Netlify logo

Netlify

Web development platform for building, deploying, and scaling modern websites and applications.

✓ 9 of 32 frameworks
+ 2 partial
Security & General Standards
SOC 2 Type II

SOC 3
?

Not publicly documented

SOC 1 Type II
?

Not publicly documented

ISO 27001 (Information Security Management)

ISO 27017 (Cloud Security)

ISO 27018 (Cloud Privacy)

ISO 27701 (Privacy Information Management)

ISO 42001 (AI Management Systems)

ISO 9001 (Quality Management)

CSA STAR (Cloud Security Alliance)

HITRUST CSF

BSI C5 (German Cloud Security)

Privacy & Data Transfer
GDPR (EU)

CCPA / CPRA (California)

UK GDPR
~

UK GDPR is a regulation, not a certification; covered via UK Extension to EU-U.S. DPF, netlify.com/security/ and trust-center.netlify-corp.com (SafeBase), checked 2026-09-06

LGPD (Brazil)

PIPEDA (Canada)

DPDP Act (India)

PIPL (China)

EU-US Data Privacy Framework

Swiss-US Data Privacy Framework

Global CBPR (APEC)

Global PRP (APEC)

Industry & Government
HIPAA (US Healthcare)
~

HIPAA compliance via enterprise service offering with executed BAA, netlify.com/security/ and trust-center.netlify-corp.com (SafeBase), checked 2026-09-06

PCI DSS (Payment Card Industry)

FedRAMP (US Federal)

StateRAMP / TX-RAMP (US State)

DORA (EU Finance)

CJIS (US Law Enforcement)

FINRA (US Broker-Dealers)

IRAP (Australian Government)

Emerging & Strategic
NIST CSF (Cybersecurity Framework)
?

Not publicly documented

Data last verified: September 2026

Is this data outdated?

Spotted an error or a recent change in Netlify's posture? Submit a correction.

Submit a correction →

Work at Netlify?

Claim this profile to verify and enrich your compliance data.

Claim this profile →

Compare Netlify with:

← All Infrastructure & Cloud tools

Data sourced from public trust centers. Not legal or compliance advice.

Logos and trademarks are property of their respective owners. Use does not imply endorsement, affiliation, or sponsorship.

© Compliance Posture 2026