Skip to main content
The platform and your data are hosted on Heroku and AWS infrastructure, which adhere to industry-leading standards, including ISO 27001, SOC 1, SOC 2/SSAE, PCI Level 1, FISMA Moderate, and Sarbanes-Oxley (SOX).

Certifications overview

ButterCMS uses SOC2 Type 2 and SOC3-compliant AWS data centers to deliver high scalability, availability, and performance levels while maintaining strict security and compliance standards.
ButterCMS leverages AWS’s extensive compliance certifications. As a customer, you benefit from AWS’s investments in security and compliance across their global infrastructure.

Compliance standards summary

StandardStatusDescription
ISO 27001CertifiedInformation security management
SOC 1CompliantFinancial reporting controls
SOC 2 Type 2CompliantSecurity, availability, confidentiality
SOC 3CompliantPublic trust report
PCI DSS Level 1CompliantPayment card data security
FISMA ModerateCompliantUS federal security standards
SOXCompliantFinancial compliance (Sarbanes-Oxley)
GDPRCompliantEU data protection regulation
HIPAAInfrastructure readyHealthcare data (via AWS)

ISO 27001

The data centers where content is stored are ISO 27001 certified, a standard recognized globally.

What is ISO 27001?

ISO 27001 is the international standard for information security management systems (ISMS). It provides a framework for:
  • Risk Assessment - Identifying and managing security risks
  • Security Controls - Implementing appropriate safeguards
  • Continuous Improvement - Ongoing security enhancement
  • Third-Party Assurance - Independent verification of security practices

ISO 27001 coverage

AreaWhat It Covers
Access ControlUser authentication, authorization
CryptographyEncryption, key management
Physical SecurityData center access controls
Operations SecurityLogging, monitoring, malware protection
Communications SecurityNetwork security, data transfer
Incident ManagementSecurity incident response
Business ContinuityDisaster recovery, backup
ComplianceLegal and regulatory requirements

SOC 2 Type 2

What is SOC 2?

SOC 2 (Service Organization Control 2) is an auditing procedure that ensures service providers securely manage data. Type 2 reports cover an extended period (typically 6-12 months) to verify controls operate effectively over time.

Trust services criteria

SOC 2 evaluates five trust service criteria:
CriteriaDescriptionButterCMS Status
SecurityProtection against unauthorized accessCompliant
AvailabilitySystem accessibility as agreedCompliant
Processing IntegrityComplete and accurate data processingCompliant
ConfidentialityProtection of confidential informationCompliant
PrivacyPersonal information handlingCompliant

Why SOC 2 matters

  • Independent Verification - Third-party auditors verify security controls
  • Continuous Compliance - Type 2 covers ongoing operations, not just a point in time
  • Industry Standard - Widely recognized for SaaS and cloud services
  • Customer Assurance - Demonstrates commitment to security
Enterprise customers can request SOC 2 reports for due diligence and compliance documentation.

PCI DSS

What is PCI DSS?

PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards designed to ensure that companies that process, store, or transmit credit card information maintain a secure environment.

PCI compliance at ButterCMS

AspectDetails
LevelPCI DSS Level 1 (via AWS)
ScopeInfrastructure and data centers
Payment ProcessingHandled by Stripe (PCI Level 1 certified)
Credit Card DataNever stored in ButterCMS
ButterCMS does not store credit card information. All payment processing is handled by Stripe, a PCI Level 1 certified payment processor.

GDPR compliance

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law in the European Union that governs how personal data is collected, processed, and stored.

ButterCMS GDPR compliance

RequirementHow ButterCMS Complies
Lawful BasisClear terms of service and privacy policy
Data MinimizationWe collect only necessary data
Right to AccessExport your data at any time
Right to ErasureDelete your account and data on request
Data PortabilityExport data in standard formats
SecurityEncryption, access controls, monitoring
Breach NotificationProcedures for timely notification

Data processing agreement (DPA)

Enterprise customers can request a Data Processing Agreement that covers:
  • Nature and purpose of processing
  • Types of personal data processed
  • Duration of processing
  • Obligations of both parties
  • Sub-processor information
  • Data transfer mechanisms

Request DPA

Contact support to request a Data Processing Agreement

FISMA

What is FISMA?

FISMA (Federal Information Security Management Act) is a United States law that requires federal agencies and their contractors to develop, document, and implement information security programs.

FISMA Moderate

ButterCMS infrastructure (via AWS) meets FISMA Moderate requirements:
  • Risk Assessment - Regular security assessments
  • Security Planning - Documented security procedures
  • Security Training - Personnel awareness programs
  • Incident Response - Defined response procedures
  • Contingency Planning - Business continuity measures
  • Physical Protection - Data center security
FISMA compliance is relevant for organizations working with US federal government data or contracts.

SOX compliance

What is SOX?

The Sarbanes-Oxley Act (SOX) is a US law that establishes requirements for financial record keeping and reporting for public companies.

SOX relevance

While SOX primarily applies to publicly traded companies, ButterCMS’s infrastructure supports SOX compliance through:
  • Access Controls - Role-based access to sensitive data
  • Audit Trails - Logging of content changes
  • Data Integrity - Protection against unauthorized modification
  • Backup & Recovery - Data protection and availability

HIPAA

What is HIPAA?

HIPAA (Health Insurance Portability and Accountability Act) establishes standards for protecting sensitive patient health information.

HIPAA and ButterCMS

AspectStatus
AWS InfrastructureHIPAA eligible services available
ButterCMS PlatformNot HIPAA certified by default
Healthcare UsePossible with proper configuration
Important: If you need to store Protected Health Information (PHI), contact ButterCMS to discuss HIPAA compliance requirements and a Business Associate Agreement (BAA).

Additional certifications

AWS certifications (infrastructure)

ButterCMS benefits from AWS’s extensive certifications:
CertificationDescription
CSA STARCloud Security Alliance certification
FedRAMPFederal Risk and Authorization Management
IRAPAustralian government security
MTCSSingapore Multi-Tier Cloud Security
C5German Cloud Computing Compliance
ENS HighSpanish National Security Framework
K-ISMSKorean Information Security Management

Industry-specific compliance

ButterCMS can support various industry-specific requirements:
IndustryRelevant Standards
FinanceSOC 2, PCI DSS, SOX
HealthcareHIPAA (with BAA)
GovernmentFISMA, FedRAMP (via AWS)
E-commercePCI DSS
InternationalGDPR, regional standards

Security assessments

Regular security practices

ButterCMS maintains security through:
  • penetration testing
  • vulnerability scanning
  • security audits
  • code reviews
  • dependency updates