§ Trust & Safety

Security

This page exists because technical buyers read the source code of the privacy policies. Here is how MY LAURA actually protects your data, in plain language, without the word 'enterprise-grade' anywhere.

// Last updated April 2026

Where your data lives

MY LAURA runs on SOC 2 Type II-certified infrastructure in US-based data centers. Your data never leaves the United States for hosting purposes.

Encryption

All data is encrypted in transit via TLS 1.2 or higher. All data at rest in the database is encrypted using AES-256. Backups are encrypted the same way. The only "at rest" data that isn't encrypted is public-facing marketing content (the pages on this site).

Authentication

MY LAURA uses OAuth 2.0 for session management. Passwords are salted and hashed with an industry-standard algorithm. Two-factor authentication is available for any account and required for team members with Admin roles.

When you connect MY LAURA to QuickBooks Online or Google Drive, the integration uses OAuth 2.0 with scope-limited permissions. We request the minimum scopes required for the feature to work. You can revoke access at any time from your integration settings.

Data ownership

You own your data. Full stop. MY LAURA has a limited license to host and display your content so the product works. That license terminates when you cancel. We do not:

  • Train AI models on your data
  • Sell your data to anyone
  • Share your data with third parties outside the services you've explicitly connected (QuickBooks, Google, Stripe) or the backend infrastructure providers that operate MY LAURA (listed below)
  • Use your data for anything other than operating the product you're paying for

Data export and portability

You can export all your data at any time as CSV or JSON from the settings page. That includes estimates, invoices, change orders, projects, clients, trade partners, and reports. If you cancel MY LAURA, your account remains fully active through the end of the billing period you have already paid for — export anything you need before that period ends, because access is not provided after the account closes.

Your Google Drive files stay in your Drive — we never moved them to ours. Your QuickBooks data stays in QuickBooks. We built MY LAURA to be a tool you use, not a hostage situation.

Access control

MY LAURA has three built-in roles:

  • Admin — full access to everything in the account
  • Estimator — can create and manage estimates, projects, and clients; limited financial visibility
  • Bookkeeper — access to invoices, payments, reports, and QuickBooks sync; limited project management

Team members only see what their role permits. Action logs track who did what, when, for audit purposes.

Backups and recovery

The production database is backed up continuously with point-in-time recovery, and daily full snapshots are retained for 30 days. In the event of a database failure, we can restore to any point within the last 30 days within 15 minutes.

Incident response

If we discover a security incident that affects your data, we commit to:

  1. Notifying affected users within 72 hours of confirmed impact
  2. Publishing a public post-mortem for any incident that affects more than one account
  3. Providing detailed guidance on what was exposed, what wasn't, and what you should do

We have never had a data breach. If that changes, you'll see it on this page and in your inbox within 72 hours.

Third-party security

MY LAURA relies on a small number of third-party services for critical infrastructure. Each one is chosen for its own security posture:

  • Render — SOC 2 Type II certified, application hosting
  • Supabase — SOC 2 Type II certified, built on AWS us-east
  • Vercel — SOC 2 Type II certified, marketing site CDN
  • Stripe — PCI DSS Level 1 certified, payment processing
  • Resend — SOC 2 Type II certified, outbound transactional email (backend integration)
  • SendGrid — SOC 2 Type II certified, inbound email-to-lead parsing only
  • Google — Drive OAuth integration
  • Intuit — QuickBooks Online OAuth integration

Responsible disclosure

If you find a security vulnerability in MY LAURA, please email laura@getmylaura.com. We investigate every report, respond within 48 hours, and credit researchers who disclose responsibly.

We are a small team — it will be a real human (usually Laura) who reads your report, not a ticket queue.


Questions about security? Email laura@getmylaura.com. If you need a signed questionnaire for your enterprise procurement process, we can accommodate that — just ask.