Offering

Trust Center

Security, privacy and compliance are the foundation of our product. This Trust Center documents transparently how Laioutr handles your data, what technical and organisational measures are in place, and which artefacts we provide for your security reviews.

Security, privacy and compliance are the foundation of our product. This Trust Center documents transparently how Laioutr handles your data, what technical and organisational measures are in place, and which artefacts we provide for your security reviews.

At a glance

Laioutr is a agentic frontend management platform for composable commerce headquartered in Germany. We process customer data exclusively as a processor (Art. 28 GDPR). Our production infrastructure runs in EU regions on certified cloud providers.

  • Company: Laioutr GmbH, Münchweilersteig 5, 12559 Berlin
  • Products: Laioutr Cloud, Laioutr Cockpit, Laioutr Frontend
  • Hosting region: European Union (Frankfurt, Germany)
  • Applicable law: GDPR, BDSG, German law
  • Security & privacy contact: security@laioutr.com
  • Live status: laioutr.statuspage.io

Where your data lives

The diagram below shows the high-level data flow for Laioutr customers. All content data stays in the EU. Only live cursor positions for real-time collaboration in the Cockpit are processed globally — without any reference to your content or end-customer data.

Explore the Trust Center

Data Protection (GDPR)

Our role under the GDPR, Data Processing Agreement, DPO contact, and international data transfers.

Subprocessors

The full list of subprocessors, their purpose, processing location and certifications.

Infrastructure & Hosting

Architecture, primary subprocessors (Vercel, Supabase, Upstash, Liveblocks) and how we keep your content in the EU.

Security Measures

Technical and organisational measures (TOMs) under Art. 32 GDPR — public summary.

Incident Response

How we handle security incidents and how to report a vulnerability.

Compliance & Certifications

Laioutr's certification status and the inherited certifications of our infrastructure stack.

FAQ

Common questions on data residency, exports, availability, access, and contracts.

Documents available on request

Under a signed mutual NDA we provide:

  • Data Processing Agreement (DPA / AVV)
  • Technical and Organisational Measures (TOMs)
  • Subprocessor list with executed DPAs
  • Transfer Impact Assessments (TIAs) for US-based subprocessors

Request a document or send a security questionnaire: security@laioutr.com

Contact & resources

TopicContact / link
General security questionssecurity@laioutr.com
Data protectiondatenschutz@laioutr.com
Vulnerability disclosuresecurity@laioutr.com
Customer support (S3 / S4)support.laioutr.com
Incident reporting (S1 / S2)incident@laioutr.com
Live platform statuslaioutr.statuspage.io

Last updated: 2026-05-25 · Version 1.0

Copyright © 2026 Laioutr GmbH