
Organizations frequently ask, “Is Laserfiche secure?” Laserfiche® provides multiple layers of security to help organizations protect documents, records, and other sensitive information. These capabilities include encryption, detailed access controls, user authentication, auditing, monitoring, and tools that help organizations address security and compliance requirements.
Security is not based on one feature alone. A secure Laserfiche implementation combines the protections built into the platform with appropriate system configuration, access policies, user administration, and ongoing oversight.
Laserfiche administrators can control access based on users, groups, roles, folders, documents, and other repository objects. Fine-grained access rights and security tags can be used to limit who can view, modify, create, delete, or manage specific information.
This allows organizations to make information available to the employees who need it while restricting confidential employee, financial, legal, healthcare, or other sensitive records.
Laserfiche Cloud protects stored information using AES-256 encryption. Information transmitted to and from Laserfiche Cloud is protected using secure encryption protocols while in transit.
Laserfiche Cloud also supports single sign-on through SAML and identity providers such as Microsoft Entra ID and Okta, helping organizations apply centralized authentication and account-management policies.
Laserfiche auditing capabilities help organizations track activity involving documents and other repository objects. Audit information can include actions such as viewing, creating, modifying, and deleting documents, along with changes to metadata and other content.
These audit trails can support internal oversight, investigations, records management, and compliance efforts.
Laserfiche Cloud includes security controls such as intrusion detection, vulnerability scanning, firewall protections, distributed denial-of-service protection, and third-party penetration testing. Available security and resilience capabilities vary by Laserfiche Cloud subscription, package, and region.
Qualifying Laserfiche Cloud offerings can also provide enhanced capabilities such as FIPS 140-3 cryptographic modules, advanced monitoring, repository snapshots, configurable security policies, and multi-region disaster recovery.
Laserfiche maintains security certifications and provides controls designed to help organizations address a range of regulatory and industry requirements. Current Laserfiche documentation includes:
Important: Certifications and platform capabilities do not automatically make every implementation compliant. Each organization should evaluate its requirements, select the appropriate Laserfiche offering, and configure and administer the system accordingly.
Laserfiche is available as a cloud service or as a self-hosted system. With Laserfiche Cloud, Laserfiche manages the underlying cloud infrastructure and associated platform protections. With a self-hosted deployment, the customer is responsible for securing and maintaining its servers, operating systems, databases, network, backups, and related infrastructure.
Nine Peaks Solutions can help organizations evaluate deployment options, plan permissions, configure access controls, and implement Laserfiche based on their operational and security requirements.
Review Laserfiche Security, Trust, and Compliance information →
Nine Peaks Solutions is a Laserfiche Solution Provider helping organizations plan, implement, secure, and support Laserfiche Cloud and self-hosted systems. We can help you evaluate deployment options and configure Laserfiche based on your organization’s security and operational requirements.
Request a Laserfiche Demonstration