Enterprise-grade security for you and your clients
Keeping customer data safe is our top priority. At Instapage, we employ industry-approved security measures and advanced features to protect your business data and your clients' privacy.
Secure access to your account
Instapage offers advanced security features to keep your account and your client's data safe.
High page performance
Instapage ensures consistently high performance and unbeatable security for every page you build.
99.99% server uptime
Instapage has dual Amazon and Google cloud server redundancy, ensuring nearly perfect uptime for your campaigns to convert around the clock.
Thor Render Engine®
Enhance page load speed, paid conversions, SEO rankings, and user experience with Intapage's unique Thor Render Engine technology.
Data privacy and compliance
Instapage provides a range of privacy and compliance measures to ensure the protection of your data.
GDPR compliance
Instapage complies with GDPR data privacy and security standards giving EU customers more control over their shared data. We've also made it easy for you to ensure GDPR compliance on your landing pages with features like a data consent cookie bar.
Learn moreSSL certification
Instapage creates SSL certificates each time you publish your page to a custom domain. SSL certificates verify website authenticity and encrypted connection between browser and website, ensuring visitor privacy protection.
SOC2 Type I & Type II
Instapage has undergone two types of SOC 2 audits and received certification showing that Intspage has the right security systems that ensure the security, availability, processing integrity, confidentiality, and privacy of customer data.
EU-U.S. Data Privacy Framework
Instapage participates in the EU-U.S. Data Privacy Framework program to comply with EU data protection requirements for personal data transfers from the EU to the U.S.
Learn moreCCPA/CPRA
Instapage follows the California Consumer Privacy Act (CCPA), now updated by the California Privacy Rights Act (CPRA), to enhance the protection of personal data and privacy for California residents.
Security overview
Instapage takes a holistic approach to security to create a safe environment for your business, protect customer data, and build trust with all our clients.
-
Information security program
Our Information Security Program covers everything from governance, operations, and people security to physical and compliance security. All our policies align with ISO 27001/2 and NIST 800-53 frameworks, reviewed yearly or after significant changes. -
Data privacy and protection program
We have a Data Privacy and Protection Program, which provides data privacy training to all of our team members during onboarding. Awareness training is conducted annually to keep everyone informed and updated on privacy rules. -
Risk management
Instapage follows documented information security risk management policies and procedures to measure, manage, and report risks systematically. Identified risks are inventoried, managed centrally, and remediated based on severity level. Instapage also has vendor risk assessment procedures. -
Information management
Our compliance security policies protect data at all sensitivity levels with Amazon Web Services (AWS) and Google Cloud Platform (GCP) certifications integrated across our cloud infrastructure. -
Incident event & communication management
Instapage has an Information Security Incident Management Program that quickly identifies, manages, responds to, and resolves incidents. The program outlines roles, responsibilities, and proactive capabilities to detect potential incidents caused by vulnerabilities. -
Threat management
Instapage has a Vulnerability Management Program to identify, prioritize, manage, and report on threats and vulnerabilities using a risk-based approach. Everyone on the team should report any security issues they find so we can address them in a timely manner.
Security operations
At Instapage, we leverage tools and procedures to monitor, detect, prevent, and address security incidents and threats.
Asset management
Instapage manages office asset inventory with a documented process. Each asset has an assigned owner for maintenance and classification and is returned when no longer needed or when the owner leaves.
Corporate security
At Instapage, we handle the onboarding and offboarding of the team members in a way that safeguards sensitive information. All team members undergo information security training during onboarding. This training aligns with our HR and information security policies and becomes an integral part of our work process. All team members maintain data confidentiality in accordance with our non-disclosure agreements (NDA) and corporate Code of Conduct.
Physical & environmental security
Team members use key cards or access codes to enter our facilities. We also have security guards, CCTV monitoring, and a visitor log process in place. We greet and guide all visitors, and our cloud-hosted facilities are equipped with perimeter fencing, vehicle barriers, and security alarms for added security measures.
Access control
We've established internal policies and procedures to identify, authenticate, and authorize access to our systems and applications. Access is granted on a need-to-know basis and adheres to the principle of least privilege. We review access logs every quarter and remove people if needed. Plus, all remote team members are required to use a VPN.
Got questions? Contact us, and we'll guide you through them.
Contact usSecurity architecture
Our security architecture comprises components to safeguard digital and physical assets, mitigate risk, and meet regulatory mandates.
-
Application security
We're enhancing application security across all endpoints to combat threats, using an agile-based SDLC framework with proven processes, tools, and technology. This helps us create high-quality and secure code by following a consistent, repeatable, and automated process. -
Business resiliency
At Instapage, we've put together a formal Business Continuity and Disaster Recovery Program with management-approved processes in place to make sure our business services and operations stay up and running. -
End-user device security
At Instapage, we implement a device management program with secure processes to handle device-related operations and ensure that only approved devices connect to our network. Our mobile device management policies and procedures enforce secure processes for mobile device activities, including password complexity, encrypted sessions, and two-factor authentication. -
Network security
Instapage's security architecture management policies and procedures ensure network safeguards like encryption (in transit and at rest), intrusion detection, browser session encryption, host-based anti-virus, and full disk encryption. We run network scans every month, do vulnerability assessments every quarter, and have internal and external penetration tests once a year. Once we find vulnerabilities, we fix them based on how critical they are.