Snapshot 19158
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Platform Overview Security & Compliance The agentic systems platform for Enterprise-grade security and compliance With modern, end-to-end security woven into every aspect of the platform and its applications, OutSystems is the agentic systems platform for out-of-the-box peace of mind. Schedule demo Contact sales Enterprise-grade, high security—built in Cutting corners on app security is for the other AI platforms. OutSystems gives you enterprise-grade protection that aims to exceed standards, not just meet them. Eliminate manual effort and improve user experience with automatic security patching and no downtime. Build secure mobile apps by unifying CI/CD tools with app shielding features. Easily and securely connect applications with your infrastructure—on-premises, in private, or public cloud—through the OutSystems Private Gateway. Be ready for anything with failover across multiple availability zones (AZs). Learn more about cloud-native security Unparalleled platform and network security You don’t have to tackle cyber threats alone. With an enterprise-grade platform and network security right out of the box, you can let OutSystems handle a lot of the risky stuff. Employ best-in-class protection from SQL injection and XSS with an industry-leading web application firewall. Prevent DDoS attacks with a Content Delivery Network (CDN) and by pairing your own web application firewall with the OutSystems WAF. Benefit from continuous automated intrusion detection, malware scanning, and runtime integrity monitoring for detection and prevention of unexpected activity and potential threats. More about OutSystems network security Security for your mission-critical applications All of your apps deserve security that’s strong enough for your mission-critical applications. With OutSystems, you never get anything less. Avoid misconfigurations that lead to vulnerabilities with an intuitive, visual IDE and automated SDLC. Take charge of your OutSystems applications and network traffic with the power to selectively allow or block user access based on IP address. Minimize risks with isolated production, development, and QA runtimes. Explore more about enterprise security We can't wait to show you this Give us your toughest challenge. We'll show you what OutSystems can do. Schedule demo Schedule demo Get your hands on it You know you want to see for yourself. Go on—give it a go. Start free Start free The fortress you need to prevent insecure data practices We know that your data is one of your most valuable assets. That's why OutSystems gives you the layer of protection you need to prevent deliberate or unintentional data loss, data breaches, and unauthorized data use. Avoid data loss with continuous incremental data backup that allows quick restoration. Reduce the risk of human errors or insider threats with a dedicated database for each development stage. Employ superior data protection with encryption in transit and at rest along with out-of-the-box cryptographic tools. Learn more about data protection Access control without limitations Prevent shadow IT—or worse—by maintaining full control over who can build apps, who can access them, and how they can be used. Leave no backdoors for bad actors with flexible, self-managed identity and access management customized to align with your governance model and access management strategy. Use the least-privilege principle to maintain the strictest possible authorizations and authentication standards. Choose between utilizing a built-in identity provider or seamlessly integrating your preferred identity providers (BYOP). Learn more about governance and access management Certified to global and national compliance standards Our rigorous compliance program ensures the platform meets rigorous international, national, industry and governmental mandates for infrastructure integrity, data protection, and regulatory readiness. Build with confidence on a vetted security foundation powered by a platform that is FedRAMP Authorized and certified for national standards including ENS (Spain), ACN (Italy), and DESC (UAE). Streamline your certification journey by leveraging our audited controls and credentials, including SOC 2 Type II, ISO 27001, and ISO 22301. Maintain continuous compliance with evolving EU and global regulations, including GDPR, the EU Data Act, the EU AI Act, and other privacy and industry mandates such as HIPAA and PCI DSS. See our full compliance portfolio Security FAQ What compliance certifications does OutSystems have? OutSystems platforms comply with HIPAA, PCI DSS, and FedRAMP requirements and hold certifications including SOC 2 Type II and multiple ISO standards. Built-in security and governance controls help customers build compliant applications out of the box. OutSystems also complies with privacy laws such as GDPR. See the OutSystems Trust Center for current details. Is OutSystems HIPAA compliant? OutSystems can support HIPAA-regulated use cases for healthcare organizations and teams handling protected health information. Depending on the deployment model and customer requirements, OutSystems can support Business Associate Agreements and security controls for access, encryption, monitoring, and governance. Customers should confirm scope, responsibilities, and configuration requirements during compliance review. Does OutSystems have FedRAMP authorization? OutSystems supports government and public sector use cases. The OutSystems platform is also FedRAMP-Moderate Authorized in a partnership with Knox. What authentication methods does OutSystems support? OutSystems supports enterprise authentication methods, including SAML, OAuth, SSO, Microsoft Entra ID, formerly Azure AD, and