Laravel · Trust Center

Laravel Trust Center

Trust center

Laravel maintains a public trust center documenting SOC 2 Type 2 and HIPAA compliance.

CompanyCloud SaasPHPDeveloper ToolsPlatform as a ServiceDeploymentServer ManagementApplication HostingInfrastructureFrameworksMonitoring
Trust center: https://trust.laravel.com/

Certifications & Compliance

SOC 2 Type 2HIPAA

Source

Trust Center

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://trust.laravel.com/
url: https://trust.laravel.com/
platform: SafeBase
scope: 'Stated as: "Welcome to Laravel Cloud''s Trust Center."'
certifications:
- SOC 2 Type 2
- HIPAA
privacy_frameworks:
- GDPR
- CCPA
- EU-US Data Privacy Framework
- Swiss-US Data Privacy Framework
- UK Extension to the EU-US Data Privacy Framework
documents:
  public_listing: true
  gated: true
  access: Documents are listed publicly; the reports and legal artifacts require a "Get access" request
    through the Trust Center.
  items:
  - category: reports
    name: Pentest Report
  - category: compliance
    name: SOC 2 Type 2
  - category: compliance
    name: HIPAA
  - category: legal
    name: Cyber Insurance
  - category: legal
    name: Data Processing Agreement
  - category: legal
    name: W-9
  - category: policies
    name: Acceptable Use Policy
  - category: policies
    name: Asset Management Policy
  - category: policies
    name: Backup Policy
  - category: policies
    name: Change Management Policy
  - category: policies
    name: Code of Conduct Policy
  - category: policies
    name: Data Classification Policy
program_sections:
- Product Security (audit logging, multi-factor authentication)
- Reports (pentest report, SOC 2 report)
- Data Security (backups, data erasure, encryption at rest)
- App Security (responsible disclosure, application penetration testing, bot detection)
- Legal (subprocessors, cyber insurance, DPA)
- Data Privacy (cookies, data breach notifications)
- Access Control (access log management, automated account management, BYOD)
- Infrastructure (status monitoring, Amazon Web Services, anti-DDoS)
- Endpoint Security (anti-malware, disk encryption)
- Network Security (bot detection, DLP, anti-DDoS)
- Corporate Security (email protection, employee training, HR security)
- Incident Response (designated response personnel, incident reporting process, pager service)
- Risk Management (data access/impact levels, risk assessments, supply chain risk management)
- Asset Management (asset classification, hardware/software inventories)
- Training (employee privacy training, phishing training, role-based training)
- Change Management (change management program, change restrictions, configuration management)
- Continuous Monitoring (automated alert response, automated compliance monitoring, event and audit log
  management)
risk_profile:
  impact_level: Substantial
  critical_dependence: true
  third_party_dependence: true
infrastructure:
  cloud_provider: Amazon Web Services
evidence:
- source: https://trust.laravel.com/
  keywords:
  - soc 2 type 2
  - hipaa
  - gdpr
  - ccpa
  - eu-us dpf
  - trust center
  - responsible disclosure
  - pentest report
related:
  vulnerability_disclosure: security/laravel-vulnerability-disclosure.yml
  conformance: conformance/laravel-conformance.yml