Security and compliance, in detail — not in badges
Security is part of the initial design, not a hardening pass before launch. Here's exactly where we stand today, stated honestly.
What we build against today
Encryption
In transit (TLS) and at rest for stored data.
Tenant isolation
Logical isolation designed into multi-tenant products from the start.
Access control
Role-based access, least-privilege, and audit logging of changes.
GDPR-aligned
Built on GDPR data-protection principles.
Where we are, and what's next
ISO 27001-aligned practices
We build against the controls today; no formal audit is complete yet.
GDPR principles
Data-protection principles applied to how we handle personal data.
SOC 2 Type II
Planned. We will publish the report the day it is actually issued — never before.
ISO 27001 certification
Planned alongside SOC 2 as the team and product mature.
We will display an actual certification badge the day an actual audit report exists, and not before.
How we treat your data
- Data is encrypted in transit and at rest.
- Access is least-privilege and logged.
- We don't sell or share client data.
- Sub-processors are disclosed on request; a public list is published as the vendor set stabilises.
NDA before any technical discussion
We sign an NDA before any technical discussion — happy to send ours first. Security questionnaires and architecture reviews are part of how we start, not an afterthought.
Responsible disclosure
Found a security issue? Email lazlosoftwaresolution@gmail.com and we'll respond promptly.
Need our security overview or a signed NDA?
Tell us your requirements and we'll respond directly.
No obligation · A senior engineer replies within 1 business day · NDA on request