Clarus LIS and its database run on your laboratory's own computer, and all daily work runs there without internet. Every person signs in to an account of their own, what staff do is written to a tamper-evident audit trail, and a backup is taken every day and checked.
The installer sets up the database on the laboratory's computer. As installed, the database, the program and its analyzer port answer only that computer (127.0.0.1), and nothing on the network can reach them.
The database asks for a password even for connections from the same computer (SCRAM-SHA-256).
The internet is used only for optional services, such as activation (a phone can be used instead), updates, the laboratory website and sending messages.
The keys the program keeps, such as the one that signs each backup's record, are sealed to this Windows computer with Windows data protection (DPAPI).
We never keep your laboratory’s data in a readable form: it stays on your laboratory’s computers. Whatever of it passes through our server, such as the patient reports your laboratory’s website publishes, passes end-to-end encrypted, so our server relays what it cannot read. So does the manager’s phone when it reaches the laboratory through our intermediary server with Clarus Link.
Each member of staff signs in with an account of their own, with no limit on the number of accounts.
Administrator, reception, technologist, pathologist, billing, inventory and stockroom roles, and each action in the program checks the permission it needs.
Passwords are never stored as written: they are kept as PBKDF2-SHA256 hashes with 260,000 iterations.
Five wrong passwords in a row lock the account for 15 minutes.
A sign-in expires after a set time, and the program keeps only a hash of each session token.
The audit trail is chained entry to entry, so an altered entry is detected. It can be searched by patient, user, action and date, and exported together with the proof that the exported entries are intact.
Clarus LIS includes mechanisms its developers designed against named GAHAR standards: a tamper-evident, searchable and exportable audit trail, critical-result read-back, backup and retention controls, and downtime procedures. They help a laboratory meet GAHAR requirements. GAHAR has not reviewed or certified them, and they do not make a laboratory compliant by themselves.
Its quality tools support ISO 15189-style accreditation work: Westgard quality-control rules, external quality assessment scored by z-score, CAPA and staff-competency records, lot tracking, audited result amendment and an accreditation-readiness overview. The program is not ISO 15189 certified, and it does not certify a laboratory.
Because the data and its backups are on your own computer and your own drives, protecting them is in your hands: who can reach the computer, where the backup drive is kept, and whether the computer's disk is encrypted.
Download the 14-day free trial with every feature, and look at the audit trail and the Backup screen yourself.
Choose which categories of cookies Clarus LIS may use. Strictly necessary cookies are always on because the service cannot run without them. You can change these choices at any time.
Required for the service to work — your session, sign-in, and security (CSRF) protections. These cannot be switched off.
Remember choices such as your language and display currency so the site behaves the way you expect on every visit.
Help us understand, in aggregate, how the site is used so we can improve it. Privacy-friendly and never used for advertising.