Security that
scales with you.
scales with you.
Vercel strives to maintain and provide a secure Frontend Cloud experience.
Our Shared Responsibility Model conveys the importance of our partnership with our customers.
Scalable application security and DDoS mitigation with Vercel Firewall.
The Vercel Firewall delivers multi-layer protection against application-layer attacks, DDoS threats, and bots.
- L3/L4 DDoS Protection
- Global L7 Firewall
- Bot Management
Vercel Web Application Firewall. Next-level security, seamlessly integrated.
Observability
Maintain visibility into key metrics and production deployments, allowing you to monitor threats and requests in real-time.
Managed Rulesets
EnterpriseActivate Vercel’s managed rulesets to protect against top priority risks, including OWASP Top 10.
Framework-aware rules
Define rules based on your framework's routes rather than fiddling with regular expressions or prefixes.
Firewall API
Programmatically manage WAF rules and integrate with third-party tools for continuous, dynamic security.
Rate Limiting
Control the frequency of requests made to your web applications and APIs.
Instant Rollback
Quickly revert to previous versions of firewall rules to ensure continuous protection without unintended outcomes.
Instant propagation
Uses the same propagation pipeline as our cache infra, so firewall changes can be seen across the globe in 300ms.
Persistent actions
Block matching requests from a suspicious client for a set duration, preventing repeat malicious behavior and preventing unnecessary resource use.
Extend your backend
Create a secure, isolated bridge from Vercel to your on-premise backend or Kubernetes services with Vercel Secure Compute.
Dedicated environments
VPN and VPC peering
Define your regions
Designed for high availability.
Traffic is routed to the nearest region in the face of incidents or network outages, for resilient protection against full regional downtimes.

Static assets are automatically replicated and cached across the Vercel Edge Network, with Anycast routing to ensure the lowest latency.




Workspace Security.
Role-based Access Control
Assign roles to ensure that the right people have the right permissions to work on your projects.
Deployment Protection
Secure your Vercel project’s preview and production URLs. Fine-grained access control for deployments.
Audit Logs
Track and analyze your team members' activity. Accessed by team members with the owner role.
Directory Sync
Manage your organization’s memberships from third-party identity providers.
@acme/design
@acme/eng
@acme/security
@acme/marketing
Code Owners.
Ensure the right people review the right code, with the right context.
Current Score
Excellent
9.6
Major Issues
Across 6 projects
3
Minor Issues
Across 12 projects
8
Conformance.
Catch issues before they become security vulnerabilities.
Security in the Software Development Lifecycle.
Frequently asked questions.
Does Vercel offer DDoS protection?
Is Vercel SOC 2 Type 2 compliant?
Is Vercel GDPR compliant?
Is Vercel ISO 27001 certified?
Is Vercel certified under the Data Privacy Framework (DPF)?
Does Vercel support HIPAA compliance?
Does Vercel support PCI compliance?
Can I protect my deployments?
Does Vercel encrypt data?
Does Vercel backup the data on its platform?
What infrastructure does Vercel use?
Does Vercel provide infrastructure segregation?
Does Vercel conduct regular penetration testing and vulnerability scans?
Does Vercel use subprocessors?
Does Vercel have a bug bounty program?
Does Vercel offer a Web Application Firewall?
Does Vercel protect against OWASP Top 10?
What is Vercel Access Security?
What is Vercel Infrastructure Security?
What is Vercel Application Security?
Ready to deploy? Start building with a free account. Speak to an expert for your Pro or Enterprise needs.
Trial Vercel with higher execution, increased app bandwidth, Speed Insights, team features, and more.