Skip to content
Security

Security at DLBD

Updated 16 August 2026

Posture

Security and compliance share one architecture in the DLBD Suite: role-based access control, organization-level data isolation, immutable audit trails with actor attribution on every change, and electronic signatures bound to their records. The details, mapped to 21 CFR Part 11 clause by clause, live on the Compliance & security page.

Identity & access

Sign-in can run through your identity provider: each organization can connect its own OpenID Connect provider for single sign-on, and can require it, so new sign-ins are governed where your IT team already manages accounts. Multi-factor authentication (authenticator apps, with recovery codes) is built in and can be enforced organization-wide. Inside the product, access follows roles your organization defines, and integrations use scoped API credentials that can be revoked independently and whose activity lands in the same audit trail as everything else.

Certifications

We’re working toward SOC 2. We’re happy to walk through our current security controls under NDA; ask via the contact form.

Reporting a vulnerability

If you believe you’ve found a security issue in this website, the demo, or the product, email hello@dlbd.us with enough detail to reproduce it. We read these first, respond quickly, and won’t take legal action over good-faith research that respects the demo environment and other people’s data.