Third Party Index

Snapshot 21308

Document
Security page
URL
https://commercetools.com/commerce-platform/security-compliance
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
195842 bytes
SHA-256 (raw)
47ab5f015e2f28805608ec61d5a929814c3cf2466e2954b45d91900199fe9ed6
SHA-256 (normalized text)
ef33cb7397e2a4e669444745ba5e239db8f1583d2fa0488ccbee540b43a52266

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust is the foundation of everything we do
Security and trust are at the core of our platform. We are committed to responsibly managing customer data and providing full transparency into how it is stored, processed and used.
Access Trust Center
SECURITY AT A GLANCE
Security built into every layer
Managing customer data responsibly is fundamental to the commercetools platform. Built on a cloud-native, multi-tenant architecture, it runs on certified infrastructure across Europe, the US and APAC, leveraging leading cloud providers and modern security standards.
Physical security
Our platform is hosted on Google Cloud Platform (GCP) and Amazon Web Services (AWS), both of which operate state-of-the-art, ISO/IEC 27001-certified data centers that are SOC 2 compliant. These environments are designed with security and data protection as core principles. In addition, commercetools offices are access-controlled, monitored and managed through strict visitor and zoning procedures to ensure physical security.
Network security
All traffic is protected using cloud-native Web Application Firewall (WAF) protections and encrypted using modern cipher standards. Access to internal networks is restricted, monitored and secured using encrypted protocols and firewalled infrastructure.
Platform security
All communication with the platform is encrypted via HTTPS using TLS 1.2 or higher. Data at rest is encrypted using AES-256, and passwords are never stored in plain text. The platform is continuously monitored for vulnerabilities, with regular penetration testing to ensure that isolation and data segregation standards are maintained.
Operational security
Security is governed by a formal Information Security Management System (ISMS), overseen by an Information Security Officer. Policies, processes and controls are continuously reviewed and improved to maintain strong security and compliance standards.
Backup & recovery
Data is backed up across geographically separated environments to ensure resilience and availability. Backups are encrypted and stored separately from production systems, enabling reliable recovery and protection against data loss.
Training & awareness
All employees and contractors complete confidentiality agreements and receive regular security and privacy training to ensure awareness and adherence to best practices.
Certificates & standards
Certificates & standards
Independent certifications that validate our commitment to security, privacy and reliability.
Cyber Essentials
Learn more
GDPR
Learn more
SOC II
Learn more
ISO/IEC 27001
Learn more
PRIVACY
Compliant with data protection and privacy regulations
Managing customer data responsibly is fundamental to the commercetools platform. Built on a cloud-native, multi-tenant architecture, it runs on certified infrastructure across Europe, the US and APAC, leveraging leading cloud providers and modern security standards.
Management processes
Our Data Protection Management System is integrated into our Information Security Management System and aligned with ISO/IEC 27001 and ISO/IEC 27701 standards. Both systems are centrally managed and regularly reviewed through internal and external audits.
Security of data processing activities
We implement appropriate technical and organizational measures (TOMs) to ensure secure processing of information across all services and infrastructure.
Data deletion
Deletion requests from data controllers are executed in accordance with applicable instructions. Internal data retention and deletion policies are also defined and enforced.
Data processing agreement
Under GDPR Article 28, data controllers are required to engage only processors that provide sufficient safeguards. commercetools offers a Data Processing Agreement (DPA) upon request via [email protected].
Data protection officer
commercetools has appointed an external Data Protection Officer who works closely with our internal Data Protection Coordinator. They can be contacted at [email protected].
International data transfer
Where data is transferred outside the EU, commercetools uses appropriate legal safeguards, including EU Standard Contractual Clauses, to ensure compliance with GDPR requirements.
Compliant with GDPR, CCPA and Australia Privacy Act
commercetools is committed to compliance with global privacy regulations, including GDPR, CCPA and the Australian Privacy Act, ensuring consistent
protection of personal data across regions.
RELIABILITY
Built for scale and always-on commerce
commercetools is a cloud-native, modular platform designed for high availability and consistent performance across all digital touchpoints. It enables seamless customer experiences across devices and channels, while running on a containerized, cloud-agnostic architecture (GCP and AWS) with full auto-scaling for resilient, always-on operations.
Business Continuity Management (BCM)
Our Business Continuity Management ensures that critical services can be restored within defined and agreed timeframes. The business continuity plan identifies potential internal and external risks and combines technical and organizational measures to ensure resilience. It includes procedures for operating under adverse conditions, such as natural disasters, cyber threats or human error, to ensure the continuity of day-to-day business operations.
Performance management
Performance management ensures that our infrastructure, service and supporting processes deliver a consistent, cost-effective level of availability and reliability aligned with customer needs. Built on a cloud-native architecture, the commercetools platform supports automatic scaling as demand increases across customers and workloads.
Change management process
Changes may be initiated by customers via support tickets, our Platform Support Team or internal teams to improve functionality, resolve issues, or enhance performance. All changes are implemented through automated CI/CD pipelines in appropriate development and test environments. Structured review and approval processes before being deployed through staging environments into production.
Enterprise-grade compliance by design
We align with the highest international standards and continuously invest in the infrastructure, certifications and controls that enterprise customers expect. From GDPR to ISO to anti-corruption practices, our approach to compliance is proactive, rigorous and built to scale.
Modern slavery statement
Incident reporting system
Cloud service providers
Modern slavery statement
This statement is made in accordance with the UK Modern Slavery Act 2015 and applies to commercetools GmbH, commercetools Limited UK and commercetools AU Pty Ltd.
It outlines our ongoing commitment to preventing slavery and human trafficking across our operations and supply chains, and reflects our broader commitment to ethical business practices, transparency and respect for human rights.
Incident reporting system
Employees, partners and third parties can report suspected legal or policy violations through our secure, external incident reporting system. This includes concerns related to misconduct, safety or security.
The system ensures confidentiality, transparency and protection from retaliation for anyone reporting genuine concerns.
Champion customers
Before onboarding new suppliers, we assess their security and data protection measures to ensure an appropriate level of protection. Our primary subcontractors are cloud service providers.
These providers are regularly independently audited and certified against global security, privacy and compliance standards, including recognized international frameworks.
Google Cloud Compliance
AWS Compliance Program
Need more information?
commercetools continuously undergoes independent verification of platform security, privacy and compliance controls. Our strong and growing focus on compliance will help you meet your regulatory and policy objectives.
The audit reports can be requested upon receipt of a signed NDA. Please contact your sales contact or send your request to see the audit reports to [email protected].
Access Trust Center
The Digital Commerce AI Company
Join 500+ enterprises already running on commercetools.
Contact us
Start free trial