Third Party Index

Snapshot 63522

Document
Security page
URL
https://www.magnolia-cms.com/platform/security.html
Fetched
HTTP status
200
Content type
text/html;charset=UTF-8
Fetch mode
static
Size
114667 bytes
SHA-256 (raw)
21afc9b02fdf66f04715f4b588d1f0e67cb5ec8d3b4fbce713c2a13de9b51121
SHA-256 (normalized text)
b77f1e670c3ec1cd39ecb6a8b7b18161c640fe38cf7df1be89cc8d5709925e89

Normalized text

Scripts and page chrome removed; this is what change detection compares.

The Magnolia DXP Trust Center
Access our complete compliance portfolio, including ISO 27001, SOC 2, and ENS certifications, directly through our self-service portal. The Trust Center provides real-time visibility into our security posture, sub-processors, and vulnerability management policies.
Visit the Trust Center
Choose your deployment model
Deployment flexibility and data sovereignty
Magnolia DXP ensures strict data residency compliance across all deployment models. Magnolia DXP also supports data sovereignty across all deployment models. Whether you utilize our managed PaaS or your own infrastructure, you define the specific legal jurisdictions where your data resides (e.g., DACH, UK, North America, or AWS Sovereign Cloud).
Magnolia DX Cloud (PaaS)
A fully managed, single-tenant environment that combines operational ease with strict regional compliance. You select the hosting region to meet your sovereignty requirements, while Magnolia DXP handles encryption, patching, and high availability.
Operational resilience in financial services
Sainsbury’s leveraged Magnolia DXP PaaS to eliminate infrastructure overhead while maintaining strict compliance standards. By offloading security maintenance and patching to Magnolia DXP’s managed environment, the bank improved authoring efficiency and core customer KPIs without compromising on data protection.
See how Sainsbury’s serves up a streamlined experience with Magnolia
Private Cloud & DX Core (On-Premises)
For organizations requiring architectural independence or air-gapped environments (e.g., Azure Private Cloud), Magnolia DXP supports self-hosted deployments. This model grants your internal security teams absolute control over the entire infrastructure stack.
Infrastructure autonomy with private cloud
Slimming World required strict adherence to its internal Azure security governance. By self-hosting Magnolia DXP, the organization retained absolute control over data residency and security architecture, ensuring the platform integrated seamlessly into their existing Zero Trust environment.
Learn more about Magnolia DX Core
Centralized identity and access management
Magnolia DXP supports enterprise security policies through comprehensive SSO and IDP federation. This architecture enables automated user provisioning and de-provisioning, ensuring that access rights remain strictly synchronized with your central directory.
Cross-domain Identity Management: Automate user provisioning and de-provisioning to ensure access rights are always synchronized with your central directory.
Universal IDP support: Seamlessly integrates with all major Identity Providers (e.g., Okta, Microsoft Entra ID) via modern security standards, eliminating the need for custom authentication development.
Granular Governance: Define scope-based permissions for editors and administrators, ensuring content security without hindering editorial workflows.
Magnolia’s security tier comparison
Our cloud platform is highly secure out of the box.
For the businesses that have extensive security needs, we also offer some advanced security features.
Security aspect
Standard Security
Advanced Security
DDoS Mitigation and Protection
Layer 3, 4 & 7
Layer 3, 4 & 7 + advanced edge rate limiting
WAF
Default Rule Set
Custom Rule Set
Bot Protection Service
excluded
included
AI Traffic Management
excluded
included
Encryption Key Storage
Key owned by cloud vendor or Magnolia
Key owned by customer
Active Threat Monitoring
excluded
included
Vulnerability Scanning
Docker image scanning
Isolated pipeline environment
Malware Detection
excluded
Included with ClamAV installation
Web Defacement Protection
excluded
included
Secure Cluster Communication Traffic
excluded
included
External Penetration Test
optional
included
Magnolia Trust Center
Magnolia provides enterprise-ready, transparent, and secure compliance
See how Magnolia manages security and compliance programs. Access and download any security certification and get instant answers to your questions
Visit the Trust Center
Related blog articles
Magnolia’s security is officially SOC 2 Type 2 compliant
Security
Read the blog
Enhancing security in the cloud: Introducing advanced solutions for Magnolia DX Cloud
Security
Read the blog
Why we prioritize security on Magnolia Digital Experience Platform
Security
Read the blog