TL;DR
LabLynx provides its laboratory information management system to a U.S. state government agency. The state’s information security standard requires vendors who operate IT systems containing state data to undergo an independent security examination every year.
LabLynx engaged TrustNet as its independent service auditor for that deployment. Each year, TrustNet plans and executes a NIST-aligned examination of the LIMS application, management’s review of the controls for its cloud hosting environment, and the organizational security controls behind it.
Background
LabLynx has built laboratory informatics software since 1997 and supports roughly 120 active deployments across analytical sciences, research, manufacturing, forensic sciences, and health and life sciences.
Among them is a LabLynx LIMS deployment for a state government agency, where the system supports sample tracking, test result management, chain-of-custody documentation, and regulatory reporting for the agency’s laboratory operations.
The Requirement
The state’s information security standard is grounded in the NIST Cybersecurity Framework and built on the NIST SP 800-53 control catalog, whose twenty control families set the baseline for everything from access control and audit logging to incident response and supply chain risk. For a vendor that services the state agency, the standard carries a specific obligation: an independent, third-party IT security examination, performed at least annually.
Why an independent service auditor matters
The state’s audit requirements demand that the auditing firm be genuinely independent of the entity that it evaluates.
TrustNet does not perform management functions, prohibited non-attest services, or other services for LabLynx, so the assessment the state receives is exactly what the requirement intends: an independent examination.
What the annual examination involves
TrustNet runs the engagement in five phases: planning and scoping, documentation review, technical testing, interviews and walkthroughs with LabLynx security and operations staff, and formal reporting.
The relationship. TrustNet has been LabLynx’s independent service auditor for this engagement since 2021.
In TrustNet's words
“LabLynx has been a great partner to work with since 2021. Their team treats security and compliance as a strategic priority rather than a checkbox, which makes our work together straightforward and effective. We appreciate the trust they have placed in TrustNet and the long-term relationship we have built.”
Trevor Horwitz, CISO, TrustNet
The outcome
The state agency client receives the independent assurance its standard requires, on schedule, every year. The engagement covers this deployment specifically, and what it validates is not only the system but the organizational security controls behind it: the policies, training, incident response, and vulnerability management that LabLynx applies across its control environment.
LabLynx builds laboratory informatics solutions configured to each client’s lab and has done so since 1997. Labs that operate under independent security and compliance audits, like the one described here, are the kind of deployment it is built for. Learn more at www.lablynx.com.



