Skip to main content
The platform and your data are hosted on Heroku and AWS infrastructure, which adhere to industry-leading standards, including ISO 27001, SOC 1, SOC 2/SSAE, PCI Level 1, FISMA Moderate, and Sarbanes-Oxley (SOX).

Certifications overview

ButterCMS uses SOC2 Type 2 and SOC3-compliant AWS data centers to deliver high scalability, availability, and performance levels while maintaining strict security and compliance standards.
ButterCMS leverages AWS’s extensive compliance certifications. As a customer, you benefit from AWS’s investments in security and compliance across their global infrastructure.

Compliance standards summary

ISO 27001

The data centers where content is stored are ISO 27001 certified, a standard recognized globally.

What is ISO 27001?

ISO 27001 is the international standard for information security management systems (ISMS). It provides a framework for:
  • Risk Assessment - Identifying and managing security risks
  • Security Controls - Implementing appropriate safeguards
  • Continuous Improvement - Ongoing security enhancement
  • Third-Party Assurance - Independent verification of security practices

ISO 27001 coverage

SOC 2 Type 2

What is SOC 2?

SOC 2 (Service Organization Control 2) is an auditing procedure that ensures service providers securely manage data. Type 2 reports cover an extended period (typically 6-12 months) to verify controls operate effectively over time.

Trust services criteria

SOC 2 evaluates five trust service criteria:

Why SOC 2 matters

  • Independent Verification - Third-party auditors verify security controls
  • Continuous Compliance - Type 2 covers ongoing operations, not just a point in time
  • Industry Standard - Widely recognized for SaaS and cloud services
  • Customer Assurance - Demonstrates commitment to security
Enterprise customers can request SOC 2 reports for due diligence and compliance documentation.

PCI DSS

What is PCI DSS?

PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards designed to ensure that companies that process, store, or transmit credit card information maintain a secure environment.

PCI compliance at ButterCMS

ButterCMS does not store credit card information. All payment processing is handled by Stripe, a PCI Level 1 certified payment processor.

GDPR compliance

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law in the European Union that governs how personal data is collected, processed, and stored.

ButterCMS GDPR compliance

Data processing agreement (DPA)

Enterprise customers can request a Data Processing Agreement that covers:
  • Nature and purpose of processing
  • Types of personal data processed
  • Duration of processing
  • Obligations of both parties
  • Sub-processor information
  • Data transfer mechanisms

Request DPA

Contact support to request a Data Processing Agreement

FISMA

What is FISMA?

FISMA (Federal Information Security Management Act) is a United States law that requires federal agencies and their contractors to develop, document, and implement information security programs.

FISMA Moderate

ButterCMS infrastructure (via AWS) meets FISMA Moderate requirements:
  • Risk Assessment - Regular security assessments
  • Security Planning - Documented security procedures
  • Security Training - Personnel awareness programs
  • Incident Response - Defined response procedures
  • Contingency Planning - Business continuity measures
  • Physical Protection - Data center security
FISMA compliance is relevant for organizations working with US federal government data or contracts.

SOX compliance

What is SOX?

The Sarbanes-Oxley Act (SOX) is a US law that establishes requirements for financial record keeping and reporting for public companies.

SOX relevance

While SOX primarily applies to publicly traded companies, ButterCMS’s infrastructure supports SOX compliance through:
  • Access Controls - Role-based access to sensitive data
  • Audit Trails - Logging of content changes
  • Data Integrity - Protection against unauthorized modification
  • Backup & Recovery - Data protection and availability

HIPAA

What is HIPAA?

HIPAA (Health Insurance Portability and Accountability Act) establishes standards for protecting sensitive patient health information.

HIPAA and ButterCMS

Important: If you need to store Protected Health Information (PHI), contact ButterCMS to discuss HIPAA compliance requirements and a Business Associate Agreement (BAA).

Additional certifications

AWS certifications (infrastructure)

ButterCMS benefits from AWS’s extensive certifications:

Industry-specific compliance

ButterCMS can support various industry-specific requirements:

Security assessments

Regular security practices

ButterCMS maintains security through:
  • penetration testing
  • vulnerability scanning
  • security audits
  • code reviews
  • dependency updates