dotCMS · Trust Center

Dotcms Trust Center

Trust center

dotCMS runs a hosted trust center at security.dotcms.com carrying its certifications, the CAIQ and a gated SOC 2 report request. The public summary page at /product/security-compliance names the certifications outright, so they are recorded here from the provider's own words rather than inferred from a badge image.

dotCMS maintains a public trust center documenting ISO/IEC 27001:2022, ISO/IEC 42001:2023, SOC 2 Type II, TX-RAMP Level II, and CSA CAIQ compliance.

CMSContentContent ManagementHeadless CMSDigital ExperienceContent DeliveryWorkflowsGraphQLMCPJava
Trust center: https://security.dotcms.com/

Certifications & Compliance

ISO/IEC 27001:2022ISO/IEC 42001:2023SOC 2 Type IITX-RAMP Level IICSA CAIQ

Source

Trust Center

Raw ↑
generated: '2026-09-06'
method: searched
probe: true
url: https://security.dotcms.com/
public_summary: https://www.dotcms.com/product/security-compliance
description: >-
  dotCMS runs a hosted trust center at security.dotcms.com carrying its certifications, the CAIQ
  and a gated SOC 2 report request. The public summary page at /product/security-compliance
  names the certifications outright, so they are recorded here from the provider's own words
  rather than inferred from a badge image.
certifications:
- ISO/IEC 27001:2022
- ISO/IEC 42001:2023
- SOC 2 Type II
- TX-RAMP Level II
- CSA CAIQ
documents:
- name: SOC 2 Type II report
  access: request
  url: https://security.dotcms.com/?requestAccessOpen=true&requestedResources=68bf49dffa149b0f145d21eb
  note: Gated behind an access request, which is normal for a SOC 2 Type II report.
- name: CAIQ (Consensus Assessments Initiative Questionnaire)
  access: public
  url: https://security.dotcms.com/doc/trust?rid=65ea66456af50d8aa7bb69bc&r=2sr38oqu8xcq3f7qdsuhn
positioning: >-
  Compliance is dotCMS's stated market position, not a footnote — the homepage title is
  "Visual Headless CMS for Compliance-led Enterprises" and the security page frames governance as
  "enforced by the platform, not configured per site". ISO/IEC 42001 is the notable one: dotCMS
  extends its AI governance claim to agent behaviour, describing an AI agent as "another actor in
  the system: it works inside the same roles, permissions, and workflows as a person, and every
  change it makes stays traceable and reversible through version history" — a claim that lines up
  with the reversibility surface recorded in conventions/dotcms-conventions.yml.
evidence:
- source: https://security.dotcms.com/
  status: 200
  kind: trust center
- source: https://www.dotcms.com/product/security-compliance
  status: 200
  keywords: [iso 27001, iso 42001, soc 2 type ii, tx-ramp, caiq, trust center]
- source: https://www.dotcms.com/.well-known/security.txt
  status: 200
  kind: security.txt
checked: '2026-09-06'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/dotcms-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.