LaravelCloud With PlanetScale

A product story

The same Cloud.
A building of its own.

Laravel Private Cloud runs your applications in a dedicated Kubernetes cluster, inside a dedicated AWS account and VPC that Laravel provisions and manages on your behalf, with no other tenant. The dashboard, the deploys and the framework integration are the ones you already know.

Walk the floors

The idea in one line Same dashboard, same deploys. Nobody else in the building.

One tenantLaravel Private Cloud

Address: static outbound IPs, yours alone

05Edge zone · custom rules, cache rulesDedicated
04Cluster · three nodes across AZsDedicated
03Data · RDS MySQL or Postgres, ElastiCacheInside
02Network · NAT gateways, private links outPrivate
01Account · dedicated AWS account and VPC, run by LaravelSingle tenant

Ground floor: Laravel operates the building. Your team ships the product.

Includes: Laravel Cloud Enterprise, the Advanced support plan

Custom quote

What shared Cloud already gives

Most teams do not need a building.

Shared Laravel Cloud is not a lesser tier. Every application already sits behind an edge firewall, runs in its own Kubernetes namespace, and is covered by Cloud's SOC 2 Type 2 attestation and ISO 27001 certification. Private Cloud is for the teams whose requirements go past that.

Every planEdge firewall and DDoS mitigation

Cloudflare's OWASP Core Ruleset and DDoS mitigation sit in front of every app, Starter included.

Every planTenant isolation in the cluster

Enforced with Kubernetes namespaces and network policies. Private Cloud moves that wall down to the infrastructure.

Laravel CloudSOC 2 Type 2 and ISO 27001

Attested for Security, Confidentiality and Availability; ISO 27001 announced 14 September 2026.

Private Cloud onlyA signed BAA for HIPAA

Health data is where shared Cloud stops and Private Cloud begins. Request the BAA before any PHI is deployed.

Sources: Monitor 559 (security defaults, 8 July 2026) and 725 (firewall and DDoS by default); Compliance & Security docs; Monitor 234 (ISO 27001, 14 September 2026); Monitor 552 (HIPAA, 25 August 2026). The compliance docs offer the BAA on the Enterprise and Private Cloud plans, not on Starter or Growth.

When it is the right choice

Five reasons
to move in.

If none of these describe your team, shared Cloud is the better answer, and cheaper. If one of them is a hard requirement, Private Cloud is how Laravel meets it without your team building the perimeter.

Regulated data

Health records, medical intake forms, government work. The question an auditor asks is whose infrastructure sits inside the scope. On Private Cloud the answer is only yours.

Shared Cloud
SOC 2 Type 2, ISO 27001; tenant isolation in the cluster
Private Cloud
Dedicated account, VPC, cluster and nodes; HIPAA with a signed BAA; PCI-DSS readiness and custom compliance auditing
Still yours
Encrypting PHI at the model, gates and policies, an application audit log

Monitor 552; Private Cloud FAQ (BAA, PCI-DSS readiness)

Use cases are Laravel's own list from the Private Cloud docs: security and compliance, private system access, performance-sensitive workloads, enterprise architecture, dedicated IP requirements.

Inside the building

One request,
floor by floor.

It arrives at your own edge

A dedicated edge zone with a rule builder: custom rules to challenge, block or allow by path, IP, country or header, and per-path cache rules. Traffic views show the top IPs and paths.

Floor 05

It lands on your own nodes

A private Kubernetes cluster with dedicated compute nodes, three always on across availability zones. Internal networking lets your apps call one another without leaving the cluster.

Floor 04

It reads from data in the same building

RDS MySQL 8.4 or Postgres 18 inside the dedicated VPC: Multi-AZ, up to 15 read replicas, point-in-time recovery. ElastiCache in Valkey or Redis OSS, up to multi-AZ with automatic failover. Laravel MySQL and Serverless Postgres remain available, but outside the VPC.

Floor 03

It calls out from a known address

A partner API sees your static outbound IPs. Calls into your existing AWS accounts go over VPC Peering or Transit Gateway, and IAM roles in those accounts replace static access keys.

Floor 02

It shows up on the bill as itself

Data Transfer, VPC, ELB, NAT Gateway and CDN costs appear as AWS line items rather than a single figure, so procurement can audit what the building costs to run.

Floor 01

Sources: Private Cloud, edge network, RDS, ElastiCache and private networking docs and the Private Cloud FAQ, read 8 October 2026; Monitor 494 (RDS replicas, Postgres and MySQL, 2 March 2026), 479 (ElastiCache, 10 June 2026), 586 (AWS line items, 25 March 2026).

Who chose it, and why

Four tenants.
Four reasons.

Each team below runs on Private Cloud, and each had a different reason for wanting the building. The figures are the customers' own, from their published stories.

Medical intake data · from Vapor

Trybe

3separate Private Clouds: staging, playground, production
  • Regulated medical data kept off shared infrastructure
  • A 1.6 TB MongoDB Atlas database left in place over VPC peering
Monitor 990 · customer story
Government AI · from Vapor

GovAI

2production regions, US and Canada, in separate single-tenant AWS accounts
  • Compliance settled the decision, the story says
  • Cost per 1,000 messages from about $22 to $16
Monitor 991 · customer story
Ecommerce data · from AWS and Vapor

Shoptimised

42%lower infrastructure cost
  • Microservices that need private connections
  • Deploys from over an hour to one or two minutes
Monitor 992 · customer story
Insurance · from Heroku

Superscript

30%infrastructure saving in the first month; 50% expected
  • Needed ISO 27001, SOC 2 and private networking
  • Five apps moved; the 80 GB database took about six hours
Monitor 998 · customer story
“The ability to have the private networking aspect could have become a deal breaker.”Colin Bradford, COO, Superscript · Monitor 998

Shared Cloud for most.
A building when you need one.

Three questions before the consultation: which of your data would an auditor want walled off; which systems must your application reach without touching the public internet; and who outside your team needs to know your IP address in advance.