Security & Privacy Policy (Laragon App)
Last updated: March 16, 2026
Laragon is designed with your privacy in mind. We believe developers deserve a tool that respects their data and works completely offline.
Offline First
Laragon is an offline-first development environment. Once downloaded and installed, Laragon works completely offline without requiring an internet connection:
- No account required to use Laragon
- No internet connection needed to run your local development environment
- All features work locally - create sites, manage databases, and develop applications offline
- No dependency on cloud services for core functionality
- Perfect for working in restricted network environments or while traveling
No Telemetry
Unlike many modern development tools, Laragon does not collect any telemetry data:
- No usage tracking - We don't monitor how you use Laragon
- No behavior analytics - Your development patterns stay private
- No crash reporting - We don't collect crash data or error reports
- No feature usage statistics - Which features you use is your business
Privacy Respect
We believe in minimal data collection and maximum user privacy:
- No third-party analytics - No Google Analytics, Mixpanel, or similar tracking. Same for laragon.org
- No data selling - We never sell your information to anyone
- No profiling - We don't build profiles based on your usage
- Your code stays yours - All your projects, files, and data remain 100% local
Software Security
Laragon is designed with security best practices in mind:
- All downloads are served over HTTPS to ensure secure file transfer
- We regularly update Laragon to address security vulnerabilities
- Our software does not include any malicious code or backdoors
- Open binary - anyone can audit our binaries on GitHub
- Community-reported security issues are promptly investigated and addressed
Digitally Signed Binaries
All Laragon executables are digitally signed to ensure authenticity and integrity:
- laragon.exe - Digitally signed to verify it comes from Laragon
- laragon-wamp.exe - Code signed to guarantee the installer hasn't been tampered with
- You can verify the signature by right-clicking the file, selecting Properties, and checking the Digital Signatures tab
- Digital signatures protect against malware impersonation and man-in-the-middle attacks
Antivirus Exclusion for Better Performance
Excluding the Laragon folder from your antivirus will boost performance tremendously and help Laragon work smoothly without interruptions.
Laragon is a development environment that creates and manages thousands of files and processes. Antivirus real-time scanning can significantly slow down:
- File operations and Git operations
- PHP/Node.js compilation and bundling
- Server startup and response times
- Database queries and migrations
- Package manager installations (npm, composer, etc.)
How to add exclusion:
- Location: Usually
C:\laragon (or your custom installation path) - How: Open your antivirus settings, add the Laragon folder to the exclusion/exception list
This will boost performance tremendously and ensure Laragon works smoothly without antivirus-induced slowdowns.
Website Security
Our website employs industry-standard security measures:
- SSL/TLS encryption for all data transmission
- Secure payment processing through Lemon Squeezy, our Merchant of Record
- Regular security audits and vulnerability scanning
- Protection against common web attacks (XSS, CSRF, SQL injection)
API Security
Laragon Key validation and verification is handled via our secure API at api.laragon.org. Our APIs are built with modern security best practices:
- Authentication & Access Control - Secure key-based authentication with proper authorization checks
- Encrypted Communication - TLS 1.2 and TLS 1.3 for all API traffic
- Strict Input Validation - All input data is rigorously validated to prevent injection attacks
- Tamper Detection - URL parameters are validated to detect any manipulation attempts
- Proper Exception Handling - Errors are handled securely without exposing sensitive information
- Read-Only Access - Only GET requests are allowed for key verification
Firewall Settings for License Activation
To activate and verify your Laragon license key, ensure your firewall allows connections to api.laragon.org:
- Why: License validation requires communication with our secure API server
- Port: HTTPS (port 443)
- Domain:
api.laragon.org
If your firewall blocks this connection, you may experience issues with license activation or verification. Add api.laragon.org to your firewall's allowed domains or create an outbound rule for HTTPS traffic to this domain.
Payment Security
All payment transactions are processed securely through Lemon Squeezy:
- PCI DSS compliant payment processing
- No credit card information is stored on our servers
- Secure checkout with industry-standard encryption
- Access to Lemon Squeezy's Data Processing Agreement (DPA)
Reporting Security Issues
If you discover a security vulnerability in Laragon, we encourage you to report it responsibly:
- Contact us at [email protected] with details of the vulnerability
- Allow reasonable time for us to address the issue before public disclosure
- Avoid exploiting the vulnerability for any purpose
- We appreciate responsible disclosure and will acknowledge your efforts
- See our Security Policy on GitHub for more details
Your Data, Your Control
With Laragon, you have complete control over your development environment:
- All project files stay on your machine
- Database data is stored locally
- No cloud sync or remote storage required
- Full control over backups and data retention
Changes to This Policy
We may update this Security & Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
Contact Us
If you have any questions about our security or privacy practices, please contact us at:
Email: [email protected]
SSL Grade A+
We take security very seriously. Our SSL/TLS configuration has been tested and rated A+ by SSL Labs:

laragon.org - Grade A+

api.laragon.org - Grade A+
Thank you for trusting Laragon. Your privacy and security are our priority.