Compliance frameworks, security audits, and quality certifications this company maintains.
LaunchDarkly maintains SOC 2 Type II certification with annual audits covering the security, availability, and confidentiality of feature flag configuration data, targeting rules, and flag evaluation event streams processed on behalf of its enterprise engineering customers.
LaunchDarkly holds ISO 27001 certification, demonstrating that its information security management system for protecting flag configuration, SDK keys, and customer targeting data meets international information security standards.
Regulatory
FedRAMP Moderate
CertifiedLaunchDarkly achieved FedRAMP Moderate Authorization, enabling US federal agencies, defense contractors, and government technology vendors to use LaunchDarkly feature management for controlled unclassified information in compliance with NIST 800-53 security controls.
LaunchDarkly complies with GDPR for European customers by providing data processing agreements, configurable data residency options, and SDK-level controls that allow engineering teams to prevent personal user attributes from being sent to LaunchDarkly flag evaluation infrastructure.
LaunchDarkly honors CCPA rights for California residents, providing data deletion request mechanisms and documentation of what user context data is processed through LaunchDarkly SDKs on behalf of its customers for feature flag targeting.
LaunchDarkly supports HIPAA-eligible deployments for healthcare engineering teams through Business Associate Agreements on Enterprise plans, enabling hospitals and health tech companies to use feature flag targeting rules that reference patient or provider attributes without HIPAA violations.
LaunchDarkly maintains CSA STAR certification, publishing its cloud security controls in the Cloud Security Alliance registry to provide enterprise customers with transparency into how flag evaluation infrastructure, SDK key management, and customer data are protected.
LaunchDarkly meets WCAG 2.1 AA accessibility guidelines across its feature management dashboard, ensuring that developers and product managers with disabilities can fully access flag configuration, targeting rule management, and experiment analysis interfaces.
Security
Penetration Testing
CompliantLaunchDarkly undergoes annual third-party penetration tests of its web application, API endpoints, and flag evaluation infrastructure, with findings triaged and remediated as part of ongoing SOC 2 and FedRAMP continuous monitoring obligations.
LaunchDarkly participates in cross-border data transfer frameworks ensuring that customer flag configuration data, SDK evaluation events, and user context attributes transferred between the US and EU are handled under appropriate legal mechanisms including Standard Contractual Clauses.