Security questionnaire answers
Pre-answered responses to the questions vendor security assessments ask most often, so a review can be completed without a call.
Last updated
These are the questions we are asked most often in vendor security reviews, answered in advance. If your questionnaire asks something not covered here, send it to support@laya.net — we would rather answer it directly than have you infer.
The questions, answered
Do you hold SOC 2, ISO 27001 or similar certification?
Not at present. We publish our control set in full instead — see the security programme — and we will list any formal report here when one exists. We would rather tell you plainly than imply an audit we have not had.
Where is our data hosted?
On Amazon Web Services in the United States. Laya is operated from the United Kingdom. See international data transfers.
Is data encrypted in transit and at rest?
In transit, yes, on all traffic, with HSTS enforced. At rest, connection credentials and webhook signing secrets are encrypted with AES-256-GCM, and passwords are hashed. Managed storage and backups inherit the provider’s encryption at rest.
Do you use our data to train AI models?
No. Never, and neither does the AI provider we use. Only the specific content a member chooses to run an AI action on is sent, and AI features are optional.
Do you sell or share personal data for advertising?
No.
Who can access our data internally?
Access to production data is limited to those who need it to operate and support the service, and personnel are under a duty of confidentiality.
Do you support single sign-on and multi-factor authentication?
Social sign-in is available with Atlassian, Azure DevOps, Google, Microsoft and Slack. Two-factor authentication is available with passkeys, authenticator apps and recovery codes, and once enabled it is enforced on every route in, including magic links and social sign-in. SAML-based enterprise SSO is not available today — ask us if you need it.
Can we restrict who connects external tools?
Yes. Connecting, mirroring and disconnecting require the connectors:manage capability, held by workspace Owners and Admins.
What happens to our data if we leave?
Export at any time; on termination we delete or return customer content at your choice. Disconnecting a tool deletes Laya’s mirror of it immediately. See data retention and deletion.
Do you have a DPA we can sign?
Yes — the full terms are published at Data Processing Agreement, and a countersigned copy is available from privacy@laya.net.
How quickly are breaches notified?
Without undue delay after we become aware, with the information you need to meet your own 72-hour duty. See incident response.
Has the application been penetration tested?
Yes. Laya has undergone penetration testing of the application and its APIs, and has run a structured multi-round adversarial security review across authentication, access control, tenancy isolation, injection, sharing and data exposure. Findings are triaged by severity and tracked to closure. Ask support@laya.net if your assessment needs dates, scope or a findings summary.
Do you have a vulnerability disclosure process?
Yes — report to support@laya.net with "Security report" in the subject. We do not pursue researchers acting in good faith. See the security programme.
Is there an audit log?
Workspace administrators have an Audit view recording membership changes and other significant workspace actions.
Can data be hosted in the UK or EU?
Not today — there is one hosting region. Tell us if you need residency and we will be honest about whether and when we can offer it.
Email support@laya.net — include what you expected, what happened, and a link to the affected board or item so we can help quickly.