Trusted by security teams.
Global protection
DDoS mitigation
Customized application security. Instantly deployed at scale.
Vercel’s Web Application Firewall allows customers to create custom rules to log, block, challenge, or rate limit L7 traffic.
Firewall

ISO 27001
SOC 2
PCI DSS
HIPAA
GDPR
DPF
Frequently asked questions.
Does Vercel offer DDoS protection?
Yes. Vercel Enterprise customers are covered by two forms of DDoS protection. Our systems can automatically detect and block malicious attacks on customer sites. For significantly larger, distributed attacks, we work closely with the customer to ensure your site(s) stay online. The combination of automated prevention and direct communication from our Customer Success Managers helps ensure your site is resilient to attacks. Contact us to learn more.
Is Vercel SOC 2 Type 2 compliant?
Yes, Vercel has a SOC 2 Type 2 attestation. Contact us for more details or to access the report.
Is Vercel GDPR compliant?
Yes. For more information, see our Privacy Policy. No data is stored permanently inside EU regions. Static assets and Serverless Functions responses can be cached in EU regions, but it is ephemeral. Vercel provides a Data Processing Addendum (DPA) which describe our Technical and Organizational Security Measures. For more information, our Privacy Policy explains how information is collected, used, processed and disclosed by Vercel.
Is Vercel ISO 27001 certified?
Yes, Vercel is ISO 27001:2013 certified. Contact us for more details or to access the certificate.
Is Vercel certified under the Data Privacy Framework (DPF)?
Yes, Vercel is certified under the DPF. Our public listing is available at https://www.dataprivacyframework.gov/list. For more information, see our Privacy Notice.
Does Vercel support HIPAA compliance?
Vercel supports HIPAA compliance for enterprise customers. Our HIPAA report is available upon request at security.vercel.com. Contact us for more details if HIPAA is important for you.
Does Vercel support PCI compliance?
Yes, Vercel has a Self-Assessment Questionnaire (SAQ)-D Attestation of Compliance (AOC) for Service Providers and a Self-Assessment Questionnaire (SAQ)-A Attestation of Compliance (AOC) for Merchants based on PCI DSS v4.0. Contact us for more details or to access these reports.
Can I protect my deployments?
Yes. Vercel offers flexible access options. Any plan has access to Deployment Protection which include Vercel Authentication and Shareable Links (Hobby plan limited to 1 link per account). Customers on the pro plan can opt-in to Advanced Deployment Protection for $150 which offers Password Protection, Deployment Protection Exceptions and Private Production Deployments.
Does Vercel encrypt data?
Yes. Data is encrypted at rest (AES-256) and in transit (HTTPS / TLS), including sensitive information like access tokens and secrets.
Does Vercel backup the data on its platform?
Yes. Our current backup interval is every two hours and each backup is persisted for 30 days. Automatic backups are taken without affecting the performance or availability of the database operations. All the backups are stored separately in a storage service, and those backups are globally replicated for resiliency against regional disasters. If a database instance is deleted, all associated backups are also automatically deleted. Backups are periodically tested by the Vercel engineering team.
What infrastructure does Vercel use?
The Vercel Edge Network & deployment platform primarily uses Amazon Web Services (AWS). In the case of an AWS outage, our network is resilient to regional downtime. Vercel will automatically route traffic to the nearest available edge. Vercel.com uses Azure CosmosDB to store and globally replicate data,
which is different than our Edge Network. This is an additional step
taken to ensure uptime for applications on our platform.
Does Vercel provide infrastructure segregation?
Enterprise Teams on Vercel have their own build infrastructure ensuring
isolation from Hobby/Pro accounts on Vercel.
Does Vercel conduct regular penetration testing and vulnerability scans?
Yes. Vercel conducts regular penetration testing with third-party
experts. In addition to our annual penetration tests, we consistently
perform targeted assessments on an ongoing basis. We also implement
daily code reviews, static analysis checks, and dependency scanning at
the code level. Our cloud security posture management platform (CSPM)
facilitates workload vulnerability scanning. Pro and Enterprise
customers can request access to our latest annual penetration testing reports.
Does Vercel use subprocessors?
Yes, a list of our current subprocessors can be found on our subprocessors page.
Does Vercel have a bug bounty program?
Yes. Vercel has a Private Bug Bounty program that rewards researchers for finding and reporting security vulnerabilities. For more information, or to report a vulnerability, please reach out to us at [email protected]
Does Vercel protect against OWASP Top 10?
Yes. Vercel offers managed rulesets, including one specifically designed to protect against the OWASP Top 10 risks. This feature is available on Enterprise plans.