Enterprise-Grade
Security & Trusted SaaS Solution
Trust is essential to any enterprise implementation, and at Storyblok, we take that responsibility seriously by providing a secure, reliable SaaS solution. Transparency is key, so this page outlines how we protect your data, ensure compliance, and maintain system availability.
Security
Your data’s security is our top priority. We implement enterprise-grade protections to keep your content safe, systems resilient, and operations uninterrupted—so you can trust Storyblok to run securely, 24/7.
Infrastructure
Storyblok’s infrastructure is built for speed, scale, and security—ensuring top-tier uptime, global CDN performance, and real-time monitoring. Your content stays fast, available, and secure, no matter the demand.
Governance
Security, compliance, and ethical responsibility are at our core. From risk management, sustainability to DEI, we ensure transparency and resilience in everything we do.
Legal & Compliance
Security, transparency, and compliance—built in, not bolted on. Storyblok protects your data, ensures regulatory compliance, and uptime guarantees, so you can operate with confidence.
Security
At Storyblok, safeguarding your data is our highest priority. We've implemented robust processes and protocols to ensure data security and compliance.
Code Security
Built to withstand threats. Storyblok follows industry-leading security practices to keep your platform resilient, secure, and uncompromised.
-
-
OWASP Best Practices
Secure coding principles are followed throughout the development lifecycle.
-
Vulnerability Management
Continuous scanning, automated dependency updates, and proactive patching of security risks.
-
Penetration Testing
Regular internal and third-party security testing to identify and remediate vulnerabilities before they become threats.
-
Peer-reviewed Code
Every code change undergoes a rigorous review process to maintain security integrity.
-
Automated Testing
Security tests are integrated into the CI/CD pipeline to detect issues early.
-
Data Encryption
Storyblok ensures enterprise-grade data security with robust encryption standards, safeguarding your content and customer data.
-
-
Encryption in Transit
TLS 1.3 secures all data transfers, preventing interception.
-
Encryption at Rest
AES-256 encryption protects stored data against unauthorized access.
-
Secure Key Management
Strict cryptographic policies ensure safe key storage and rotation.
-
No Legacy Algorithms
Deprecated methods like 3DES, MD5, and SHA-1 are strictly prohibited, eliminating security risks.
-
Quality Assurance & Automated Testing
Storyblok builds security and reliability into every stage of development, ensuring a resilient and high-performance platform.
-
-
Formal Design Reviews
Every new feature undergoes a rigorous security review.
-
Threat Modeling & Risk Assessments
Built into development to proactively identify risks.
-
Automated Security Scans
Continuously detect vulnerabilities in dependencies and code.
-
Security Workshops
Ongoing developer training on secure coding best practices.
-
Access Rights
Storyblok enforces strict access controls to protect your content and systems.
-
-
Role-Based Access Control (RBAC)
Fine-grained permission management for efficiently overseeing large teams.
-
Two-Factor Authentication (2FA)
Mandatory for all privileged accounts.
-
Certificate-based Authentication
Secure access to production environments.
-
Least Privilege Policy
Access is granted only when needed and revoked instantly when it's not.
-
Dependency Management
Storyblok continuously monitors third-party dependencies.
-
-
Automated Updates & Patching
Ensures security vulnerabilities are resolved promptly.
-
Strict Vendor Screening
Any third-party library used in the platform undergoes security evaluations.
-
Supply Chain Security
Regular assessments to ensure suppliers comply with industry-standard security practices.
-
Infrastructure
You rely on us delivering the best and most reliable SaaS, which is why we build on modern technologies, best-in-class processes and transparency to ensure the availability of our solution.
Service Levels & Support
Storyblok offers enterprise-grade reliability, uptime, and world-class support to keep your digital experiences running smoothly.
-
-
Up to 99.99% Uptime, Service & Support
Enterprise-grade availability with minimal downtime.
-
24/7 Global Support
Always-on assistance from our global support team.
-
Priority Support with Dedicated Success Manager
Enterprise customers get live chat, expert escalation paths, and a dedicated CSM.
-
Proactive Monitoring
Detects and prevents issues before they impact you.
-
Multi-tiered Support
Critical issue responses are as little as 2 hours for enterprise plans.
-
Self-service & Community Resources
Help Center access and an active Discord community.
-
Content Delivery Network (CDN)
Storyblok’s global CDN ensures fast, secure, and reliable content delivery.
-
-
Low Latency Distribution
Faster page loads, anywhere in the world.
-
Built-In DDoS Protection
Shields against attacks to keep services running.
-
Edge Caching
Reduces server load and boosts performance.
-
Monitoring & Reporting
Real-time monitoring keeps your system reliable and secure.
-
-
Continuous Performance Monitoring
Detects bottlenecks and optimizes response times.
-
AI-Powered Anomaly Detection
Identifies threats before they become issues.
-
Incident Logging & Reporting
Enhanced visibility into security events to support compliance with applicable laws and security standards.
-
Contingency Planning
Storyblok ensures business continuity with proactive disaster recovery strategies.
-
-
Emergency Alert System
Instantly notifies key executives and security teams at Storyblok.
-
Disaster Recovery Testing
Regular testing guarantees swift, effective incident response.
-
Redundancy Mechanisms
Prevents data loss and keeps operations running smoothly.
-
Business Contingency Plans
Regular testing of business continuity and disaster recovery measures to safeguard service availability.
-
Scaling
Storyblok dynamically scales to keep performance seamless, no matter the demand.
-
-
Automatic Scaling
Instantly adapts to traffic spikes for uninterrupted service.
-
Load Balancing
Distributes traffic efficiently for peak performance.
