Webflow
Platform and infrastructure
AWS, Fastly, SSL, DDoS protection, and platform updates.

Webflow security
Webflow owns the platform and infrastructure. We own the custom code, third-party integrations, and launch checks. The boundary is explicit so procurement and security teams can review it.
Controls and compliance evidence follow Webflow's current documentation and the project scope.
Shared responsibility
Webflow
AWS, Fastly, SSL, DDoS protection, and platform updates.
Tenten
Secure coding, third-party review, and launch checks.
Your team
Permissions, strong passwords, two-factor authentication, and data handling.
These are Webflow platform controls and evidence sources. Project security still depends on the selected plan, custom code, integrations, account controls, and customer data practices.
Webflow-hosted sites use platform-managed SSL/TLS for data in transit. The project review still covers custom domains, forms, embeds, scripts, and integrations because transport encryption does not secure every data flow by itself.
Learn more about SSL hostingWebflow lists DDoS protection as a network-security control in its Trust Center. Procurement should review the current platform evidence and any plan-specific requirements instead of treating the control as a universal site-level uptime commitment.
Webflow's current Trust Center lists SOC 2 Type II, ISO 27001, PCI DSS, penetration-test material, and other platform evidence. These are Webflow attestations, not a certification of Tenten or of every customer website.
Webflow's security overviewWebflow maintains its managed platform and publishes security updates. Custom code, third-party scripts, apps, access roles, consent tools, and operational procedures remain separate review and maintenance responsibilities.

Infrastructure
Webflow publishes platform controls, certifications, penetration-test material, and other review documents through its current Trust Center. Some evidence is public and some requires access, so procurement should review the current scope instead of relying on a project page summary.

Data protection
Webflow documents its processor obligations, privacy practices, DPA, and subprocessors. Its own Privacy FAQs also state that the customer remains the controller for end-user data and keeps separate legal, notice, consent, and request-handling obligations.
Bring the checklist to a 30-minute call with the people who build and maintain the site.
The questions clients ask before signing off.
Vendor questionnaire or a one-line question: send it over. We answer every enquiry within one business day.
Schedule your discovery call