Certifications overview
ButterCMS uses SOC2 Type 2 and SOC3-compliant AWS data centers to deliver high scalability, availability, and performance levels while maintaining strict security and compliance standards.ButterCMS leverages AWS’s extensive compliance certifications. As a customer, you benefit from AWS’s investments in security and compliance across their global infrastructure.
Compliance standards summary
ISO 27001
The data centers where content is stored are ISO 27001 certified, a standard recognized globally.What is ISO 27001?
ISO 27001 is the international standard for information security management systems (ISMS). It provides a framework for:- Risk Assessment - Identifying and managing security risks
- Security Controls - Implementing appropriate safeguards
- Continuous Improvement - Ongoing security enhancement
- Third-Party Assurance - Independent verification of security practices
ISO 27001 coverage
SOC 2 Type 2
What is SOC 2?
SOC 2 (Service Organization Control 2) is an auditing procedure that ensures service providers securely manage data. Type 2 reports cover an extended period (typically 6-12 months) to verify controls operate effectively over time.Trust services criteria
SOC 2 evaluates five trust service criteria:Why SOC 2 matters
- Independent Verification - Third-party auditors verify security controls
- Continuous Compliance - Type 2 covers ongoing operations, not just a point in time
- Industry Standard - Widely recognized for SaaS and cloud services
- Customer Assurance - Demonstrates commitment to security
PCI DSS
What is PCI DSS?
PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards designed to ensure that companies that process, store, or transmit credit card information maintain a secure environment.PCI compliance at ButterCMS
ButterCMS does not store credit card information. All payment processing is handled by Stripe, a PCI Level 1 certified payment processor.
GDPR compliance
What is GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive data protection law in the European Union that governs how personal data is collected, processed, and stored.ButterCMS GDPR compliance
Data processing agreement (DPA)
Enterprise customers can request a Data Processing Agreement that covers:- Nature and purpose of processing
- Types of personal data processed
- Duration of processing
- Obligations of both parties
- Sub-processor information
- Data transfer mechanisms
Request DPA
Contact support to request a Data Processing Agreement
FISMA
What is FISMA?
FISMA (Federal Information Security Management Act) is a United States law that requires federal agencies and their contractors to develop, document, and implement information security programs.FISMA Moderate
ButterCMS infrastructure (via AWS) meets FISMA Moderate requirements:- Risk Assessment - Regular security assessments
- Security Planning - Documented security procedures
- Security Training - Personnel awareness programs
- Incident Response - Defined response procedures
- Contingency Planning - Business continuity measures
- Physical Protection - Data center security
FISMA compliance is relevant for organizations working with US federal government data or contracts.
SOX compliance
What is SOX?
The Sarbanes-Oxley Act (SOX) is a US law that establishes requirements for financial record keeping and reporting for public companies.SOX relevance
While SOX primarily applies to publicly traded companies, ButterCMS’s infrastructure supports SOX compliance through:- Access Controls - Role-based access to sensitive data
- Audit Trails - Logging of content changes
- Data Integrity - Protection against unauthorized modification
- Backup & Recovery - Data protection and availability
HIPAA
What is HIPAA?
HIPAA (Health Insurance Portability and Accountability Act) establishes standards for protecting sensitive patient health information.HIPAA and ButterCMS
Additional certifications
AWS certifications (infrastructure)
ButterCMS benefits from AWS’s extensive certifications:Industry-specific compliance
ButterCMS can support various industry-specific requirements:Security assessments
Regular security practices
ButterCMS maintains security through:- penetration testing
- vulnerability scanning
- security audits
- code reviews
- dependency updates