Compliance Guides

Laravel Compliance, Explained for Developers

SOC 2, HIPAA, PCI DSS, and ISO 27001 all require continuous security monitoring and documented evidence of controls. These guides map each standard's requirements to specific Laravel configurations — and show what StackShield monitors automatically.

SOC 2 Type II

SOC 2 for Laravel Applications

SOC 2 Type II requires auditable evidence of security controls over a 6–12 month period. This guide maps the Trust Service Criteria to specific Laravel configurations and tells you exactly what evidence auditors ask for.

  • Trust Service Criteria mapped to Laravel
  • MFA enforcement, session controls, access policies
  • Audit logging with Laravel's Log facade
  • How StackShield satisfies CC6.x and CC7.x
Read the SOC 2 guide
HIPAA Security Rule

HIPAA for Laravel Applications

If your Laravel application stores or processes Protected Health Information, you need specific technical safeguards. This guide covers every HIPAA Security Rule requirement that affects PHP developers, with working code.

  • Access controls, audit logs, auto-logoff
  • Field-level PHI encryption with Attribute casting
  • Transmission security: TLS enforcement via nginx
  • Breach notification: the 60-day rule explained
Read the HIPAA guide
PCI DSS v4.0

PCI DSS for Laravel Applications

PCI DSS v4.0 became mandatory in March 2025. This guide maps the 12 requirements to your Laravel stack, explains SAQ types, and shows how to reduce scope using tokenisation — so you only comply with what actually applies.

  • Scope reduction via Stripe/Braintree tokenisation
  • All 12 requirements mapped to Laravel specifics
  • SAQ A vs A-EP vs D: which applies to you
  • Vulnerability scanning cadence for Requirement 11
Read the PCI DSS guide
ISO 27001:2022

ISO 27001 for Laravel Applications

ISO 27001 requires an Information Security Management System with 93 Annex A controls. This guide focuses on the Technological controls that directly affect Laravel developers — access management, logging, cryptography, secure development.

  • Annex A controls mapped to Laravel implementations
  • Risk register template for a Laravel SaaS
  • Evidence collection guide for ISO 27001 auditors
  • Common gaps Laravel teams fail on
Read the ISO 27001 guide

How StackShield Supports Compliance

Every compliance standard requires continuous monitoring and documented evidence. StackShield automates the external monitoring layer and generates audit-ready scan history.

Continuous Monitoring Evidence

SOC 2 CC7.x, ISO 27001 A.8.16, and PCI DSS Requirement 10 all require continuous security monitoring. StackShield's timestamped scan history is directly presentable to auditors.

Exportable Audit Reports

Pull historical scan data for any date range and export it as compliance evidence. Show auditors your security posture on any specific date — including the day you deployed a new feature.

Misconfiguration Alerts

Every compliance standard requires that security misconfigurations are caught and remediated promptly. StackShield alerts you within minutes of a deployment that introduces a new issue.

Start Building Compliance Evidence Today

StackShield monitors your Laravel application continuously from the outside — generating the audit trail that compliance frameworks require, automatically.

No credit card required until your trial ends.