Platform Overview
Security & Compliance

The agentic systems platform for
Enterprise-grade security and compliance

With modern, end-to-end security woven into every aspect of the platform and its applications, OutSystems is the agentic systems platform for out-of-the-box peace of mind.

security-and-compliance-hero

Enterprise-grade, high security—built in

Cutting corners on app security is for the other AI platforms. OutSystems gives you enterprise-grade protection that aims to exceed standards, not just meet them.

bullet-point-grey-icon

Eliminate manual effort and improve user experience with automatic security patching and no downtime.

bullet-point-grey-icon

Build secure mobile apps by unifying CI/CD tools with app shielding features.

bullet-point-grey-icon

Easily and securely connect applications with your infrastructure—on-premises, in private, or public cloud—through the OutSystems Private Gateway.

bullet-point-grey-icon

Be ready for anything with failover across multiple availability zones (AZs).

screen requests log monitoring

Unparalleled platform and network security

You don’t have to tackle cyber threats alone. With an enterprise-grade platform and network security right out of the box, you can let OutSystems handle a lot of the risky stuff.

bullet-point-grey-icon

Employ best-in-class protection from SQL injection and XSS with an industry-leading web application firewall.

bullet-point-grey-icon

Prevent DDoS attacks with a Content Delivery Network (CDN) and by pairing your own web application firewall with the OutSystems WAF.

bullet-point-grey-icon

Benefit from continuous automated intrusion detection, malware scanning, and runtime integrity monitoring for detection and prevention of unexpected activity and potential threats.

outsystems developer cloud platform security

Security for your mission-critical applications

All of your apps deserve security that’s strong enough for your mission-critical applications. With OutSystems, you never get anything less.

bullet-point-grey-icon

Avoid misconfigurations that lead to vulnerabilities with an intuitive, visual IDE and automated SDLC.

bullet-point-grey-icon

Take charge of your OutSystems applications and network traffic with the power to selectively allow or block user access based on IP address.

bullet-point-grey-icon

Minimize risks with isolated production, development, and QA runtimes.

outsystems developer cloud ip filters

The fortress you need to prevent insecure data practices

We know that your data is one of your most valuable assets. That's why OutSystems gives you the layer of protection you need to prevent deliberate or unintentional data loss, data breaches, and unauthorized data use.

bullet-point-grey-icon

Avoid data loss with continuous incremental data backup that allows quick restoration.

bullet-point-grey-icon

Reduce the risk of human errors or insider threats with a dedicated database for each development stage.

bullet-point-grey-icon

Employ superior data protection with encryption in transit and at rest along with out-of-the-box cryptographic tools.

private gateways for data security

Access control without limitations

Prevent shadow IT—or worse—by maintaining full control over who can build apps, who can access them, and how they can be used.

bullet-point-grey-icon

Leave no backdoors for bad actors with flexible, self-managed identity and access management customized to align with your governance model and access management strategy.

bullet-point-grey-icon

Use the least-privilege principle to maintain the strictest possible authorizations and authentication standards.

bullet-point-grey-icon

Choose between utilizing a built-in identity provider or seamlessly integrating your preferred identity providers (BYOP).

platform access control

Certified to global and national compliance standards

Our rigorous compliance program ensures the platform meets rigorous international, national, industry and governmental mandates for infrastructure integrity, data protection, and regulatory readiness.

bullet-point-grey-icon

Build with confidence on a vetted security foundation powered by a platform that is FedRAMP Authorized and certified for national standards including ENS (Spain), ACN (Italy), and DESC (UAE).

bullet-point-grey-icon
bullet-point-grey-icon

Maintain continuous compliance with evolving EU and global regulations, including GDPR, the EU Data Act, the EU AI Act, and other privacy and industry mandates such as HIPAA and PCI DSS.

compliance logos

Security FAQ

What compliance certifications does OutSystems have?

OutSystems platforms comply with HIPAA, PCI DSS, and FedRAMP requirements and hold certifications including SOC 2 Type II and multiple ISO standards. Built-in security and governance controls help customers build compliant applications out of the box. OutSystems also complies with privacy laws such as GDPR. See the OutSystems Trust Center for current details.

Is OutSystems HIPAA compliant?

