Skip to content
Introducing the Vercel Experts MarketplaceExplore →
  • Templates
  • Analytics
  • Pricing
ContactLoginSign up
Security Shield

Security at Vercel

Vercel is trusted by the best teams to develop, preview, and ship their websites.

Contact Us
Learn More
Trusted by
the best frontend teams
HashiCorp Logo
McDonald’s Logo
Airbnb Logo
Washington Post Logo
Auth0 Logo
Twilio Logo
Uber Logo
Tripadvisor Logo
HashiCorp Logo
McDonald’s Logo
Airbnb Logo
Washington Post Logo
Auth0 Logo
Twilio Logo
Uber Logo
Tripadvisor Logo
HashiCorp Logo
McDonald’s Logo
Airbnb Logo
Washington Post Logo
Auth0 Logo
Twilio Logo
Uber Logo
Tripadvisor Logo

SOC 2

We're committed to securely managing the privacy of our clients.

GDPR

We help our clients (both EU and globally) comply with GDPR.

Enterprise WAF

Our world-class security team keeps your sites online.

Automated Backups

Backups occur every hour and are persisted for 1 month.

SSO/SAML Login

Securely authenticate with platforms like Okta, Auth0, and more.

Scalable DDoS Mitigation

Vercel automatically detects and blocks malicious attacks.

HTTPS/SSL by default

Industry standard encryption by default with the Vercel platform.

Enterprise Edge Network

Your own secure, isolated environment.

Global Resiliency

Prevent downtime with automatic failovers to the nearest region.

The Most Secure Platform For Next.js

Developers love Next.js, the open source React framework Vercel built together with Google and Facebook. Vercel is the platform built for Next.js.

Talk to an Expert

Google Chrome

The Google Chrome team works closely with Vercel to consistently improve the performance and security of Next.js.

Facebook

The React team at Facebook ensures the latest security updates and patches are immediately released to Next.js.

AWS

In rare cases of large distributed attacks on our customers, we work directly with AWS to prevent downtime.

Frequently Asked Questions

Vercel is a global deployment network using Serverless technology, taking advantage of sandboxing and isolation to ensure no two customers share the same virtual machine. Vercel makes teams productive by giving teams a seamless developer experience to build modern, scalable web apps.

Yes. Vercel Enterprise customers are covered by two forms of DDoS protection. Our Enterprise WAF can automatically detect and block malicious attacks on customer sites. For significantly larger, distributed attacks, we work closely with the customer to ensure your site(s) stay online. The combination of automated prevention and direct communication from our Customer Success Managers helps ensure your site is resilient to attacks. Contact our sales team to learn more.

Vercel's Enterprise WAF helps protect customers against vulnerabilities by filtering out malicious traffic. Enterprise customers can also work with our Security team to modify their IP allowlist.

Vercel is SOC2 Type 1 compliant. We are in the process of completing SOC2 Type 2 compliance. Contact us for more details on completion.

Yes. For more information, see our Privacy Policy. No data is stored permanently inside EU regions. Static assets and Serverless Functions responses can be cached in EU regions, but it is ephemeral.

Vercel is currently not HIPAA compliant. We are planning to complete compliance in 2021. Contact us if HIPAA is important for you and we can share more details.

Vercel does not store personal credit card information for any of our customers. We use Stripe to securely process transactions and trust their commitment to best-in-class security. Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry.

Yes. For team accounts (Pro or Enterprise), Vercel offers Password Protection and SSO Protection for Preview and Production deployments.

Yes. Data is encrypted at rest (AES-256) and in transit (HTTPS / TLS), including sensitive information like access tokens and secrets.

Yes. Our current backup interval is every hour and each backup is persisted for 1 month. Automatic backups are taken without affecting the performance or availability of the database operations.

All the backups are stored separately in a storage service, and those backups are globally replicated for resiliency against regional disasters. If a database instance is deleted, all associated backups are also automatically deleted. Backups are periodically tested by the Vercel engineering team.

The Vercel Edge Network & deployment platform primarily uses Amazon Web Services (AWS). In the case of an AWS outage, our network is resilient to regional downtime. Vercel will automatically route traffic to the nearest available edge. Vercel's platform has the ability to switch to other cloud providers entirely (GCP, Azure) in the event of major downtime. We currently have 16 different regions and an Anycast network with global IP addresses.

Vercel.com uses Azure CosmosDB to store and globally replicate data, which is different than our Edge Network. This is an additional step taken to ensure uptime for applications on our platform.

Vercel Enterprise customers have their own sandboxed environment, ensuring resiliency from Hobby/Pro accounts on Vercel. This is an additional security measure we've put in place to ensure our 99.99% SLA for Enterprise is met. Additionally, our Enterprise WAF has advanced DDoS protection (see "Does Vercel offer DDoS protection?").

Yes. We conduct regular penetration testing through third-party pen testers. On top of that, we also have daily code reviews, static analysis checks, and dependency vulnerability scans through GitHub and Vanta. Our Enterprise customers have access to our latest pen test reports.

Report Vercel Security Concerns

Get in touch with our security team to disclose any security vulnerabilities.

Talk to Us
  • Next.js
  • Create React App
  • Gatsby
  • Nuxt.js
  • Vue
  • Angular
  • More Frameworks
  • Documentation
  • Experts
  • Guides
  • Support
  • API Reference
  • OSS
  • Command-Line
  • Integrations
  • Home
  • Blog
  • Changelog
  • About
  • Careers
  • Pricing
  • Security
  • Next.js Conf
  • Partners
  • Contact Us
  • Privacy Policy
  • Terms of Service
  • Trademark Policy
  • Inactivity Policy
  • DPA
  • SLA
Copyright © 2021 Vercel Inc. All rights reserved.