Laruna ← Back to site
Security overview

How we protect your business

The controls below are live in the platform today — designed to the standards independent auditors certify against, for both security (SOC 2, ISO 27001) and responsible AI (ISO 42001).

✓
Aligned to SOC 2, ISO 27001 & ISO 42001

Built and operated to the controls independent auditors certify against — SOC 2 and ISO 27001 for security, ISO 42001 for responsible AI. Formal, independent certification is available as part of an enterprise agreement.

✓
You stay in control of the AI

Nothing reaches your customers without an authorised approval — you choose how much runs automatically, and where it stops for you.

✓
Complete, tamper-evident audit trail

Every action the system or a person takes is permanently recorded and exportable — records can't be quietly altered.

✓
Least-privilege access

People get the minimum access their role needs; anything extra is time-boxed and expires automatically.

✓
Multi-factor authentication

Administrative accounts are protected by a second factor, not just a password.

✓
Automatic sign-out on inactivity + session limits

Unattended sessions sign out automatically after a period of inactivity (with a countdown warning first), and every session has a hard time limit — so a walked-away screen or a forgotten login can't be misused.

✓
Your data stays yours — and stays here

Hosted in Australia (dedicated instances available in your region — including deployment into AWS or Azure for enterprise requirements), fully separated per client, never used to train AI models, exportable if you ever leave.

✓
Encrypted connections & encrypted backups

Traffic is encrypted end-to-end; backups run nightly, encrypted, and are stored off the primary server.

✓
24/7 monitoring

Every service is watched around the clock — issues alert us immediately and we respond within your plan’s response times.

✓
Privacy law compliance

Built around the Australian Privacy Principles, including your customers' right to access and erasure.

✓
Responsible AI, by design

Human approval gates, fully audited AI actions and instant kill-switches — the controls emerging AI standards (ISO 42001, Australia's Voluntary AI Safety Standard) call for, built in from day one.

✓
Coordinated vulnerability disclosure

A published way for security researchers to report a flaw safely — acknowledged within 2 business days, and every report opens a tracked incident with the same fix clock as anything we find ourselves.

live in the platform today

Questions from your IT person or insurer? Ask for our full security overview →

Questions about security?

Book a free 30-minute call and we'll answer them straight — and map exactly how your data would be handled.

Start your free audit
Found a security issue?

Report it to security@laruna.ai and we'll acknowledge it within 2 business days. Good-faith research has safe harbour — our disclosure policy explains what to include, our response targets, and scope.

Report a security issue →
© 2026 Laruna. Built & run in Australia. Home · Privacy · Terms · Security · Report a security issue