Data ownership
The question you should ask any system of record, answered before you ask it.
Why this page exists
A system of record has to answer this before it is asked.
You would be right to ask what happens to eight years of certificates if the company behind the software goes quiet. Most vendors do not address it. Here it is a design constraint, and the answers are mechanisms rather than assurances.
What does the export contain?
Every table that carries your laboratory's name: customers and contacts, assets, reference standards and their history, jobs and job items, calibration runs with their raw inputs, certificates and inspection reports with their hashes, quotes, invoices, payments, the thirteen quality registers, the audit log, the credits you hold, and the public half of every signing key. Documents come as PDF; records come as JSON. Nothing in it references a file outside it — the legacy system this replaced died of external links, and the rule is now a hard one.
How do you know it is complete?
A battery in the build asserts that every table carrying a laboratory identifier appears in the export list. Adding a table without adding it to the export fails the release. It has caught five tables so far, including the signing keys, which is the one that would have mattered most.
What does retention look like?
ISO/IEC 17025 §8.4 makes the laboratory responsible for retaining records for its declared period. The software carries that period on the laboratory and refuses to delete a laboratory that holds issued certificates inside it — including at the operator's request. The retention obligation is yours; the refusal is ours.
What stays readable after a trial or a cancellation?
Everything. A lapsed subscription is a clerical matter, and nothing stops a laboratory reading or exporting its own records over a clerical matter. Only seats refuse. The four hard blocks in the system are all ISO/IEC 17025 clauses, not billing states.
Does verification keep working?
Yes, always. A certificate's verification page is public, is served without a login, and does not consult the subscription. The token on it is random, so nobody can enumerate your certificates; the hash beside it lets anybody check the document they hold is the one that was issued.
And if CalibraWorks stops?
The agreement commits to notice and an export window before any shutdown, and the archive is in open formats with the hashes inside it, so a certificate's integrity can be checked with no server at all. The reason the format is open is exactly this: the records have to outlive the vendor, and a proprietary archive would not.
Every table that carries a laboratory's identifier is in the export, and a test fails the build if one is not. The public half of every signing key is included, so a laboratory that leaves can still verify every certificate it ever signed.
Public certificate verification is never switched off for non-payment. A lapsed subscription is a clerical matter, and nothing in the system stops a laboratory reading its own records over one.
In writing
- Can I export everything, at any time?
- Yes. The export is a complete archive of every table that carries your laboratory's name — jobs, certificates, customers, reference standards, the registers, the invoices, the credits you hold, and the public halves of your signing keys — and a battery in the build refuses a release in which a new table is missing from it. It has caught five.
- Why are the signing keys in the export?
- Because without the public half of them a laboratory that leaves would make every certificate it ever signed unverifiable. The export exists so that leaving costs you nothing you are entitled to keep.
- What happens to my records when a trial ends, or I cancel?
- Nothing is deleted. The records stay readable and exportable. The agreement says so, and the software refuses to delete a laboratory that holds issued certificates inside its retention period.
- Does certificate verification stop if I stop paying?
- No. Public verification is never gated on a subscription. A certificate is your customer's record as much as yours, and switching off the means of checking it would be a finding against you, not against us.
- What if CalibraWorks ceases trading?
- The export gives you the whole archive in open formats — JSON for records, PDF for documents — with nothing referencing a file outside it. The certificate hashes are in the archive, so a document's integrity can be checked without us. The agreement commits to notice and an export window before any shutdown.
- Who owns the data?
- You do. The agreement says the laboratory owns its records and CalibraWorks holds them on the laboratory's behalf. CalibraWorks does not use a laboratory's records to train anything; the one model in the system reads an incoming instrument list into proposals a person confirms, and writes to no table.
The agreement itself is on the application: subscription terms and privacy policy. The security controls behind these commitments are on the security page.
Start free. Thirty days, everything included.
No card. Nothing is deleted when a trial ends — the records are yours and stay readable.