Discover dotCMS, the leading headless CMS built for multi-site management. Empower your teams with flexible content modeling, omnichannel delivery, and enterprise scalability.
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
ISO 42001
International standard for AI management systems. Adoption is early; advertising it is a notable signal.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
ISO 27001
International standard for an information security management system, certified by accredited bodies.
-
TX-RAMP
Texas state authorization program for cloud products used by state agencies.
Compliance timeline
-
January 2023
Trust center first observed in public web archives
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Dotcms discloses on its trust center. Linked entries have their own profile in the Trust Index.
40% chain trust: 2 of 5 disclosed subprocessors are themselves in the Trust Index.
- AWS
- Google Cloud Platform Cloud provider
- Strong DM
- Keeper
- GitHub
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.