OutSystems can support HIPAA-regulated use cases for healthcare organizations and teams handling protected health information. Depending on the deployment model and customer requirements, OutSystems can support Business Associate Agreements and security controls for access, encryption, monitoring, and governance. Customers should confirm scope, responsibilities, and configuration requirements during compliance review.

Does OutSystems have FedRAMP authorization?

OutSystems supports government and public sector use cases. The OutSystems platform is also FedRAMP-Moderate Authorized in a partnership with Knox.

What authentication methods does OutSystems support?

OutSystems supports enterprise authentication methods, including SAML, OAuth, SSO, Microsoft Entra ID, formerly Azure AD, and multi-factor authentication via supported identity providers. The platform also includes accelerators for social/B2C logins (Facebook, Google, LinkedIn, Apple). This allows organizations to centralize access control, align applications with existing identity standards, and enforce consistent login and security policies on the platform and across applications.

How does OutSystems handle user provisioning and role management across multiple applications?

OutSystems supports centralized user provisioning, role-based access control, and permission management across applications. Teams can define roles, assign access by user or group, and manage permissions as their application portfolio grows. OutSystems also allows customers to extend the built-in capabilities via user and access management REST APIs. This helps enforce least-privilege access, simplify administration, address specific provisioning and role management scenarios, and maintain governance across multiple applications and teams.

How does OutSystems handle data encryption?

OutSystems encrypts data at rest by default and protects data in transit with TLS. Depending on the platform and deployment model, physical and logical separation and namespace segregation help keep customer data isolated. Included security libraries also support envelope encryption, allowing customers to add a second layer of protection for sensitive data.

In what region/data center is the data stored?

Data residency depends on the customer’s selected region. OutSystems can support region-specific hosting requirements so organizations can keep application data in approved geographies. This is especially important for regulated industries with sovereignty, privacy, or country-specific compliance obligations.

How does OutSystems handle vulnerability patching and security updates?

OutSystems manages platform and infrastructure patching based on the deployment model. In ODC, one-click patching (1CP) reduces application-owner effort: customers are notified when patches are available, and the platform automatically builds and applies them the next time the application is published.

Can we perform penetration testing on our OutSystems applications?

Yes. Customers can perform penetration testing on OutSystems applications, typically with coordination and approval to ensure testing follows platform policies and does not disrupt shared infrastructure. Security teams can also use third-party scanning tools and internal assessment processes to validate application security, compliance requirements, and production readiness.

What happens during a Vendor Risk Assessment (VRA)?

During a Vendor Risk Assessment, OutSystems provides security documentation, compliance evidence, architecture details, data protection information, and responses to customer security questionnaires. Procurement, legal, and security teams use this process to evaluate risk, confirm controls, and verify that OutSystems meets organizational requirements before purchase or deployment.

Can OutSystems integrate with our security monitoring tools?

Yes. OutSystems can integrate with security monitoring and observability tools such as Splunk, Dynatrace, New Relic, and SIEM or APM platforms. Teams can stream logs, monitor application behavior, and connect platform events to existing security operations workflows, helping maintain visibility across the broader enterprise monitoring stack.

What security monitoring capabilities are built into the platform?

OutSystems includes built-in monitoring capabilities for application health, errors, performance, access activity, and operational events. Teams can use native logs and dashboards to investigate issues, detect abnormal behavior, and support audits. For deeper observability, OutSystems can also connect with external monitoring, SIEM, or APM tools.

How does OutSystems ensure AI models don't expose sensitive data?

OutSystems helps protect sensitive data in AI use cases through agent guardrails, access controls, governed model connections, data boundaries, auditability, and configuration options that limit what information agents or AI features can use. Customers should define approved models, data handling rules, and review workflows to reduce leakage risk.

What AI security guardrails does OutSystems provide?

OutSystems supports AI security guardrails such as role-based access, governed tool access, monitoring, audit logs, and controls that help reduce risks like prompt injection, PII exposure, and unsafe outputs. Agent Evaluations also let teams test agent behavior against defined datasets and criteria, helping validate that agents perform as expected before and after deployment.

Can we keep AI processing within our own data centers or specific regions?

AI processing location depends on the selected model, provider, and deployment architecture. OutSystems can support governance patterns that help customers choose approved models, route requests through controlled endpoints, and align processing with regional or data sovereignty requirements. Teams with strict constraints should validate provider, hosting, and data residency options early.

See how OutSystems can work for you