Enterprise-Grade Website Security

Pantheon protects your Drupal, WordPress and Next.js websites with architecture that limits unauthorized change, makes drift visible, and gives teams a provable record of what is running.

Image

Security

Secure Every Step to Production

Secure your site with architecture that helps prevent unauthorized code changes and makes every release visible and reversible.

Image

Integration cloud

Close the code-to-production path

Pantheon’s containerized production environment is read-only. Code cannot be silently altered in production, helping block the drive-by plugin and file-drop path before it becomes a change on a live site.

Image

updates

Prove what is running

Mandated version control across Dev, Test, and Live makes changes visible, reversible, and easier to compare against a known-good state.

Image

DDoS

Respond across the platform

When a new threat emerges, Pantheon applies protective rules across the platform while teams identify affected sites, communicate with customers, and support audit and cleanup work.

Image

Open Source CMS as a Service

Isolate site workloads

Each site runs in isolated containers, helping limit the impact of issues across applications and infrastructure.

Image

Check

Monitor continuously

Continuous checks across network, server, and application resources help surface issues early and provide a transparent record of platform status.

Image

Website Management

Encrypt every connection

Managed TLS certificates help protect your site and visitors without adding certificate-management overhead.

Image

Profiles

Strengthen identity controls

Use SAML, SSO, and MFA to centralize authentication and support stronger access policies.

Image

Role-Based Access Control

Control deployment access

Role-based permissions let teams work where they need to—and limit who can deploy to live sites.

Image

Disaster Recovery

Recover with encrypted backups

Automated, encrypted backups and dashboard restores give teams a dependable path back when recovery is needed.

Compliance & Information Security

Pantheon is regularly reviewed by third parties to verify platform security, privacy, and compliance—and we are constantly working to widen this coverage. Learn more about Pantheon’s conformity with the following information security policies and certifications:

SOC 2 Type 2

SOC 2 compliance provides third party assurance to our customers about the adequacy of Pantheon’s information security system. Our SOC 2 Type 2 compliance covers the Security and Availability Trust Services Criteria.

Image

AICPA SOC logo

Image

GDPR logo

GDPR

The General Data Protection Regulation (GDPR) is a data privacy law that defines a framework for how companies use and protect personal information about European Union citizens. Pantheon complies with all applicable data privacy laws including GDPR.

FERPA

The Family Educational Rights and Privacy Act (FERPA) is a federal law that protects the privacy of student education records. While customers are responsible for designing their application correctly to meet FERPA standards, Pantheon's security policies and infrastructure allow customers to be FERPA compliant.

Image

FERPA logo

Image

images.png

TX-RAMP Level 1

Pantheon’s Level 1 Texas Risk and Authorization Management Program (TX-RAMP) Certification validates that our WebOps platform meets the rigorous security and risk management standards required to safely handle the public and non-confidential data of Texas state agencies and higher education institutions.

Platform Security

Our stack is secure by design—engineered and maintained using rigorous security best practices.

Image

security

Resource Isolation

Pantheon ensures process and memory-level isolation using control groups for memory, disk, CPU. Valhalla's encrypted distributed file system employs client-server authentication. Customer files are secured by Linux permissions, while system and customer logs remain isolated.

Image

redundancy

Redundancy

Pantheon maintains full redundancy for core components: API, edge routing, DNS, and file storage. Automated tools aid recovery. Services tolerate process/server failure. Multi-datacenter presence facilitates restoration. Redundant upstream providers enhance reliability.

Image

security

Anti-Malware

Pantheon relies on trusted repos, validates packages, and audits changes on Linux servers. User software runs in isolated containers, preventing direct execution of uploaded files. ClamAV antivirus with updated databases is provided for customer use.

Image

database

Datacenter Security

Pantheon’s primary data centers are managed by Google and feature a layered security model. This includes safeguards like custom-designed electronic access cards, alarms, vehicle access barriers, perimeter fencing, metal detectors & biometrics, and laser beam intrusion detection.

Image

network

Employee Administrative Access

Pantheon grants access according to least privilege. Employees can interact with servers via a secure API without actual server access—when they do need it, SSH-key based authentication is used and activity is recorded in a central log.

Image

Automated Updates

Patches and Updates

Pantheon updates container hosts with latest kernel, OS, packages. Seamless migration to new instances, zero downtime. CMS updates and patches are internally tested and deployed via one-click workflow for customers.

Image

Support

Incident Response

Pantheon's agility swiftly addresses vulnerabilities (Heartbleed, Shellshock, GHOST). Fresh layers prevent exposure. Post-incident reviews enhance future responses. Significant disruptions updates can be found at https://status.pantheon.io/ and @pantheonstatus

Image

Publish Content

Customer Content Durability

Pantheon uses on-disk storage with hardware RAID, multiple disks. Automated backups offer further protection. Backups, over 99.99% durable, encrypted, stored in multiple datacenters, ensure availability.

Image

security

Network Security / Intrusion Prevention

Pantheon uses x.509-based authentication, encryption for network security. Edge routers tunnel traffic, prevent bypass. Host intrusion prevention for user-pw services, server layer stops unauthorized access. Centralized security logs retained for a year.

Need additional security measures?

How Secure Is Your Data in Drupal? (And 5 Essential Security Tips)

4 min read
Read More
Multizone Failover

Maintain 99.99% uptime and minimize loss in the event of a total data center failure.

Read More
Managed Updates for WordPress and Drupal

Seamlessly update your WordPress or Drupal website with features like regular detection, visual regression testing, and supervised deployment

Read More