Skip to content
Security and design specialists reviewing website architecture and responsibility boundaries

Webflow security

Webflow website security, layer by layer.

Webflow owns the platform and infrastructure. We own the custom code, third-party integrations, and launch checks. The boundary is explicit so procurement and security teams can review it.

Controls and compliance evidence follow Webflow's current documentation and the project scope.

  • SSL
  • DDoS
  • Webflow SOC 2
  • Customer GDPR duties
  • Custom-code review

Shared responsibility

Security is not one certificate. It is three owners holding their boundaries.

01

Webflow

Platform and infrastructure

AWS, Fastly, SSL, DDoS protection, and platform updates.

02

Tenten

Custom code and integrations

Secure coding, third-party review, and launch checks.

03

Your team

Accounts and data governance

Permissions, strong passwords, two-factor authentication, and data handling.

Platform controls, with their boundary

These are Webflow platform controls and evidence sources. Project security still depends on the selected plan, custom code, integrations, account controls, and customer data practices.

Secure hosting with SSL encryption

Webflow-hosted sites use platform-managed SSL/TLS for data in transit. The project review still covers custom domains, forms, embeds, scripts, and integrations because transport encryption does not secure every data flow by itself.

Learn more about SSL hosting

DDoS protection

Webflow lists DDoS protection as a network-security control in its Trust Center. Procurement should review the current platform evidence and any plan-specific requirements instead of treating the control as a universal site-level uptime commitment.

Webflow Trust Center evidence

Webflow's current Trust Center lists SOC 2 Type II, ISO 27001, PCI DSS, penetration-test material, and other platform evidence. These are Webflow attestations, not a certification of Tenten or of every customer website.

Webflow's security overview

Regular updates and patches

Webflow maintains its managed platform and publishes security updates. Custom code, third-party scripts, apps, access roles, consent tools, and operational procedures remain separate review and maintenance responsibilities.

Webflow security infrastructure on AWS and Fastly

Infrastructure

Engineered from the ground up, tested from the outside

Webflow publishes platform controls, certifications, penetration-test material, and other review documents through its current Trust Center. Some evidence is public and some requires access, so procurement should review the current scope instead of relying on a project page summary.

  • Penetration testingOutside firms run comprehensive penetration tests against the platform.
  • Certifications and attestationsThe current Trust Center records Webflow's certifications, attestations, and access-controlled reports.
  • Findings become fixesReview current reports, published updates, and open customer actions before approving the platform boundary.
Read the Webflow security whitepaper
Data protection and privacy on Webflow

Data protection

Privacy duties stay shared

Webflow documents its processor obligations, privacy practices, DPA, and subprocessors. Its own Privacy FAQs also state that the customer remains the controller for end-user data and keeps separate legal, notice, consent, and request-handling obligations.

  • Customer consent decisionsThe customer identifies applicable notices and consent requirements; the implementation follows that approved direction.
  • Data-rights workflowThe customer, as controller, owns end-user requests. The site and connected systems need a documented path for access, correction, deletion, and escalation.
  • Processor and integration recordsReview Webflow's DPA and subprocessors alongside every project integration that receives customer or end-user data.
Webflow's GDPR commitment

Questions your security team still needs answered?

Bring the checklist to a 30-minute call with the people who build and maintain the site.

Security ownership, from build through maintenance

Track record

Security scope

Written

Engineering access

Direct

Continuity

After launch

Reply time

1 day

Frequently asked questions

The questions clients ask before signing off.

How does Webflow keep my website secure over time?
Webflow maintains platform-level controls and publishes current security evidence in its Trust Center. Your review should also cover the selected plan, account roles, custom code, third-party integrations, consent tools, and the owners responsible after launch.
Can I use custom code on my Webflow site without compromising security?
Custom code is possible, but it changes the security boundary. We review and test the code against the agreed scope, document third-party dependencies and data flows, and record any remaining limitations before launch.
How does Webflow handle data backups and recovery?
Webflow publishes backup and recovery controls in its Trust Center. The project still needs to confirm the current plan, what data is covered, who can restore it, and how custom integrations or external systems are recovered.
Is Webflow compliant with data protection regulations besides GDPR?
Webflow publishes privacy commitments and processor obligations, but its own Privacy FAQs state that customers retain separate controller obligations. Your legal counsel should determine which laws apply; we implement the approved consent, notice, and data-flow requirements in scope.

Bring us your security checklist.

Vendor questionnaire or a one-line question: send it over. We answer every enquiry within one business day.

Schedule your discovery call