232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE
← Webflow · Trust Centre

This is an extract from an archived copy, fetched 1 October 2026. Webflow didn't author this page for us. It's a snapshot we captured from https://trust.webflow.com/?itemUid=1a9e841c-2a24-4c01-b5ad-975e63798beb&source=click. We hold the whole page and publish this part of it: the sentence a verdict rests on, with the text either side, so you can see it hasn't been lifted out of an exception.

SHA-256
632E4EC6…B48A

The passage, in context

Paragraph 162 of 224

Does Webflow allow customers to perform penetration testing and vulnerability scan?

Is Webflow HIPAA Compliant?

Webflow offers numerous capabilities as part of the Webflow Platform. Please refer to https://webflow.com/feature/ai for more details.

At Webflow, we firmly believe your data belongs to you. We do not use customer data to train generative AI models - whether proprietary or third-party.

For third-party AI integrations, we ensure contractual agreements are in place that prohibit the use of customer data for training purposes.

Strong Governance & Responsible AI Practices A dedicated Corporate AI Council sets company-wide standards for safe and ethical AI use. Clear policies guide how AI is used across Webflow, ensuring privacy, fairness, and accountability. All employees receive specialized AI and security training to ensure responsible handling of customer data. Rigorous Vendor & Tool Reviews Every AI tool or partner undergoes strict security and privacy evaluations before approval. AI vendors supporting Webflow's features are prohibited from training models on customer data. Certified & Audited Security Controls Webflow maintains industry-recognized certifications, including SOC 2 Type II, ISO 27001, ISO 27017, and ISO 27018. We conduct both internal and third-party audits each year to validate our security posture. We proactively align with emerging AI standards, such as ISO 42001 and the EU AI Act. Robust Technical Protections Role-based access controls (RBAC) and Single Sign-On ensure only authorized teams can access systems. Data is protected with AES-256 encryption at rest and TLS 1.2+ encryption in transit. Customer assets are segmented and strictly controlled within our multi-tenant environment. AI features undergo secure development processes, including code reviews, security testing, and risk evaluations for bias and quality. Ongoing Testing & Vulnerability Management Annual third-party penetration tests and continuous vulnerability scanning help identify and remediate risks quickly. Our public Vulnerability Disclosure Program allows security researchers to responsibly report potential issues. Secure Devices & Infrastructure Webflow-managed employee devices follow NIST-aligned security standards and include advanced endpoint detection and response technology.

At Webflow, we're committed to delivering AI-powered features that are secure, transparent, and built with your trust at the center. Our AI Security program is designed to protect your data at every stage - through strong governance, responsible practices, and industry-leading safeguards.

Other captures of this document the entry has cited

Checking the rest of it

The complete page is kept here and isn't republished. It's Webflow's copyrighted document, and an extract is what a reader needs to check a quotation. The SHA-256 above is of that whole snapshot: fetch the page yourself, hash it, and you can tell whether ours has been altered without having to trust us.

If you work for Webflow, or you are researching this and need the full capture, ask us for it and we will send it. If you believe a quote here is wrong or out of date, send us the paragraph. The correction gets published beside the clause.