Compliance frameworks, security audits, and quality certifications this company maintains.
Automattic's WordPress.com, WooCommerce Payments, and Jetpack cloud services undergo SOC 2 Type II audits, providing enterprise customers with independent assurance of security, availability, and confidentiality controls for hosted website infrastructure.
WooCommerce Payments and the WooCommerce.com marketplace maintain PCI DSS Level 1 compliance, enabling merchants to process cardholder payments securely through Automattic's payment infrastructure without independent PCI certification.
Automattic complies with GDPR across WordPress.com, WooCommerce, Jetpack, and Tumblr, providing data processing agreements, EU data residency controls, and GDPR-readiness tools that help WordPress site owners meet their own GDPR obligations.
Automattic complies with the California Consumer Privacy Act for data collected through WordPress.com, WooCommerce, and Jetpack, providing consumers with rights to access, delete, and opt out of sale of their personal data.
Automattic's WordPress.com and WooCommerce infrastructure teams operate under ISO 27001 certified information security management processes, governing how Automattic protects customer website data stored across its global data center network.
WordPress.com and the WordPress block editor comply with WCAG 2.1 AA accessibility standards, ensuring that the 43%+ of websites running on WordPress provide accessible user experiences for visitors with disabilities.
Regulatory
GPLv2 Open Source
CertifiedWordPress core, WooCommerce, and Jetpack are released under GPLv2 open-source license — ensuring that Automattic's commercial software remains freely modifiable and distributable, forming the legal foundation of the WordPress ecosystem's 58,000+ plugin marketplace.
Automattic supports HIPAA-eligible deployments for WordPress.com VIP enterprise customers in healthcare, enabling organizations to use WordPress publishing and content platforms for HIPAA-compliant patient communications and healthcare content workflows.
Automattic holds ISO 27017 cloud service security certification, demonstrating that WordPress.com, WooCommerce, and Tumblr infrastructure follows internationally recognized cloud-specific security controls for protecting customer data across Automattic platforms.
Automattic complies with the Children's Online Privacy Protection Act for WordPress.com and other consumer platforms, enforcing age restrictions and data handling safeguards to protect the privacy of children under 13 who may access Automattic services.