Skip to content
Lazlo is an AI-first engineering partner for enterprises building mission-critical software.
Lazlo
TRUST CENTER

Security and compliance, in detail — not in badges

Security is part of the initial design, not a hardening pass before launch. Here's exactly where we stand today, stated honestly.

SECURITY PRACTICES

What we build against today

Encryption

In transit (TLS) and at rest for stored data.

Tenant isolation

Logical isolation designed into multi-tenant products from the start.

Access control

Role-based access, least-privilege, and audit logging of changes.

GDPR-aligned

Built on GDPR data-protection principles.

COMPLIANCE ROADMAP

Where we are, and what's next

Today

ISO 27001-aligned practices

We build against the controls today; no formal audit is complete yet.

Today

GDPR principles

Data-protection principles applied to how we handle personal data.

Roadmap

SOC 2 Type II

Planned. We will publish the report the day it is actually issued — never before.

Roadmap

ISO 27001 certification

Planned alongside SOC 2 as the team and product mature.

We will display an actual certification badge the day an actual audit report exists, and not before.

DATA HANDLING

How we treat your data

  • Data is encrypted in transit and at rest.
  • Access is least-privilege and logged.
  • We don't sell or share client data.
  • Sub-processors are disclosed on request; a public list is published as the vendor set stabilises.
ENGAGEMENT

NDA before any technical discussion

We sign an NDA before any technical discussion — happy to send ours first. Security questionnaires and architecture reviews are part of how we start, not an afterthought.

Responsible disclosure

Found a security issue? Email lazlosoftwaresolution@gmail.com and we'll respond promptly.

Need our security overview or a signed NDA?

Tell us your requirements and we'll respond directly.

No obligation · A senior engineer replies within 1 business day · NDA on request