The agentic systems platform for
Enterprise-grade security and compliance
With modern, end-to-end security woven into every aspect of the platform and its applications, OutSystems is the agentic systems platform for out-of-the-box peace of mind.

Enterprise-grade, high security—built in
Cutting corners on app security is for the other AI platforms. OutSystems gives you enterprise-grade protection that aims to exceed standards, not just meet them.
Eliminate manual effort and improve user experience with automatic security patching and no downtime.
Build secure mobile apps by unifying CI/CD tools with app shielding features.
Easily and securely connect applications with your infrastructure—on-premises, in private, or public cloud—through the OutSystems Private Gateway.
Be ready for anything with failover across multiple availability zones (AZs).

Unparalleled platform and network security
You don’t have to tackle cyber threats alone. With an enterprise-grade platform and network security right out of the box, you can let OutSystems handle a lot of the risky stuff.
Employ best-in-class protection from SQL injection and XSS with an industry-leading web application firewall.
Prevent DDoS attacks with a Content Delivery Network (CDN) and by pairing your own web application firewall with the OutSystems WAF.
Benefit from continuous automated intrusion detection, malware scanning, and runtime integrity monitoring for detection and prevention of unexpected activity and potential threats.
Security for your mission-critical applications
All of your apps deserve security that’s strong enough for your mission-critical applications. With OutSystems, you never get anything less.
Avoid misconfigurations that lead to vulnerabilities with an intuitive, visual IDE and automated SDLC.
Take charge of your OutSystems applications and network traffic with the power to selectively allow or block user access based on IP address.
Minimize risks with isolated production, development, and QA runtimes.

The fortress you need to prevent insecure data practices
We know that your data is one of your most valuable assets. That's why OutSystems gives you the layer of protection you need to prevent deliberate or unintentional data loss, data breaches, and unauthorized data use.
Avoid data loss with continuous incremental data backup that allows quick restoration.
Reduce the risk of human errors or insider threats with a dedicated database for each development stage.
Employ superior data protection with encryption in transit and at rest along with out-of-the-box cryptographic tools.

Access control without limitations
Prevent shadow IT—or worse—by maintaining full control over who can build apps, who can access them, and how they can be used.
Leave no backdoors for bad actors with flexible, self-managed identity and access management customized to align with your governance model and access management strategy.
Use the least-privilege principle to maintain the strictest possible authorizations and authentication standards.
Choose between utilizing a built-in identity provider or seamlessly integrating your preferred identity providers (BYOP).

Certified to global and national compliance standards
Our rigorous compliance program ensures the platform meets rigorous international, national, industry and governmental mandates for infrastructure integrity, data protection, and regulatory readiness.
Build with confidence on a vetted security foundation powered by a platform that is FedRAMP Authorized and certified for national standards including ENS (Spain), ACN (Italy), and DESC (UAE).
Maintain continuous compliance with evolving EU and global regulations, including GDPR, the EU Data Act, the EU AI Act, and other privacy and industry mandates such as HIPAA and PCI DSS.

Security FAQ
OutSystems platforms comply with HIPAA, PCI DSS, and FedRAMP requirements and hold certifications including SOC 2 Type II and multiple ISO standards. Built-in security and governance controls help customers build compliant applications out of the box. OutSystems also complies with privacy laws such as GDPR. See the OutSystems Trust Center for current details.
OutSystems can support HIPAA-regulated use cases for healthcare organizations and teams handling protected health information. Depending on the deployment model and customer requirements, OutSystems can support Business Associate Agreements and security controls for access, encryption, monitoring, and governance. Customers should confirm scope, responsibilities, and configuration requirements during compliance review.
OutSystems supports government and public sector use cases. The OutSystems platform is also FedRAMP-Moderate Authorized in a partnership with Knox.
OutSystems supports enterprise authentication methods, including SAML, OAuth, SSO, Microsoft Entra ID, formerly Azure AD, and multi-factor authentication via supported identity providers. The platform also includes accelerators for social/B2C logins (Facebook, Google, LinkedIn, Apple). This allows organizations to centralize access control, align applications with existing identity standards, and enforce consistent login and security policies on the platform and across applications.
OutSystems supports centralized user provisioning, role-based access control, and permission management across applications. Teams can define roles, assign access by user or group, and manage permissions as their application portfolio grows. OutSystems also allows customers to extend the built-in capabilities via user and access management REST APIs. This helps enforce least-privilege access, simplify administration, address specific provisioning and role management scenarios, and maintain governance across multiple applications and teams.
OutSystems encrypts data at rest by default and protects data in transit with TLS. Depending on the platform and deployment model, physical and logical separation and namespace segregation help keep customer data isolated. Included security libraries also support envelope encryption, allowing customers to add a second layer of protection for sensitive data.
Data residency depends on the customer’s selected region. OutSystems can support region-specific hosting requirements so organizations can keep application data in approved geographies. This is especially important for regulated industries with sovereignty, privacy, or country-specific compliance obligations.
OutSystems manages platform and infrastructure patching based on the deployment model. In ODC, one-click patching (1CP) reduces application-owner effort: customers are notified when patches are available, and the platform automatically builds and applies them the next time the application is published.
Yes. Customers can perform penetration testing on OutSystems applications, typically with coordination and approval to ensure testing follows platform policies and does not disrupt shared infrastructure. Security teams can also use third-party scanning tools and internal assessment processes to validate application security, compliance requirements, and production readiness.
During a Vendor Risk Assessment, OutSystems provides security documentation, compliance evidence, architecture details, data protection information, and responses to customer security questionnaires. Procurement, legal, and security teams use this process to evaluate risk, confirm controls, and verify that OutSystems meets organizational requirements before purchase or deployment.
Yes. OutSystems can integrate with security monitoring and observability tools such as Splunk, Dynatrace, New Relic, and SIEM or APM platforms. Teams can stream logs, monitor application behavior, and connect platform events to existing security operations workflows, helping maintain visibility across the broader enterprise monitoring stack.
OutSystems includes built-in monitoring capabilities for application health, errors, performance, access activity, and operational events. Teams can use native logs and dashboards to investigate issues, detect abnormal behavior, and support audits. For deeper observability, OutSystems can also connect with external monitoring, SIEM, or APM tools.
OutSystems helps protect sensitive data in AI use cases through agent guardrails, access controls, governed model connections, data boundaries, auditability, and configuration options that limit what information agents or AI features can use. Customers should define approved models, data handling rules, and review workflows to reduce leakage risk.
OutSystems supports AI security guardrails such as role-based access, governed tool access, monitoring, audit logs, and controls that help reduce risks like prompt injection, PII exposure, and unsafe outputs. Agent Evaluations also let teams test agent behavior against defined datasets and criteria, helping validate that agents perform as expected before and after deployment.
AI processing location depends on the selected model, provider, and deployment architecture. OutSystems can support governance patterns that help customers choose approved models, route requests through controlled endpoints, and align processing with regional or data sovereignty requirements. Teams with strict constraints should validate provider, hosting, and data residency options early.

