In an enterprise platform decision this heading usually sets the shortlist. Marketing teams run the feature comparison, but information security and legal have the last word. This page collects WordPress VIP’s security and compliance posture in a form you can take to a review board.
Wider context: what WordPress VIP is.
Certifications and authorisations
- SOC 2 — independently audited information security controls, with audits repeated annually.
- ISO 27001 certified data centres.
- US federal authorisation (FedRAMP Moderate). VIP states it is the only enterprise WordPress platform holding it. Usually a precondition for organisations working with federal agencies.
- State and local public sector authorisations (GovRAMP, TX-RAMP).
- Accessibility compliance — WCAG 2.0 AA and Section 508, with a higher level targeted.
Outside the United States these frameworks are not local obligations. In procurement committees they are read as a maturity signal: evidence that you are buying from a provider that submits to independent audit. Local data protection obligations and where your data physically sits are separate questions, to be settled during contracting.
Vulnerabilities: the most important difference
This is specific to WordPress and it is where the platform earns most of its enterprise value. On an ordinary installation the cycle runs like this: a vulnerability is disclosed, a fix is published, your team applies it. The gap runs from hours to days, and attackers work precisely inside that gap.
VIP closes it. Vulnerabilities are scanned for continuously and addressed at platform level before you hear about them. In organisational terms: tracking security patches stops being your team’s job.
Data, backups and continuity
- Full separation. Each customer’s data is held separately; there is no environment shared with another client.
- Continuous backups. Taken without interruption, recoverable up to a month back, and held offsite as well.
- An independent copy. At higher service levels backups can also be sent to storage under your own control. If your internal policy requires a copy independent of the provider, this line decides the level.
- Disaster recovery. Documented recovery procedures, with failover at higher levels.
- Structural protection. The platform architecturally closes one of the most common attack paths in the WordPress world. It is not a setting but an unchangeable design decision.
Who has access to what
- Single sign-on against your corporate identity system. When someone leaves, their access closes centrally.
- Multifactor authentication and role-based permissions.
- Complete audit logging. Who did what, and when, is on record.
- Fine-grained publishing permissions. Rights can be defined not just at page or role level, but at the level of individual parts of a piece of content.
- The same granularity applies to AI tools.
Read the last two together. In an enterprise, granting AI the ability to publish will not pass internal review unless that authority can be bounded precisely. The platform’s real contribution on the AI side is not the model, it is this control layer.
One note: we tested this layer in our own VIP environment and found a few behaviours not covered in the documentation, which we reported to Automattic. If you plan to audit AI usage, raise the subject explicitly with the vendor during evaluation.
What happens during an incident
- Recovery from backup, with documented procedures.
- A committed response time tied to your service level; fifteen minutes at the highest.
- Breach notification and investigation support.
- A stated commitment to transparency on third-party legal requests.
Before you enter a security review
Settling these five in advance shortens the process noticeably:
- Which certifications are contractual requirements, and which are preferences? Evaluations run for months without that split.
- Where does your data need to sit?
- Which identity system will it integrate with?
- How long must you retain audit logs, and where should they flow?
- What are the limits on any authority you grant AI tools?
We can produce an assessment mapping your requirements against the platform’s actual capabilities: the mandatory items, the open questions, and what to put to the vendor. See how we work or get in touch.
United States / English
Slovensko / Slovenčina
Canada / Français
Türkiye / Türkçe