Machine-readable ✓ llms.txt ✓ agents.json ✓ MCP endpoint OpenAPI spec

Security

Last Updated: July 22, 2026

Protecting the data you trust us with is a core part of how we operate, not an afterthought. This page describes the practices and safeguards behind the DataLabs.store service. For how we collect, use, and retain data, see our Privacy Notice.

Hosting & Infrastructure

Customer databases are hosted on dedicated infrastructure located in the EU and United States. For customers with larger data volumes, we also offer an optional Azure SQL Database hosting tier in the EU region.

Each customer's data lives in its own isolated, dedicated database rather than a shared multi-tenant table structure. Database authentication is scoped per database, so credentials for one customer are never valid for another's.

Encryption

All connections to our services — the web application, our API/MCP interfaces, and direct database access — are encrypted in transit via TLS.

Direct Database Access

Part of our product is that customers can connect directly to their own database with standard SQL client tools, rather than being limited to an API. This is a deliberate feature. It's protected by per-database credentials, automated brute-force protection that bans source IPs after repeated failed authentication attempts, and the default SQL Server administrative account is disabled fleet-wide.

Access Control

Access to customer data is restricted to authorized personnel on a need-to-know basis. Administrative access to our infrastructure uses key-based authentication rather than passwords.

Third-Party Processing

We use a small number of carefully selected sub-processors, listed in full in our Privacy Notice and DPA: Microsoft Azure (optional hosting), Stripe (PCI-DSS compliant payment processing), and Brevo (outreach email delivery).

Disconnecting & Data Deletion

When you disconnect a Source (e.g., HubSpot) from your account, we revoke the associated access token with that provider and remove the corresponding authorization record. See our Privacy Notice for our data retention practices.

Cookie Consent

Our website uses a cookie consent mechanism — non-essential analytics and advertising cookies are only set after you provide consent.

Continuous Improvement

Security isn't static. We continue to invest in additional safeguards, including expanding encryption coverage for stored credentials, as our infrastructure and customer base grow.

Reporting a Concern

If you believe you've found a security issue, contact us at products@datalabs.store. We take all reports seriously and respond promptly.