's data flow is entirely local:
- Instruments connect via RS-232 serial or TCP/IP to the local machine.
- Raw ASTM E1394 and HL7 v2.x messages are parsed by the WASM engine running inside the desktop app process.
- Parsed results are forwarded via HTTP POST to your configured HIS/LIMS endpoint on your local network.
- All result data and audit logs are stored in a local SQLite database (default) on your device.
- Data retention is configurable — default 30 days; set to 0 to keep indefinitely.
The only outbound connections from the desktop application are:
- License validation requests to our licensing server (machine ID + timestamp, no patient data).
- WASM module update checks to our CDN (cdn.trodad.com) — polling every 15 minutes, authenticated via HMAC-SHA256.
3. Web Platform Security
- NextAuth Session management for all authenticated routes on lisbridge.com. Sessions are server-side with signed JWTs.
- HTTPS All traffic to lisbridge.com is encrypted in transit via TLS 1.2 or higher.
- Passwords are hashed using bcrypt before storage. Plain-text passwords are never stored or logged.
- Email verification is required before account activation.
- Password reset links are time-limited (1 hour) and single-use.
- Admin routes require both an authenticated session and the ADMIN role — standard users cannot access admin endpoints.
4. License Key Security
LISBridge uses device-based licensing to prevent unauthorised use and key sharing.
- Machine ID A hardware-derived identifier is generated on first activation. It is combined with a timestamp and signed using HMAC-SHA256 to prevent replay attacks.
- License keys are encrypted before being stored locally on your device. The encryption key is derived from both the license key and the machine ID — a key stolen from one machine cannot activate another.
- Offline caching — the validated license is cached locally for up to 24 hours, allowing the desktop app to operate without internet access. The cache is invalidated and re-validated on reconnection.
- Revocation — when you revoke a device from the dashboard, the cached license is invalidated on the next validation attempt. The desktop app will prompt for a new key.
5. WASM Module Integrity
The LISBridge parser engine is delivered as a WebAssembly (WASM) module via our CDN. The hot-swap delivery pipeline includes multiple integrity checks to prevent tampered modules from running.
- HMAC-SHA256 Every download request includes an HMAC-SHA256 signature computed from the machine ID and a request timestamp. The server verifies this signature before serving the module.
- Ed25519 Each WASM release is signed with an Ed25519 private key. The desktop app verifies the signature against the public key embedded at build time before loading the module.
- Version pinning — the desktop app checks the CDN every 15 minutes. If a new version is available and passes integrity checks, it is hot-swapped into memory without requiring a restart. If verification fails, the existing version continues to run.
6. Network Security
- IP Allowlist Available from desktop app version 1.18.0. You can configure a list of allowed IP addresses or CIDR ranges. The desktop app will only accept connections from instruments and HIS/LIMS endpoints within the allowlist, blocking all other inbound traffic.
- TCP/IP mode — the desktop app can operate as either a TCP server or TCP client when connecting to instruments. In server mode, only configured instrument IPs are accepted.
- HIS/LIMS integration — result delivery uses HTTP POST with an optional Bearer token for authentication. Credentials are stored locally and are never transmitted to LISBridge servers.
7. Data Retention
Desktop app data (instrument results, audit logs, images) is stored in a local SQLite database on your device. You control retention completely:
- Default: 30 days. Results older than 30 days are deleted automatically by a nightly cleanup job.
- Set to 0 to keep all data indefinitely.
- Cascade deletes — removing a result deletes associated findings and images.
- LISBridge has no access to this data at any point.
Web platform data (account, subscription, device, license records) is retained per our Privacy Policy and deleted within 90 days of account closure on request.
8. Third-Party Security
- Stripe — payment card data is handled entirely by Stripe under PCI DSS Level 1 compliance. Card numbers are never transmitted to or stored on LISBridge servers.
- Vercel — the lisbridge.com web platform is hosted on Vercel with automatic TLS, DDoS mitigation, and isolated serverless function execution.
- Neon/PostgreSQL — database connections use TLS in transit and data is encrypted at rest.
- CDN (cdn.trodad.com) — WASM module delivery CDN. All assets are authenticated before serving (see §5 above).
9. Incident Response
In the event of a security incident affecting your account or subscription data on the LISBridge web platform:
- We will notify affected users by email within 72 hours of becoming aware of a breach that poses a risk to their data.
- License keys for affected devices may be revoked and reissued as a precautionary measure.
- Because patient and instrument data is stored locally and never transmitted to us, a web platform incident cannot expose your laboratory data.
To report a suspected vulnerability, contact us at [email protected] with the subject line [Security]. We will respond within 48 hours.
10. Contact
For security questions, vulnerability disclosures, or data requests:
- Email: [email protected]
- Contact form: lisbridge.com/contact