LaravelCloud One app, three homes

An enterprise story

The binder is ready.
Every tab is dated.

Procurement asks the same questions every time: which attestation, for which product, on which plan, since when. This is the ledger for Laravel Cloud, Private Cloud and Nightwatch, with a date and a source on every entry.

Open the binder

The idea in one line Name the product and the plan before you name the certificate.

Compliance binderCloud · Private Cloud · Nightwatch

SOC 2 Type 1Controls designed and in placeCloud
SOC 2 Type 2Security, Confidentiality, AvailabilityCloud
SOC 2 Type 1Point-in-time auditNightwatch
Private Cloud launchesUnder the SOC 2 Type II attestationPrivate Cloud
HIPAA, with a signed BAAAnnounced at Laracon USPrivate Cloud
ISO 27001ISO/IEC 27001:2022 on the Trust CenterCloud

Reports and certificates: trust.laravel.com

On request

Which certificate covers what

Product first.
Then plan.

Laravel's attestations are scoped to products, and HIPAA is scoped to a plan. A security questionnaire answered with the wrong product name costs more time than it saves. Read across before you read down.

AttestationLaravel Cloud, shared plansPrivate CloudNightwatch
SOC 2 Type 2Yes. Audit completed 31 July 2025; Security, Confidentiality, AvailabilityYes. Under Cloud's attestation since launchType 1 only, 9 October 2025. Type 2 was aimed for end of December 2025 [VERIFY]
ISO 27001Yes. From 14 September 2026Yes. Listed on the Private Cloud pageNot stated [VERIFY]
HIPAA, with a BAAOn Enterprise. Not on Starter or Growth, per the compliance docsYes. Request the BAA before deploying PHINot stated
PCI-DSSNot statedReadiness, per the FAQ. A blog post calls it a certification; the Trust Center does not list it [VERIFY]Not stated
GDPR, CCPA, DPFYes. Laravel-wide; EU-US DPF, Swiss-US DPF and the UK extension on the Trust CenterYes. Included with CloudLaravel-wide by the Trust Center; product scope not stated [VERIFY]

Sources: Compliance & Security docs; Private Cloud FAQ; trust.laravel.com, all read 8 October 2026; Monitor 662 (SOC 2 Type 2, GDPR and CCPA), 627 (Nightwatch), 552 (HIPAA plan scope; calls PCI-DSS a certification), 497 (Private Cloud launch), 731 and 234 (ISO 27001).

The dated ledger

Six tabs,
eighteen months.

Each tab is one entry in the binder: what was attested, for which product, when, and where the evidence lives. Type 1 checks that controls are designed and in place at a point in time; Type 2 tests that they worked over a period.

SOC 2 Type 1, Laravel Cloud

Laravel Cloud completed its SOC 2 Type 1 audit a month after launch. Taylor Otwell posted the next day that Type 2 was on its way.

Date
26 March 2025 (blog); 27 March 2025 (X)
Product
Laravel Cloud
Attests
Controls suitably designed and in place at a point in time
Now
Superseded by Type 2 for Cloud

Monitor 708, 364

Dates are publication dates of the cited source, not certificate issue dates. Ask the Trust Center for the report period before quoting one.

The controls behind the tabs

What the auditor
asks next.

A firewall in front of every app

Cloudflare's OWASP Core Ruleset and DDoS mitigation at the edge, with default rate limiting at 100 requests a minute per IP. Private Cloud adds custom WAF rules.

Every plan

Roles, down to one environment

Basic RBAC with predefined roles on every plan. Advanced RBAC adds custom roles, application and environment-level access, and a Restricted role suited to auditors. Shipped 7 May 2026.

Business, Enterprise

Secrets written once, read never

Organisation-level secrets, encrypted in the browser before they reach Cloud, never shown again, decrypted only at deploy with keys held in AWS KMS. Shipped 16 July 2026.

Cloud

A log of every action

Changes made in the dashboard, the Cloud API or the CLI are logged for audit and internal review. SSO and SAML connect the company identity provider.

Cloud

Walls, addresses and a BAA

Dedicated account, VPC and nodes; static outbound IPs for allowlisting; HIPAA with a signed BAA. You validate it with your own penetration testing, as Laravel invites.

Private Cloud

Sources: Monitor 725 (firewall and DDoS by default, 29 September 2026), 559 (security defaults, rate limit, audit logs, 8 July 2026), 483 (RBAC), 473 (Secrets Manager), 552 (the shared line); Private Cloud FAQ (custom WAF rules, penetration testing).

A regulated move, in their figures

The binder
closed the deal.

Three teams whose buyers or regulators asked the questions above, and what they moved to answer them. The figures are the customers' own, from their published stories.

Insurance · from Heroku · Private Cloud

Superscript

30%infrastructure saving in the first month, 50% expected
  • Needed ISO 27001, SOC 2 and private networking between its software layers
  • Five apps moved; MFA and Google Workspace login for access
Monitor 998 · customer story
Government AI · from Vapor · Private Cloud

GovAI

2regions in separate single-tenant AWS accounts, US and Canada
  • Compliance sealed the decision, in the story's words
  • FERPA and GLB were on the roadmap the story cites Signalled
Monitor 991 · customer story
Medical intake data · from Vapor · Private Cloud

Trybe

3separate Private Clouds, so staging never shares a wall with production
  • Medical intake forms regulated as private medical information
  • RBAC set up by ticking boxes, in place of IAM policies
Monitor 990 · customer story

Superscript also asked for more granular role-based access to prevent accidents; Advanced RBAC (Monitor 483) is the current answer on Business and Enterprise.

Name the product.
Then open the binder.

Three questions for the security review: which Laravel products sit inside your scope, Cloud alone or Nightwatch too; does any workload touch health data and so need Private Cloud and a BAA; and which report period does your questionnaire ask for.