dot CMS

SECURITY & COMPLIANCE

Enterprise Security You Can Verify

Protect your content, data, and infrastructure with security controls built across the dotCMS platform. Independently assessed security, privacy, and AI governance programs help organizations meet rigorous security and compliance requirements.

 

ISO/IEC 27001 · ISO/IEC 42001 · SOC 2 Type II · TX-RAMP Level II

image
  • ISO/IEC 42001:2023

    ISO/IEC 42001:2023 Certified

    AI governance, independently verified.

     

    dotCMS is certified to ISO/IEC 42001:2023, the international standard for AI management systems. The certification covers the governance and risk management practices applied to customer-facing dotAI capabilities and internal AI use.

     

    In dotCMS, an AI agent is another actor in the system: it works inside the same roles, permissions, and workflows as a person, and every change it makes stays traceable and reversible through version history.


  • TXRAMP

    TX-RAMP Level II

    Security requirements for Texas public-sector organizations.

     

    dotCMS is certified at TX-RAMP Level II, demonstrating that dotCMS Cloud meets the security requirements established for cloud service providers working with Texas state agencies and other eligible public-sector organizations.

  • SOC 2 Type II Certified

    SOC 2 Type II

    Security controls tested over time.

     

    dotCMS has completed a SOC 2 Type II examination. An independent CPA firm assessed dotCMS controls against the AICPA Trust Services Criteria for security, availability, and confidentiality and tested their operating effectiveness over time.

     

    The full report and auditor test results are available through the dotCMS Trust Center.

  • ISO/IEC 27001:2022

    ISO/IEC 27001:2022

    Information security managed to an international standard.

     

    dotCMS is ISO/IEC 27001:2022 certified, demonstrating that its information security management system follows internationally recognized requirements for managing security risks and protecting information across its cloud services and supporting operations.

  • CAIQ

    CAIQ

    Cloud security controls, documented and accessible.

    dotCMS maintains a completed Consensus Assessments Initiative Questionnaire (CAIQ) from the Cloud Security Alliance, providing customers and auditors with detailed information about its cloud security practices and controls.

Check which dotCMS deployment meets your infrastructure and security standards

dotCMS runs where your policy requires it to run, under the same certified governance model. dotCMS Cloud on AWS is one deployment option, not the only one. Meet infrastructure, security, and data-residency requirements without locking your content strategy into one deployment model.

dotCMS Cloud

dotCMS Cloud

Fully managed on dotCMS's AWS infrastructure, including monitoring, patches, and upgrades.

Read More about Read More
Cloud Anywhere

Cloud Anywhere

Fully managed by dotCMS on AWS, Azure, or GCP, with you contracting directly with your own cloud provider.

Read more about Read more
Self-hosted

Self-hosted

You own and control the infrastructure, whether for company policy or geographic requirements.

Read more about Read more

AUTHENTICATION AND ACCESS

How do authentication and role mapping work in dotCMS?

dotCMS authenticates against your identity provider and enforces authorization with its own roles and permissions.

SAML single sign-on

Configured through the SAML App in the Apps tool. dotCMS documents configuration for Okta, Azure AD, Google, Amazon, and Shibboleth.

Role mapping

 Identity-provider role names are mapped onto existing dotCMS roles, so access is governed by the roles your IdP already assigns.


Per-site configuration

A different SAML configuration can be specified for each site, or one configuration applied across all sites.

API tokens

REST API calls authenticate with JWT API tokens, and every call uses the permissions of the user the token was created for. Content returned by the REST API always respects dotCMS permissions.

Security & Privacy Policies

dotCMS has implemented a set of corporate policies to take maximum security measures for our clients and our company. These policies are reviewed periodically (at a minimum once per year) as part of our business continuity plan. dotCMS currently has the following security & privacy policies implemented:

  • Code of Conduct

  • Cryptography Policy

  • Data Classification Policy

  • Data Deletion Policy

  • Data Protection Policy

  • Disaster Recovery Plan

  • Incident Response Plan

  • Information Security Policy

  • Privacy policy

  • Cookie Policy

  • GDPR policy

  • Acceptable Use Policy

  • Asset Management Policy

  • Backup Policy

  • Business Continuity Plan

  • Change Management Policy

  • Password Policy

  • Physical Security Policy

  • Responsible Disclosure Policy

  • Risk Assessment Program

  • Security Questionnaires Policy

  • System Access Control Policy

  • Vendor Management Policy

  • Vulnerability Management Policy

Explore dotCMS for your organization

image

dotCMS Named a Major Player

In the IDC MarketScape: Worldwide AI-Enabled Headless CMS 2025 Vendor Assessment

image

Explore an interactive tour

See how dotCMS empowers technical and content teams at compliance-led organizations.

image

Built for Compliance. Certified for AI.

dotCMS is ISO 27001 and ISO 42001 certified, pairing independently verified information security with governed, accountable AI.