Laravel · Trust Center
Laravel Trust Center
Trust center
Laravel maintains a public trust center documenting SOC 2 Type 2 and HIPAA compliance.
CompanyCloud SaasPHPDeveloper ToolsPlatform as a ServiceDeploymentServer ManagementApplication HostingInfrastructureFrameworksMonitoring
Trust center: https://trust.laravel.com/
Certifications & Compliance
SOC 2 Type 2HIPAA
Source
Trust Center
generated: '2026-07-19'
method: searched
probe: true
source: https://trust.laravel.com/
url: https://trust.laravel.com/
platform: SafeBase
scope: 'Stated as: "Welcome to Laravel Cloud''s Trust Center."'
certifications:
- SOC 2 Type 2
- HIPAA
privacy_frameworks:
- GDPR
- CCPA
- EU-US Data Privacy Framework
- Swiss-US Data Privacy Framework
- UK Extension to the EU-US Data Privacy Framework
documents:
public_listing: true
gated: true
access: Documents are listed publicly; the reports and legal artifacts require a "Get access" request
through the Trust Center.
items:
- category: reports
name: Pentest Report
- category: compliance
name: SOC 2 Type 2
- category: compliance
name: HIPAA
- category: legal
name: Cyber Insurance
- category: legal
name: Data Processing Agreement
- category: legal
name: W-9
- category: policies
name: Acceptable Use Policy
- category: policies
name: Asset Management Policy
- category: policies
name: Backup Policy
- category: policies
name: Change Management Policy
- category: policies
name: Code of Conduct Policy
- category: policies
name: Data Classification Policy
program_sections:
- Product Security (audit logging, multi-factor authentication)
- Reports (pentest report, SOC 2 report)
- Data Security (backups, data erasure, encryption at rest)
- App Security (responsible disclosure, application penetration testing, bot detection)
- Legal (subprocessors, cyber insurance, DPA)
- Data Privacy (cookies, data breach notifications)
- Access Control (access log management, automated account management, BYOD)
- Infrastructure (status monitoring, Amazon Web Services, anti-DDoS)
- Endpoint Security (anti-malware, disk encryption)
- Network Security (bot detection, DLP, anti-DDoS)
- Corporate Security (email protection, employee training, HR security)
- Incident Response (designated response personnel, incident reporting process, pager service)
- Risk Management (data access/impact levels, risk assessments, supply chain risk management)
- Asset Management (asset classification, hardware/software inventories)
- Training (employee privacy training, phishing training, role-based training)
- Change Management (change management program, change restrictions, configuration management)
- Continuous Monitoring (automated alert response, automated compliance monitoring, event and audit log
management)
risk_profile:
impact_level: Substantial
critical_dependence: true
third_party_dependence: true
infrastructure:
cloud_provider: Amazon Web Services
evidence:
- source: https://trust.laravel.com/
keywords:
- soc 2 type 2
- hipaa
- gdpr
- ccpa
- eu-us dpf
- trust center
- responsible disclosure
- pentest report
related:
vulnerability_disclosure: security/laravel-vulnerability-disclosure.yml
conformance: conformance/laravel-conformance.yml