securityprivacycompliancecompanylaunch

Trust Is Built In: Launching the LaserData Trust Center

LaserData is now ISO/IEC 27001:2022 certified, SOC 2 Type II, and GDPR compliant, a milestone rooted in how we have built from day one.

Kranti Parisa
Kranti Parisa
Co-founder & CEO

Today, we are launching the LaserData Trust Center—a public home for our security, privacy, compliance, and operational practices.

We are also proud to share three important milestones:

  • ISO/IEC 27001:2022 certified
  • SOC 2 Type II compliant
  • GDPR compliant

These achievements matter. They give customers independent evidence that the controls behind LaserData are not just described in architecture diagrams or promised in sales conversations. They are documented, tested, audited, and operated over time.

But for us, this is not the beginning of the security journey. It is a checkpoint in a journey that started before the first line of LaserData code was written.

The lesson we carried from Apple

Before LaserData, I spent years at Apple leading search, personalization, and real-time AI/ML workloads at internet scale. At that scale, infrastructure disappears when it works and becomes the product when it does not.

A few extra milliseconds can change a customer experience. A poorly isolated service can turn one failure into a much larger incident. A shortcut in access control, deployment, or data handling can create risks that no feature work can repair after the fact.

The deeper lesson was simple: security and privacy are product decisions, not features.

They cannot be added at the end of a roadmap as a layer around the system. They live in the boundaries between services, the direction in which connections are allowed to open, the scope of a credential, the way a binary is verified, the data an operator can access, and the evidence left behind when something changes.

That experience shaped how we approached LaserData. We did not begin by asking how to make an existing architecture pass an audit. We began by asking what architecture we would want to trust with our own production data.

Architecture before attestations

LaserData moves and manages data for real-time, AI-native, and event-driven systems. That places security directly on the critical path. Streams can carry sensitive operational context. Agent workflows can coordinate consequential actions. State and memory can outlive the request that created them. Protecting that data is part of delivering the platform correctly.

So we made a set of architectural choices early, even when the less secure alternative might have been easier to build.

Every deployment is isolated. Customer deployments run on dedicated virtual machines with their own storage and network path. We do not place multiple non-free tier customers on shared VMs, filesystems, or serverless data paths. Isolation is not a premium add-on; it is the default operating model.

Management is pull-only. The Warden agent running on each node initiates outbound HTTPS communication with the LaserData control plane. The control plane cannot open an inbound management connection or push commands directly into a deployment. Tasks are queued, pulled, and cryptographically verified before execution. There is no standing SSH or SSM path for us to fall back on.

Access begins closed. New deployments start without an open network path. Customers explicitly define which IP ranges and protocols can reach an endpoint, with private networking options such as VPC peering, AWS PrivateLink, and GCP Private Service Connect available for deployments that need to remain off the public internet.

Encryption and integrity exist at every layer. Connections use TLS, persisted messages can be encrypted before write, release binaries and control-plane tasks are signed, and deployment certificates are scoped and rotated automatically. The goal is not simply to protect data in transit or at rest, but to verify the software and instructions operating on that data as well.

Identity is narrow and accountable. We use SSO instead of storing user passwords. API keys are scoped, expire, can be IP-restricted, and can be revoked immediately. Administrative changes and security-sensitive operations are recorded with an actor and timestamp.

BYOC means your boundary remains yours. In a Bring Your Own Cloud deployment, LaserData uses a deliberately scoped cloud role for provisioning. The virtual machines, disks, VPC, and data remain in the customer's account, and that access can be revoked by the customer.

None of these choices exists solely because a compliance framework asks for it. They exist because they reduce the number of ways a system can fail its users. The frameworks helped us turn those engineering decisions into a disciplined, repeatable operating program.

What the milestones mean

The three milestones announced today look at different parts of that program.

ISO/IEC 27001:2022 certifies our information security management system: how we identify risk, assign responsibility, operate controls, respond to incidents, and continuously improve. It connects engineering practice to a company-wide system of accountability.

SOC 2 Type II examines whether relevant controls were not only designed appropriately, but operated effectively over an evaluation period. That distinction matters to infrastructure customers. A written policy is useful; evidence that the process is followed consistently is much more useful.

GDPR compliance formalizes our responsibilities around personal data, including how data is handled, protected, retained, and governed. Privacy is not only a legal obligation. It is part of the trust contract between a platform and every person whose data may pass through it.

Together, these milestones validate a broad program spanning secure software development, infrastructure management, access control, encryption, monitoring, incident response, business continuity, vendor management, and employee practices.

Why launch a Trust Center

Security should be inspectable.

Enterprise security reviews often begin with the same reasonable questions: Where does our data live? Who can reach it? How is access reviewed? What happens during an incident? Which vendors are involved? Which controls are continuously monitored? Can we see the policies and reports behind the claims?

The LaserData Trust Center gives customers and partners one place to find those answers. It brings together our compliance status, control program, security and privacy resources, and subprocessor information. Where a document requires appropriate access, customers can request it through the same center.

This is not a static badge page. It is the public surface of a living program. Controls are monitored, policies are reviewed, evidence is maintained, risks are reassessed, and the program evolves as the platform and the threat landscape change.

Compliance is a floor, not a finish line

Reaching this point required sustained work across engineering, infrastructure, operations, legal, and company processes. It forced us to make implicit knowledge explicit, turn good habits into repeatable controls, document ownership, test our response plans, and produce evidence that stands up outside our own team.

That work made LaserData better. It also made clear why certification cannot be treated as a one-time project.

Threats change. Products change. Teams change. A control that worked for yesterday's architecture may not be enough for tomorrow's. Our job is to keep the security program moving with the platform without weakening the principles underneath it.

Those principles remain straightforward:

  • Minimize access before monitoring access.
  • Isolate failure domains before relying on detection.
  • Make secure behavior the default path.
  • Keep customer data out of the control plane wherever possible.
  • Leave an auditable record of consequential actions.
  • Be clear about what we can protect, how we protect it, and where responsibility is shared.

The Trust Center makes those commitments easier to examine. ISO/IEC 27001:2022, SOC 2 Type II, and GDPR compliance give customers independent assurance that the operating system behind those commitments is real.

We are proud of this milestone. More importantly, we are proud that it reflects the way LaserData was designed from the beginning.

Security and privacy are not features we ship once. They are part of the product we operate every day.

Visit the LaserData Trust Center →