Skip to content
For the complete Netlify documentation index, see llms.txt. Markdown versions of any documentation page are available by appending .md to its URL.

More flexibility and credits now available for Pro plans 🎉

Security overview

Netlify can meet the complex security and compliance needs of Enterprises and cross-functional teams with customizable access to production and preview sites, SAML SSO login, SCIM provisioning, role-based access control, Firewall traffic rules, and more.

If you have an Enterprise plan, you can improve your team’s security and reduce your vulnerabilities by reviewing the Security Scorecard for your Enterprise team.

You can also check out the security checklist for more details on how Netlify can improve your security.

Customize access control for your sites with a password prompt, login credentials, or based on site visitors’ IP address or location.

Block traffic to your site with Firewall traffic rules and set custom rate limits with our rate limiting rules.

Learn more about Secure access to sites.

Protect your domains from unauthorized takeovers. You can lock your domain to prevent unauthorized changes by other accounts.

Secure how people can access your Netlify team, resources, and sensitive information with these security features:

  • SAML SSO login through an identity provider
  • SCIM Directory Sync to provision users
  • Secrets Controller, which allows you to protect your most sensitive secrets
  • Role-based access control
  • Enforce 2FA

Learn more about Secure access to Netlify

Netlify’s Frontend Cloud has a reduced attack surface, offering security by design.

Netlify also offers these security features to help you stay secure as you scale:

Even if a malicious attacker tries to take down your site, our global infrastructure and automated DDoS protection can keep your site available.

Netlify automatically detects distributed denial-of-service (DDoS) attacks and will rate limit and block malicious clients from connecting to sites hosted on our servers.

Our edge network mitigates malicious clients from impacting network performance in several ways, including:

  • Global load balancing: routes traffic strategically amongst our many servers. Netlify manages these servers to ensure capacity grows as needed.
  • Automatic DDoS detection: automatically identifies anomalous clients that pose a risk to your site’s availability.
  • Automatic rate limiting & blocking: mitigates attacks by rate limiting and blocking identified clients from connecting to sites deployed on Netlify and hosted on our servers.
  • SOC 2 Type II: annual independent audit
  • ISO 27001: information security management certification
  • ISO 27018: protection of personally identifiable information in public cloud environments
  • PCI DSS v4.0: payment card industry compliance
  • HIPAA: HIPAA-compliant service offering with a Business Associate Agreement (BAA)
  • GDPR and CCPA: data protection and privacy compliance
  • EU-US DPF and Swiss-US DPF: EU-U.S. and Swiss-U.S. Data Privacy Framework participation
  • VPAT: Voluntary Product Accessibility Template

For the latest compliance updates, learn more about our Trust Center.

Anyone with a Netlify account can access the Trust Center, on any plan and with any role.

For an overview of Netlify’s compliance certifications, our compliance documents, and our subprocessor list, check out the Trust Center overview, which is publicly available.

Once you sign in with your Netlify account, you can:

  • download the reference architecture document for building HIPAA-compliant sites on Netlify
  • download the subprocessor list as a PDF or CSV file
  • review the list of Netlify network locations
  • request access to more sensitive compliance documents if not already granted

Some documents require you to request access before you can download them. To download these documents, you need both:

  • An approved access request. You can have one open request per account. Enterprise accounts with an NDA on file with Netlify are approved automatically.
  • An executed NDA with Netlify, either for your email address or for your whole email domain.

Once access is granted, you’ll get an email letting you know you now have access.

You can also check your access from the Netlify dashboard at app.netlify.com when you go to User settings > Trust Center.

User settings menu open in the bottom left of the Netlify dashboard

Approval applies to your email address or your email domain and unlocks all documents that require access, not just the one you requested.

Downloaded documents are watermarked with your email address, and each download link expires after 5 minutes.

To find where Netlify’s global edge network serves traffic from, check the list of network locations in the Trust Center. Learn more about the Trust Center and how to access it.

To ensure that Netlify can quickly contact you about potential abuse, fraud, or other security incidents, add at least one email address as an incidents contact. If you have an organization, you can only add a contact in your organization settings.

  1. As a Team Owner, go to Team settings General Primary Contacts, then select Edit contacts.

  2. Add at least one email address as a primary contact for security, abuse, or fraud incidents.

If your team is a part of an organization, you can only add contacts in your organization settings.

  1. As an Organization Owner, select your organization name in the navigation and then select Organization overview.

  2. Select your Organization’s Settings page, go to Primary contacts, then select Edit contacts.

  3. Add at least one email address as a primary contact for security, abuse, or fraud incidents. This contact info will appear as read-only in team settings.