This is a preview of the Storyblok Website with Draft Content

Trust Center

Enterprise-Grade

Security & Trusted SaaS Solution

Trust is essential to any enterprise implementation, and at Storyblok, we take that responsibility seriously by providing a secure, reliable SaaS solution. Transparency is key, so this page outlines how we protect your data, ensure compliance, and maintain system availability.

Security

At Storyblok, safeguarding your data is our highest priority. We've implemented robust processes and protocols to ensure data security and compliance.

Code Security

Built to withstand threats. Storyblok follows industry-leading security practices to keep your platform resilient, secure, and uncompromised.

    • OWASP Best Practices

      Secure coding principles are followed throughout the development lifecycle.

    • Vulnerability Management

      Continuous scanning, automated dependency updates, and proactive patching of security risks.

    • Penetration Testing

      Regular internal and third-party security testing to identify and remediate vulnerabilities before they become threats.

    • Peer-reviewed Code

      Every code change undergoes a rigorous review process to maintain security integrity.

    • Automated Testing

      Security tests are integrated into the CI/CD pipeline to detect issues early.

Data Encryption

Storyblok ensures enterprise-grade data security with robust encryption standards, safeguarding your content and customer data.

    • Encryption in Transit

      TLS 1.3 secures all data transfers, preventing interception.

    • Encryption at Rest

      AES-256 encryption protects stored data against unauthorized access.

    • Secure Key Management

      Strict cryptographic policies ensure safe key storage and rotation.

    • No Legacy Algorithms

      Deprecated methods like 3DES, MD5, and SHA-1 are strictly prohibited, eliminating security risks.

Quality Assurance & Automated Testing

Storyblok builds security and reliability into every stage of development, ensuring a resilient and high-performance platform.

    • Formal Design Reviews

      Every new feature undergoes a rigorous security review.

    • Threat Modeling & Risk Assessments

      Built into development to proactively identify risks.

    • Automated Security Scans

      Continuously detect vulnerabilities in dependencies and code.

    • Security Workshops

      Ongoing developer training on secure coding best practices.

Access Rights

Storyblok enforces strict access controls to protect your content and systems.

    • Role-Based Access Control (RBAC)

      Fine-grained permission management for efficiently overseeing large teams.

    • Two-Factor Authentication (2FA)

      Mandatory for all privileged accounts.

    • Certificate-based Authentication

      Secure access to production environments.

    • Least Privilege Policy

      Access is granted only when needed and revoked instantly when it's not.

Dependency Management

Storyblok continuously monitors third-party dependencies.

    • Automated Updates & Patching

      Ensures security vulnerabilities are resolved promptly.

    • Strict Vendor Screening

      Any third-party library used in the platform undergoes security evaluations.

    • Supply Chain Security

      Regular assessments to ensure suppliers comply with industry-standard security practices.

Infrastructure

You rely on us delivering the best and most reliable SaaS, which is why we build on modern technologies, best-in-class processes and transparency to ensure the availability of our solution.

Service Levels & Support

Storyblok offers enterprise-grade reliability, uptime, and world-class support to keep your digital experiences running smoothly.

Content Delivery Network (CDN)

Storyblok’s global CDN ensures fast, secure, and reliable content delivery.

    • Low Latency Distribution

      Faster page loads, anywhere in the world.

    • Built-In DDoS Protection

      Shields against attacks to keep services running.

    • Edge Caching

      Reduces server load and boosts performance.

Monitoring & Reporting

Real-time monitoring keeps your system reliable and secure.

    • Continuous Performance Monitoring

      Detects bottlenecks and optimizes response times.

    • AI-Powered Anomaly Detection

      Identifies threats before they become issues.

    • Incident Logging & Reporting

      Enhanced visibility into security events to support compliance with applicable laws and security standards.

Contingency Planning

Storyblok ensures business continuity with proactive disaster recovery strategies.

Scaling

Storyblok dynamically scales to keep performance seamless, no matter the demand.

    • Automatic Scaling

      Instantly adapts to traffic spikes for uninterrupted service.

    • Load Balancing

      Distributes traffic efficiently for peak performance.

    • High-availability Architecture

      Redundant infrastructure ensures reliability.

Incident Management

Swift detection, response, and resolution to keep your operations secure.

    • Security Event Escalation

      Prioritized response based on predefined severity levels and agreements.

    • Incident Response Team

      A dedicated team ready to act on high-priority threats.

    • Root Cause Analysis (RCA)

      Post-incident reviews to prevent repeat issues.

Data Centers

Storyblok’s infrastructure is built for global security, compliance, and reliability.

    • AWS Hosting

      GDPR-compliant and meets EU data protection laws.

    • Flexible Data Residency

      Supported by AWS data centers in North America (US & Canada), Europe (Germany), and Australia.

    • ISO 27001

      Industry-leading compliance standards for data protection.

    • Strict Physical Security

      Data center access is tightly controlled and restricted to authorized personnel.

Backups

Storyblok ensures data integrity with a multi-layered backup strategy.

    • Daily Backups

      Customer-managed and securely stored in Amazon S3 for reliable recovery.

    • Read Replica Failover

      In case of a database failure in the main region, a hot-standby replica is available to take over the service immediately.

    • 14-Day Transaction Log Retention

      Restore data to any point in time within the last 14 days.


    • Regular Backup Testing

      Validates recoverability for peace of mind.


Governance

You rely on us delivering the best and most reliable SaaS, which is why we build on modern technologies, best-in-class processes and transparency to ensure the availability of our solution.

Governance & Information Security

Enterprise-grade governance and compliance ensure your content stays protected, operations remain uninterrupted, and risks are proactively managed.

    • Business Continuity Planning

      Resilient operations supported by tested business continuity and disaster recovery plans, with infrastructure redundancy and rapid recovery protocols designed to minimize disruption.

    • ISMS Policies & Certifications

      Adheres to ISO 27001, TISAX and industry standards for data security and compliance.

    • Risk Management

      Proactively identifies, assesses, and mitigates security risks to safeguard data and operations.

    • Incident Reporting

      Compliant with the applicable security and cybersecurity laws, ensuring rapid detection, response, and resolution of security incidents.

Corporate Governance

Storyblok’s corporate governance is a foundation for trust, accountability, and long-term success.

    • Accountable & Compliant Business Practices

      By following our Code of Conduct, Anti-Bribery Policy, and Whistleblowing Policy, we all contribute to a culture of accountability and transparency at Storyblok. All stakeholders have to adhere to our Code of Conduct and applicable laws.

    • Vendor Management Process

      Storyblok supports responsible partnerships with like-minded vendors who adhere to applicable laws, fair labor practices, and ethical business standards.

    • Occupational Health & Safety

      Storyblok complies with all applicable health and safety regulations for remote work.

    • Diversity, Equity & Inclusion (DEI)

      Storyblok is a remote-first international company committed to fostering an inclusive and diverse workplace. Every person’s unique perspective enhances our creativity and understanding. We work together to build a culture where everyone feels valued and empowered to succeed.

    • Personal Development and Training

      We provide regular training in information security, compliance, and professional development to help our team stay expert in their fields and ensure reliable, trusted service.

Sustainability & Ethical Responsibility

Storyblok is committed to ethical business, environmental responsibility, and human rights, ensuring a positive impact on people and the planet.


Storyblok ensures full compliance with applicable regulations and laws around the world.