Third Party Index

Snapshot 18858

Document
Data processing addendum
URL
https://compliance.vtex.com/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
512865 bytes
SHA-256 (raw)
381af8f60b7e8fd72614aecad6d6796f522ff3c16e89206e1cbbfe57b97119eb
SHA-256 (normalized text)
500f6149e8316325728f68074df9a1f9214529e6654bf5424a1ac44c0668d0dd

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
Start your security review
View & download sensitive information
Ask for information
Overview
Welcome to the VTEX Trust Center — where transparency meets accountability.
At VTEX, trust is the foundation of everything we build. Our platform is designed with security, privacy, and compliance by design, aligned with international standards like ISO 27001, SOC 1 Type II, SOC 2 Type II, PCI DSS, GDPR, LGPD, CCPA, and more. We integrate robust governance, risk management, secure development practices, and data protection into every layer of our operations to deliver a resilient and transparent commerce experience. Through industry-recognized compliance validations, proactive incident response, and customer-centric privacy tools, we ensure that you — and your shoppers — can grow confidently with VTEX. This Trust Center is your gateway to everything we do to earn and maintain your trust, every day.
Remember, #WeAreTrusted.
Compliance
ISO/IEC 27001
PCI DSS
SOC 1 Type 2
SOC 2 Type 2
GDPR
CCPA
CPRA
HIPAA
ISO/IEC 27701
LGPD
PIPEDA
SOX
Visa Service Provider
BBB National Programs DPF Services
VTEX is reviewed and trusted by
J.W. Pepper
Worldwide Golf
U.S. Electrical Services
Al's
Stanley Black & Decker
L3Harris
Nestlé
Electrolux
Coca-Cola
Carrefour
Walmart
Vans
Documents
COMPLIANCEISO/IEC 27001
COMPLIANCEISO/IEC 27701
COMPLIANCEPCI DSS
COMPLIANCESOC 1 Type 2
COMPLIANCESOC 2 Type 2
LEGALEnd User Licensing Agreement
LEGALGeneral External Privacy Notice
COMPLIANCEAnti-Bribery and Anti-Corruption
COMPLIANCEAnti-Competitive Practices
COMPLIANCEAnti-Money Laundering
COMPLIANCECode of Ethics
COMPLIANCECode of Ethics and Conduct for Third Parties
Product Security
Audit Logging
Data Security
Data Security Standards
View more
Vulnerability Management
Platform Customizations
Scan Frequency
Privacy & Data Protection
Data Processing Addendum
Privacy Whitepaper - Privacy Program
Privacy Whitepaper - International Transfers and the DPF
View more
Legal
Subprocessors
Customer Audits
Cyber Insurance
View more
Platform Security
Anomaly Detection
API-first
HTTPS
View more
Data Security
Access Monitoring
Data Backups
Data Erasure
View more
App Security
Responsible Disclosure
Bot Detection
Code Analysis
AI
AI Security
AI Monitoring
AI Risk Management
View more
Compliance
Anti-Bribery and Anti-Corruption
Anti-Competitive Practices
Anti-Money Laundering
View more
Access Control
Access Management Policy
Data Access
Internal Single-Sign-On (SSO)
View more
Infrastructure
Status Monitoring
Amazon Web Services
Anti-DDoS
View more
Endpoint Security
Disk Encryption
DNS Filtering
Endpoint Detection & Response
Network Security
Data Loss Prevention
DNSSEC
Firewall
Corporate Security
Asset Management Practices
Email Protection
Employee Training
Policies
Acceptable Use Policy
Strategic Information Security and Privacy Policy
Access Management Guideline
View more
Incident Response
Data Protection
Incident Reporting Plan
Pentest
View more
Log Auditing
Access to Log Records
Log Record
Asset Management
Asset Inventories (Hardware/Software)
Critical Assets
Secure Asset Disposal
BC/DR
Business Continuity Plan (BCP)
Disaster Recovery Plan (DRP)
Training
Phishing Training
Secure Development Training
Security Awareness Training
View more
Physical & Environment
Data Center Location
Data Center Protection
Devices and Equipments
Secure Development
Best Practices
Secure Coding Guidelines
Segregation of Environments
View more
Knowledge Base (FAQ)
Are information security polices critically analyzed and maintained to comply with legal, regulatory, or contractual cybersecurity obligations? How often are they reviewed?
What's the frequency of the vulnerability scans run by VTEX?
Does the VTEX platform use an API-first approach?
Does the company have a data protection and privacy policy? If yes, how often is it reviewed? Has the policy been distributed and communicated to the entire company?
Does VTEX perform international transfers of personal data? How does VTEX ensure the reliability on international transfers?
View more