-
High-availability Architecture
Redundant infrastructure ensures reliability.
-
Incident Management
Swift detection, response, and resolution to keep your operations secure.
-
-
Security Event Escalation
Prioritized response based on predefined severity levels and agreements.
-
Incident Response Team
A dedicated team ready to act on high-priority threats.
-
Root Cause Analysis (RCA)
Post-incident reviews to prevent repeat issues.
-
Data Centers
Storyblok’s infrastructure is built for global security, compliance, and reliability.
-
-
AWS Hosting
GDPR-compliant and meets EU data protection laws.
-
Flexible Data Residency
Supported by AWS data centers in North America (US & Canada), Europe (Germany), and Australia.
-
ISO 27001
Industry-leading compliance standards for data protection.
-
Strict Physical Security
Data center access is tightly controlled and restricted to authorized personnel.
-
Backups
Storyblok ensures data integrity with a multi-layered backup strategy.
-
-
Daily Backups
Customer-managed and securely stored in Amazon S3 for reliable recovery.
-
Read Replica Failover
In case of a database failure in the main region, a hot-standby replica is available to take over the service immediately.
-
14-Day Transaction Log Retention
Restore data to any point in time within the last 14 days.
-
Regular Backup Testing
Validates recoverability for peace of mind.
-
Governance
You rely on us delivering the best and most reliable SaaS, which is why we build on modern technologies, best-in-class processes and transparency to ensure the availability of our solution.
Governance & Information Security
Enterprise-grade governance and compliance ensure your content stays protected, operations remain uninterrupted, and risks are proactively managed.
-
-
Business Continuity Planning
Resilient operations supported by tested business continuity and disaster recovery plans, with infrastructure redundancy and rapid recovery protocols designed to minimize disruption.
-
Risk Management
Proactively identifies, assesses, and mitigates security risks to safeguard data and operations.
-
Incident Reporting
Compliant with the applicable security and cybersecurity laws, ensuring rapid detection, response, and resolution of security incidents.
-
Corporate Governance
Storyblok’s corporate governance is a foundation for trust, accountability, and long-term success.
-
-
Accountable & Compliant Business Practices
By following our Code of Conduct, Anti-Bribery Policy, and Whistleblowing Policy, we all contribute to a culture of accountability and transparency at Storyblok. All stakeholders have to adhere to our Code of Conduct and applicable laws.
-
Vendor Management Process
Storyblok supports responsible partnerships with like-minded vendors who adhere to applicable laws, fair labor practices, and ethical business standards.
-
Occupational Health & Safety
Storyblok complies with all applicable health and safety regulations for remote work.
-
Diversity, Equity & Inclusion (DEI)
Storyblok is a remote-first international company committed to fostering an inclusive and diverse workplace. Every person’s unique perspective enhances our creativity and understanding. We work together to build a culture where everyone feels valued and empowered to succeed.
-
Personal Development and Training
We provide regular training in information security, compliance, and professional development to help our team stay expert in their fields and ensure reliable, trusted service.
-
Sustainability & Ethical Responsibility
Storyblok is committed to ethical business, environmental responsibility, and human rights, ensuring a positive impact on people and the planet.
-
-
Environmental Sustainability
Storyblok takes action through a variety of environmental sustainability efforts to reduce our impact and contribute to a more sustainable future.
-
Modern Slavery & Human Rights
Storyblok has zero tolerance for forced labor and is committed to ethical labor practices. We ensure fair wages, reasonable working hours, equal opportunities, and a safe working environment for all team members, in accordance with applicable labor laws and International Labour Organization (ILO) standards.
-
Legal & Compliance
Storyblok ensures full compliance with applicable regulations and laws around the world.
Platform & Service Agreements
Clear agreements, terms, and notices that promote operational reliability, accountability, and customer trust.
-
-
General Terms & Conditions (GTC)
Our GTC defines platform usage, rights, and responsibilities. The applicable GTC for enterprise customers in the Americas region and the GTC for global self-service customers & enterprise customers in all other regions are available online.
-
Terms of Service for AI-Powered Features
Storyblok provides clear terms for AI-powered features that prioritize compliant and ethical use of artificial intelligence.
-
DCMA Notice
Storyblok complies fully with the Digital Millennium Copyright Act of 1998.
-
DSA Notice
Storyblok complies with the Regulation (EU) 2022/2065 on a Single Market For Digital Services, "Digital Services Act".
-
Partner Agreement
We believe in building strong, transparent relationships with our partners. Our Partner Agreement outlines the terms of collaboration for a seamless and successful experience.
-
Data Protection & Privacy
Enterprise-grade data security, privacy, and compliance.
-
-
Privacy Compliance
Storyblok is fully compliant with GDPR and other applicable privacy laws. We are also self-certified under the EU-U.S. Data Privacy Framework.
-
Privacy Policy
We handle your personal data with care, in compliance with applicable data protection regulations. Please refer to our policies for more information.
-
Data Processing Agreement
For cases in which Storyblok acts as a processor of personal data, our Data Processing Agreement outlines the applicable terms and responsibilities.
-
Privacy Policy for Applicants
How Storyblok collects, uses, and protects applicant information during the recruitment process.
-
Trust & Security Resources
Access resources with detailed information on Storyblok's availability, modern architecture, data security, and compliance.
- https://www.certipedia.com/certificates/01+153+2100668?locale=en
- https://www.tuv.com/world/en/
- https://owasp.org/www-project-code-review-guide/assets/OWASP_Code_Review_Guide_v2.pdf
- https://www.storyblok.com/trust-center/service-level
- https://www.storyblok.com/trust-center/service-support
- https://uptime.storyblok.com/