A firewall in front of every app
Cloudflare's OWASP Core Ruleset and DDoS mitigation at the edge, with default rate limiting at 100 requests a minute per IP. Private Cloud adds custom WAF rules.
An enterprise story
Procurement asks the same questions every time: which attestation, for which product, on which plan, since when. This is the ledger for Laravel Cloud, Private Cloud and Nightwatch, with a date and a source on every entry.
The idea in one line Name the product and the plan before you name the certificate.
Compliance binderCloud · Private Cloud · Nightwatch
Reports and certificates: trust.laravel.com
On request
Which certificate covers what
Laravel's attestations are scoped to products, and HIPAA is scoped to a plan. A security questionnaire answered with the wrong product name costs more time than it saves. Read across before you read down.
| Attestation | Laravel Cloud, shared plans | Private Cloud | Nightwatch |
|---|---|---|---|
| SOC 2 Type 2 | Yes. Audit completed 31 July 2025; Security, Confidentiality, Availability | Yes. Under Cloud's attestation since launch | Type 1 only, 9 October 2025. Type 2 was aimed for end of December 2025 [VERIFY] |
| ISO 27001 | Yes. From 14 September 2026 | Yes. Listed on the Private Cloud page | Not stated [VERIFY] |
| HIPAA, with a BAA | On Enterprise. Not on Starter or Growth, per the compliance docs | Yes. Request the BAA before deploying PHI | Not stated |
| PCI-DSS | Not stated | Readiness, per the FAQ. A blog post calls it a certification; the Trust Center does not list it [VERIFY] | Not stated |
| GDPR, CCPA, DPF | Yes. Laravel-wide; EU-US DPF, Swiss-US DPF and the UK extension on the Trust Center | Yes. Included with Cloud | Laravel-wide by the Trust Center; product scope not stated [VERIFY] |
Sources: Compliance & Security docs; Private Cloud FAQ; trust.laravel.com, all read 8 October 2026; Monitor 662 (SOC 2 Type 2, GDPR and CCPA), 627 (Nightwatch), 552 (HIPAA plan scope; calls PCI-DSS a certification), 497 (Private Cloud launch), 731 and 234 (ISO 27001).
The dated ledger
Each tab is one entry in the binder: what was attested, for which product, when, and where the evidence lives. Type 1 checks that controls are designed and in place at a point in time; Type 2 tests that they worked over a period.
Laravel Cloud completed its SOC 2 Type 1 audit a month after launch. Taylor Otwell posted the next day that Type 2 was on its way.
Monitor 708, 364
Audited on three of the five Trust Services Criteria, where Security alone is the minimum. Laravel chose Availability and Confidentiality as well.
Monitor 518 (changelog), 662 (blog)
Nightwatch holds monitoring data that can contain sensitive application detail, which is why Confidentiality matters for it. Its Type 1 report is available to customers.
Monitor 627
Private Cloud arrived under Cloud's SOC 2 Type II attestation, described at launch as designed for HIPAA and PCI-DSS. It added infrastructure-level isolation to the binder.
Monitor 497; Private Cloud FAQ
Announced at Laracon US 2026. Laravel signs a Business Associate Agreement for Private Cloud customers handling protected health information. The certification covers the Private Cloud plan, not Starter or Growth.
Monitor 556, 254, 552, 549
An international standard for an information security management system. The Trust Center lists it as ISO/IEC 27001:2022, and certificates can be requested there.
Monitor 731, 234; compliance docs
Dates are publication dates of the cited source, not certificate issue dates. Ask the Trust Center for the report period before quoting one.
The controls behind the tabs
Cloudflare's OWASP Core Ruleset and DDoS mitigation at the edge, with default rate limiting at 100 requests a minute per IP. Private Cloud adds custom WAF rules.
Basic RBAC with predefined roles on every plan. Advanced RBAC adds custom roles, application and environment-level access, and a Restricted role suited to auditors. Shipped 7 May 2026.
Organisation-level secrets, encrypted in the browser before they reach Cloud, never shown again, decrypted only at deploy with keys held in AWS KMS. Shipped 16 July 2026.
Changes made in the dashboard, the Cloud API or the CLI are logged for audit and internal review. SSO and SAML connect the company identity provider.
Dedicated account, VPC and nodes; static outbound IPs for allowlisting; HIPAA with a signed BAA. You validate it with your own penetration testing, as Laravel invites.
Sources: Monitor 725 (firewall and DDoS by default, 29 September 2026), 559 (security defaults, rate limit, audit logs, 8 July 2026), 483 (RBAC), 473 (Secrets Manager), 552 (the shared line); Private Cloud FAQ (custom WAF rules, penetration testing).
A regulated move, in their figures
Three teams whose buyers or regulators asked the questions above, and what they moved to answer them. The figures are the customers' own, from their published stories.
Superscript also asked for more granular role-based access to prevent accidents; Advanced RBAC (Monitor 483) is the current answer on Business and Enterprise.
Three questions for the security review: which Laravel products sit inside your scope, Cloud alone or Nightwatch too; does any workload touch health data and so need Private Cloud and a BAA; and which report period does your questionnaire ask for.