For the complete Netlify documentation index, see llms.txt. Markdown versions of any documentation page are available by appending .md to its URL. Netlify can meet the complex security and compliance needs of Enterprises and cross-functional teams with customizable access to production and preview sites, SAML SSO login, SCIM provisioning, role-based access control, Firewall traffic rules, and more.
Check your security posture
Section titled “Check your security posture”If you have an Enterprise plan, you can improve your team’s security and reduce your vulnerabilities by reviewing the Security Scorecard for your Enterprise team.
You can also check out the security checklist for more details on how Netlify can improve your security.
Secure access to sites
Section titled “Secure access to sites”Customize access control for your sites with a password prompt, login credentials, or based on site visitors’ IP address or location.
Block traffic to your site with Firewall traffic rules and set custom rate limits with our rate limiting rules.
Learn more about Secure access to sites.
Secure your domains
Section titled “Secure your domains”Protect your domainsdomainsThe web address people use to visit your site, such as yoursite.com. from unauthorized takeovers. You can lock your domain to prevent unauthorized changes by other accounts.
Secure Netlify access
Section titled “Secure Netlify access”Secure how people can access your Netlify team, resources, and sensitive information with these security features:
- SAML SSO login through an identity provider
- SCIM Directory Sync to provision users
- Secrets ControllerSecretsSensitive credentials, like passwords and API keys, that must be kept private., which allows you to protect your most sensitive secrets
- Role-based access control
- Enforce 2FA
Learn more about Secure access to Netlify
Secure by design and at scale
Section titled “Secure by design and at scale”Netlify’s Frontend Cloud has a reduced attack surface, offering security by design.
Netlify also offers these security features to help you stay secure as you scale:
- Proactive DDoS monitoring
- Content Security Policy
- Log Drains
- Data encrypted at rest with AES-256 or stronger
- Traffic encrypted in transit with TLS 1.2 or greater
- Private Connectivity
Support against DDoS attacks
Section titled “Support against DDoS attacks”Even if a malicious attacker tries to take down your site, our global infrastructure and automated DDoS protection can keep your site available.
Netlify automatically detects distributed denial-of-service (DDoS) attacks and will rate limit and block malicious clients from connecting to sites hosted on our servers.
Our edge network mitigates malicious clients from impacting network performance in several ways, including:
- Global load balancing: routes traffic strategically amongst our many servers. Netlify manages these servers to ensure capacity grows as needed.
- Automatic DDoS detection: automatically identifies anomalous clients that pose a risk to your site’s availability.
- Automatic rate limiting & blocking: mitigates attacks by rate limiting and blocking identified clients from connecting to sites deployed on Netlify and hosted on our servers.
Compliance and Certifications
Section titled “Compliance and Certifications”- SOC 2 Type II: annual independent audit
- ISO 27001: information security management certification
- ISO 27018: protection of personally identifiable information in public cloud environments
- PCI DSS v4.0: payment card industry compliance
- HIPAA: HIPAA-compliant service offering with a Business Associate Agreement (BAA)
- GDPR and CCPA: data protection and privacy compliance
- EU-US DPF and Swiss-US DPF: EU-U.S. and Swiss-U.S. Data Privacy Framework participation
- VPAT: Voluntary Product Accessibility Template
For the latest compliance updates, learn more about our Trust Center.
Access the Trust Center
Section titled “Access the Trust Center”Anyone with a Netlify account can access the Trust Center, on any plan and with any role.
For an overview of Netlify’s compliance certifications, our compliance documents, and our subprocessor list, check out the Trust Center overview, which is publicly available.
Once you sign in with your Netlify account, you can:
- download the reference architecture document for building HIPAA-compliant sites on Netlify
- download the subprocessor list as a PDF or CSV file
- review the list of Netlify network locations
- request access to more sensitive compliance documents if not already granted
Some documents require you to request access before you can download them. To download these documents, you need both:
- An approved access request. You can have one open request per account. Enterprise accounts with an NDA on file with Netlify are approved automatically.
- An executed NDA with Netlify, either for your email address or for your whole email domain.
Once access is granted, you’ll get an email letting you know you now have access.
You can also check your access from the Netlify dashboard at app.netlify.com when you go to User settings > Trust Center.

Approval applies to your email address or your email domain and unlocks all documents that require access, not just the one you requested.
Downloaded documents are watermarked with your email address, and each download link expires after 5 minutes.
Find Netlify network locations
Section titled “Find Netlify network locations”To find where Netlify’s global edge network serves traffic from, check the list of network locations in the Trust Center. Learn more about the Trust Center and how to access it.
Add contacts for security incidents
Section titled “Add contacts for security incidents”To ensure that Netlify can quickly contact you about potential abuse, fraud, or other security incidents, add at least one email address as an incidents contact. If you have an organization, you can only add a contact in your organization settings.
Add a contact for a team
Section titled “Add a contact for a team”-
As a Team Owner, go to Team settings General Primary Contacts, then select Edit contacts.
-
Add at least one email address as a primary contact for security, abuse, or fraud incidents.
Add a contact for an organization
Section titled “Add a contact for an organization”If your team is a part of an organization, you can only add contacts in your organization settings.
-
As an Organization Owner, select your organization name in the navigation and then select Organization overview.

-
Select your Organization’s Settings page, go to Primary contacts, then select Edit contacts.
-
Add at least one email address as a primary contact for security, abuse, or fraud incidents. This contact info will appear as read-only in team settings.
More security resources
Section titled “More security resources”Did you find this doc useful?
Your feedback helps us improve our docs.