multi-factor authentication via supported identity providers. The platform also includes accelerators for social/B2C logins (Facebook, Google, LinkedIn, Apple). This allows organizations to centralize access control, align applications with existing identity standards, and enforce consistent login and security policies on the platform and across applications. How does OutSystems handle user provisioning and role management across multiple applications? OutSystems supports centralized user provisioning, role-based access control, and permission management across applications. Teams can define roles, assign access by user or group, and manage permissions as their application portfolio grows. OutSystems also allows customers to extend the built-in capabilities via user and access management REST APIs. This helps enforce least-privilege access, simplify administration, address specific provisioning and role management scenarios, and maintain governance across multiple applications and teams. How does OutSystems handle data encryption? OutSystems encrypts data at rest by default and protects data in transit with TLS. Depending on the platform and deployment model, physical and logical separation and namespace segregation help keep customer data isolated. Included security libraries also support envelope encryption, allowing customers to add a second layer of protection for sensitive data. In what region/data center is the data stored? Data residency depends on the customer’s selected region. OutSystems can support region-specific hosting requirements so organizations can keep application data in approved geographies. This is especially important for regulated industries with sovereignty, privacy, or country-specific compliance obligations. How does OutSystems handle vulnerability patching and security updates? OutSystems manages platform and infrastructure patching based on the deployment model. In ODC, one-click patching (1CP) reduces application-owner effort: customers are notified when patches are available, and the platform automatically builds and applies them the next time the application is published. Can we perform penetration testing on our OutSystems applications? Yes. Customers can perform penetration testing on OutSystems applications, typically with coordination and approval to ensure testing follows platform policies and does not disrupt shared infrastructure. Security teams can also use third-party scanning tools and internal assessment processes to validate application security, compliance requirements, and production readiness. What happens during a Vendor Risk Assessment (VRA)? During a Vendor Risk Assessment, OutSystems provides security documentation, compliance evidence, architecture details, data protection information, and responses to customer security questionnaires. Procurement, legal, and security teams use this process to evaluate risk, confirm controls, and verify that OutSystems meets organizational requirements before purchase or deployment. Can OutSystems integrate with our security monitoring tools? Yes. OutSystems can integrate with security monitoring and observability tools such as Splunk, Dynatrace, New Relic, and SIEM or APM platforms. Teams can stream logs, monitor application behavior, and connect platform events to existing security operations workflows, helping maintain visibility across the broader enterprise monitoring stack. What security monitoring capabilities are built into the platform? OutSystems includes built-in monitoring capabilities for application health, errors, performance, access activity, and operational events. Teams can use native logs and dashboards to investigate issues, detect abnormal behavior, and support audits. For deeper observability, OutSystems can also connect with external monitoring, SIEM, or APM tools. How does OutSystems ensure AI models don't expose sensitive data? OutSystems helps protect sensitive data in AI use cases through agent guardrails, access controls, governed model connections, data boundaries, auditability, and configuration options that limit what information agents or AI features can use. Customers should define approved models, data handling rules, and review workflows to reduce leakage risk. What AI security guardrails does OutSystems provide? OutSystems supports AI security guardrails such as role-based access, governed tool access, monitoring, audit logs, and controls that help reduce risks like prompt injection, PII exposure, and unsafe outputs. Agent Evaluations also let teams test agent behavior against defined datasets and criteria, helping validate that agents perform as expected before and after deployment. Can we keep AI processing within our own data centers or specific regions? AI processing location depends on the selected model, provider, and deployment architecture. OutSystems can support governance patterns that help customers choose approved models, route requests through controlled endpoints, and align processing with regional or data sovereignty requirements. Teams with strict constraints should validate provider, hosting, and data residency options early. Related resources Mobile App Security | Evaluation Guide Secure your data with mobile app security. Discover how OutSystems meets the strictest mobile security standards today. Sentry Get supercharged protection for your enterprise cloud-native applications with advanced security tools. Best Practices to Reduce Attack Surface With organizations investing in digital-first apporaches, they needs to increase the focus on cybersecurity. In this... Secure cloud-native low-code patforms checklist Get this checklist on how to evaluate cloud-native low-code platforms. See how OutSystems can work for you Schedule demo Start free