NewIntroducing Palmata: Contentful's new solution for AI discovery

Security at Contentful

ISO SOC 3 Tisax 2

At Contentful, security isn't simply a priority. It's fundamental to how we design, build, and operate our platform. Embedded throughout our technology, processes, and culture, our security program helps protect customer data through strong governance, secure engineering practices, operational resilience, and internationally recognized security standards.

Our security program is governed by an Information Security Management System (ISMS) certified to ISO/IEC 27001:2022. This internationally recognized standard provides a structured framework for identifying and managing information security risks, maintaining effective controls, and continually improving our security practices. Certification is independently assessed by an accredited third-party certification body.


Compliance & Certifications

Contentful maintains an independent security assurance program that is regularly assessed against recognized industry standards.

Our current independent certifications and assurance activities include:

  • ISO/IEC 27001 certification

  • SOC 2 Type 2

  • SOC 3

  • PCI DSS SAQ A

  • TISAX

Contentful has maintained ISO/IEC 27001 certification since June 2019. To maintain certification, we undergo independent annual surveillance audits and a full recertification audit every three years.

In addition to ISO/IEC 27001, Contentful maintains an independent SOC 2 Type 2 examination, providing assurance over the design and operating effectiveness of controls relating to security, availability, and confidentiality. 

Contentful GmbH participates in TISAX (Trusted Information Security Assessment Exchange), the information security assessment framework for the automotive industry governed by the ENX Association on behalf of the German Association of the Automotive Industry (VDA). Our assessment was conducted independently by TÜV Rheinland. TISAX assessment results are not publicly available. 

Our latest certifications, audit reports, and supporting assurance documentation are available through the Contentful Trust Center.


Contentful Trust Center

The Contentful Trust Center provides a centralized location for customers to access security, compliance, and assurance documentation. While some Trust Center content is publically accessible, other resources are restricted to current and active customers only. If you’re a prospective customer, please contact your sales representative and we will facilitate getting you the information you need.

The Trust Center, removes the need for manual document requests and supporting faster security reviews, procurement, and due diligence activities, including:

  • Security certifications

  • Audit reports

  • Penetration test reports

  • Security policies

  • Infrastructure documentation

  • Business resilience and disaster recovery information

  • Additional security and compliance resources

The Trust Center also includes an AI-powered assistant that helps customers quickly find answers based on the documentation and security controls available within the platform.

shield check icon white

Explore the Contentful Trust Center

Visit trust.contentful.com

How to report vulnerabilities

Contentful values the important role the security community plays in helping us identify and address potential vulnerabilities. We actively encourage responsible disclosure and work collaboratively with researchers to investigate and remediate legitimate security findings.

If you've discovered a potential vulnerability, bug, or unusual behavior, please submit it using the form below as part of our Responsible Disclosure Program (Bug Bounty Program).

For other security-related enquiries, please contact us by emailing support@contentful.com or by opening a support ticket. If you require encrypted communication, our PGP key is available on Keybase.

To help protect our customers and platform, we kindly ask that you refrain from publicly disclosing any vulnerability until we have had the opportunity to investigate and address the issue with you.