Compliance frameworks, security audits, and quality certifications this company maintains.
Fastly maintains SOC 2 Type II certification across its edge cloud platform, providing enterprise customers with independent assurance that security, availability, and confidentiality controls meet the trust service criteria for CDN, WAF, and compute services.
Fastly holds ISO 27001 certification for its information security management system, covering the global edge network infrastructure that processes enterprise customer traffic across 90+ points of presence.
Fastly is PCI DSS Level 1 certified as a service provider, enabling e-commerce customers like Shopify to route payment page traffic through Fastly CDN and WAF while maintaining their own PCI compliance obligations.
Fastly is GDPR compliant with data processing agreements, EU-based edge nodes for data residency, and privacy controls that enable European enterprise customers to route user traffic through Fastly without violating EU data transfer regulations.
Fastly supports HIPAA-eligible workloads for healthcare customers by signing Business Associate Agreements and providing audit logging, access controls, and encryption for protected health information transmitted through the Fastly edge network.
Fastly holds FedRAMP Moderate authorization, enabling U.S. federal agencies to use Fastly CDN and edge services for government websites and applications requiring FedRAMP-compliant content delivery infrastructure.
Fastly maintains CSA STAR Level 2 certification for its cloud security posture, demonstrating third-party validated security controls for the edge cloud platform that enterprise security teams require before routing sensitive API traffic through Fastly.
Fastly is ISO 27017 certified for cloud service information security controls, providing enterprise customers with assurance that Fastly's shared responsibility model for edge infrastructure meets internationally recognized cloud security standards.
Fastly is CCPA compliant, supporting California-resident data rights by providing data deletion, opt-out, and privacy request workflows for California-based users whose traffic is processed through Fastly's edge network on behalf of enterprise customers.
Fastly uses FIPS 140-2 validated cryptographic modules for TLS encryption across its edge network, meeting the federal cryptography standards required by U.S. government agencies that route sensitive workloads through Fastly CDN under FedRAMP authorization.