Does Webflow allow customers to perform penetration testing and vulnerability scan?
Is Webflow HIPAA Compliant?
Webflow offers numerous capabilities as part of the Webflow Platform. Please refer to https://webflow.com/feature/ai for more details.
At Webflow, we firmly believe your data belongs to you. We do not use customer data to train generative AI models - whether proprietary or third-party.
For third-party AI integrations, we ensure contractual agreements are in place that prohibit the use of customer data for training purposes.
Strong Governance & Responsible AI Practices A dedicated Corporate AI Council sets company-wide standards for safe and ethical AI use. Clear policies guide how AI is used across Webflow, ensuring privacy, fairness, and accountability. All employees receive specialized AI and security training to ensure responsible handling of customer data. Rigorous Vendor & Tool Reviews Every AI tool or partner undergoes strict security and privacy evaluations before approval. AI vendors supporting Webflow's features are prohibited from training models on customer data. Certified & Audited Security Controls Webflow maintains industry-recognized certifications, including SOC 2 Type II, ISO 27001, ISO 27017, and ISO 27018. We conduct both internal and third-party audits each year to validate our security posture. We proactively align with emerging AI standards, such as ISO 42001 and the EU AI Act. Robust Technical Protections Role-based access controls (RBAC) and Single Sign-On ensure only authorized teams can access systems. Data is protected with AES-256 encryption at rest and TLS 1.2+ encryption in transit. Customer assets are segmented and strictly controlled within our multi-tenant environment. AI features undergo secure development processes, including code reviews, security testing, and risk evaluations for bias and quality. Ongoing Testing & Vulnerability Management Annual third-party penetration tests and continuous vulnerability scanning help identify and remediate risks quickly. Our public Vulnerability Disclosure Program allows security researchers to responsibly report potential issues. Secure Devices & Infrastructure Webflow-managed employee devices follow NIST-aligned security standards and include advanced endpoint detection and response technology.
At Webflow, we're committed to delivering AI-powered features that are secure, transparent, and built with your trust at the center. Our AI Security program is designed to protect your data at every stage - through strong governance, responsible practices, and industry-leading safeguards.