Security at ApostropheCMS

ApostropheCMS maintains a systematic, transparent security program designed for enterprise customers and developer teams. As an open source core platform, we combine documented processes, regular validation, and continuous improvement.

De-risk your CMS decision

  • Documented security baselines and incident response

  • Annual red team penetration testing

  • Transparent security practices and responsible disclosure

  • Enterprise-ready with security by design

Annual Security Cadence (Or Better)

We maintain a regular schedule of security activities throughout the year. This systematic approach ensures continuous security improvement and independent validation.

Activity

Frequency

Last Completed

Next Scheduled

Risk Assessment

Annual

Q1 2026

Q1 2027

IR Tabletop Exercise

Annual

Q2 2026

Q2 2027

Security Training

Annual

Q2 2026

Q2 2027

Risk Register Review

Quarterly

Q1 2026

Q2 2026

Dependency Health Monitoring

Nightly

Nightly

Nightly

Our Security Program

ApostropheCMS maintains five core components of security maturity, each with documented processes and regular validation.
  • Documented Security Baselines

    We maintain written security standards that define minimum requirements across infrastructure, applications, access control, and data handling. Our baseline covers cloud security controls, mandatory code review, least privilege access, and encryption requirements.

    Current Version: Security Baseline v1.1 (Updated January 2026)

  • Incident Response Preparedness

    Our documented Incident Response Plan defines roles, severity classifications, escalation procedures, and communication templates. We conduct annual tabletop exercises with senior leadership to test and improve our response capabilities.

    Response Team:

    Incident Commander: Tom Boutell (CEO)

    Technical Lead: Miro Yovchev (Senior Engineer)

    Communications: Lindsay Ifill (Customers), Bob Means (Community)

  • Security & Privacy Training

    All team members complete annual security and privacy training covering data protection, access security, and incident reporting. Engineers receive additional secure development training including OWASP Top 10 and dependency management.

    Training Requirements:

    New hires: Completed within first week, before production access

    Annual refresh: All team members (Q2 annually)

    Status: Training program launched in 2026, 100% completion

  • Risk Management

    We conduct quarterly risk assessments to identify, score, and mitigate security and privacy risks across our organization. High-priority risks receive quarterly reviews to track mitigation progress.

    Current Summary:

    Total Active Risks: 13

    Risk Categories: Infrastructure, application, data protection, access control, privacy & compliance, third-party, operational

    Next Assessment: Q2 2026

  • Internal Security Testing Program

    We have instituted in-house red team penetration test exercises. Our red team is given the time and resources, including AI resources, to seriously challenge the defenses of ApostropheCMS. In the past we have also collaborated with major customers' red teams and responded promptly with security fixes where needed.

    Testing Scope:

    Application security assessment (ApostropheCMS platform)

    Findings remediation: when not publicly known, issues found are addressed in our next monthly maintenance release (e.g. 30 days or less).

    Next Test: Q3 2026 (scheduled)

  • Open Source Security

    In the AI era, security issues are easier to find for "white hats" and "black hats" alike. Open source gives us an edge here. We participate in github's Security Advisory program, and respond promptly to all security issues reported. These are treated with the same gravity as discoveries made by our in-house team, and remediated promptly on the same basis.

  • Dependency Health Monitoring

    We maintain a continuous, automated inventory of all open source dependencies across the ApostropheCMS codebase. Each package is scored on update recency, adoption (GitHub stars and download counts), and known vulnerability status. Scores are rolled up into an organizational security score, updated weekly and published to the team for maximum visibility.

Securing Your Content

  • Platform Security Features

    In addition to our organizational security program, ApostropheCMS includes robust security features built into the platform itself.

  • Controlled Content Access

    Restrict access to pages or sections of your site with login-required protections, ensuring only authorized users can view private content.

  • Document-Level Editing Permissions

    Control who can edit at the page or individual document level with fine-tuned user and group settings using our Advanced Permission extension.

  • Role-Based Content Management

    Apply permissions at the group level for both document types and individual documents with our Advanced Permission extension. Or manage contributions safely using our standard Contributor and Editor roles in Community Edition.

  • Scheduled Publishing & Embargo

    Set future publication dates to automate content releases while maintaining full control over visibility.

  • Secure File Management

    Prevent unauthorized sharing of file links with automatic permission updates when files and content are archived.

  • Built-In Review & Approval

    Ensure quality and compliance with streamlined content approval workflows before publication.

  • Single Sign-On (SSO) Support

    Focus on a single secure login system by integrate with Google Workspace, OAuth, SAML, and more. Or use our built-in accounts, secured with industry-standard scrypt password hashing.

Open Source Security

As an open source project, ApostropheCMS benefits from community scrutiny and transparent security practices. We embrace this transparency as a competitive advantage.

Privacy Principles

  • Privacy & GDPR Compliance

    ApostropheCMS is designed with privacy by default. We collect minimal data, do not activate analytics or tracking by default, and give customers full control over their GDPR compliance.

  • Data Minimization

    We only collect data necessary for platform functionality. No unnecessary tracking or analytics by default.

  • Customer Data Ownership

    Customers maintain full ownership and control of their content and data.

  • Prompt Data Deletion

    Customer data is deleted immediately upon service termination. No retention for marketing or other purposes.

  • Transparency

    Clear documentation of data handling practices, storage locations, and processing activities.

GDPR Support

  • Data Processing Agreements (DPAs)

    DPAs are available upon request for customers requiring formal GDPR documentation.

  • Privacy Risk Assessments

    Privacy considerations are integrated into our annual risk assessment process.

  • Data Protection by Design

    Privacy principles are incorporated into feature development from the start.

  • Data Location

    Customer data is stored in AWS data centers. Customers are always invited to select their AWS region of choice. Self-hosting is also fully supported.

Customer Responsibility

Customers developing sites with ApostropheCMS make their own GDPR compliance decisions for their specific use cases (visitor consent, analytics, cookies). ApostropheCMS itself does not introduce GDPR compliance issues by default.

Contact security@apostrophecms.com

Enterprise Security Support

Detailed security documentation is available for qualified enterprise prospects:

  • Security Baseline: Infrastructure, application, access control, and data protection standards

  • Incident Response Plan: Roles, procedures, severity classifications, and communication protocols

  • Risk Register Summary: Identified risks, scoring, and mitigation plans

  • Penetration Test Reports: Executive summaries available after Q2 2026 testing completion


Response Times

  • Security Reports: Within 2 business days

  • Security Questionnaires: 2-3 business days

  • Custom Documentation Requests: Upon request

Security Program Status & Roadmap

  • Completed
    • Documented security baselines and standards (v1.1)

    • Incident response plan with defined roles and procedures

    • Annual security training program launched

    • Annual risk assessment process established

    • Quarterly risk reviews scheduled

    • Automated dependency vulnerability scanning (npm audit)

    • Security Training Program Created and Completed (100% completion rate)

  • In progress
    • Red team penetration testing (scheduled Q3 2026)

Security Updates

This security page is reviewed and updated quarterly to reflect our current security posture.

ApostropheCMS is committed to maintaining a transparent, systematic security program that evolves with our customers' needs and the threat landscape.