Security & Compliance

React Bricks is built for teams that need strong governance, documented security practices, and reliable operational safeguards, without giving up developer control or a fast editing experience.

If you want the complete overview, visit the full Security & Compliance page.

ISO 27001 certification

Since 2025, React Bricks has been certified under ISO/IEC 27001, the international standard for Information Security Management Systems. This means our security practices are structured, audited, and continuously improved through a formal ISMS.

For enterprise teams, this helps reduce vendor risk and can simplify procurement, security reviews, and third-party assessments.

Download the ISO 27001 certificate

Security

Our API and database servers are hosted in top-tier European data centers with strong physical and operational protections, network and power redundancy, and audited security practices.

Security is embedded in how React Bricks is designed, developed, and operated, with documented processes, risk management, and continuous oversight.

Datacenter React Bricks

Privacy & data residency

React Bricks is fully GDPR-compliant and follows a data-protection by design and by default approach. We are transparent about how personal data is processed, and enterprise customers can request additional GDPR documentation when needed. For more information, see our Privacy Notice.

Our databases, replicas, and API servers are located in Europe. Only public assets distributed through the CDN may be served globally.

Access control & SSO

React Bricks supports Single Sign-On with any SAML2-compatible identity provider, including Okta, Entra ID, Auth0, Google, and others. Teams can configure access from the dashboard and optionally enforce SSO-only login.

Fine-grained permissions and custom roles allow you to control access at multiple levels, including users, pages, page types, bricks, and even sidebar controls. Read more on the Security & Compliance page and the Roles and permissions page.

Backup & recovery

Teams can create manual content backups from the dashboard and restore content when needed. For enterprise customers, React Bricks also supports scheduled off-site backups to the customer's own S3-compatible storage.

These backups include structured JSON content and assets, helping organizations maintain an external copy of their CMS data. Learn more on the Security & Compliance page.

Governance

Security only works when it is supported by governance. React Bricks includes operational and editorial controls that help teams manage change safely and consistently.

  • Custom roles and fine-grained permissions
  • Approval workflows and review processes
  • Multiple environments for safer releases
  • Documented controls and auditability aligned with enterprise needs

Explore the complete overview on the full Security & Compliance page.

Ready to start building?