ISO 27001

GDPR Ready

99.9% uptime

Build secure, reliable websites every time

Every website built using Duda is backed by enterprise-grade security and industry-leading reliability, so you can worry less about your infrastructure and focus more on delivering great websites.

Secure from the start

Rock-solid infrastructure

Build sites that can weather any storm with 99.9% uptime, advanced cybersecurity practices, and automatic backups.

Secure development

With Duda, security starts at development. Code is written in a way that minimizes risk and is repeatedly tested for vulnerabilities.

Protected data

Your data, and your customers’ data, is carefully protected by multiple engineering and information security safeguards.

Websites built using Duda boast advanced cybersecurity practices, automatic data protections, and ultra-reliable hosting—all of which come together to form a strong foundation.

Rock-solid infrastructure

The entire Duda platform, from individual websites to the editor itself, is hosted on Amazon’s dependable AWS platform, the world’s largest server provider, to provide the reliability your clients expect.

Guaranteed 99.9% uptime

Duda websites come with automated DDoS mitigation, SSL certificates, data encryption, and strict access controls out of the box to squash attacks from bad actors—all without you needing to even lift a finger. 

Advanced cyber security

Your data, and your customer’s data, is physically dispersed across multiple cloud-computing zones and automatically backed up to reduce risk while ensuring integrity and easy recovery.

Worry-free data storage


At Duda, a high degree of security and reliability is woven throughout the platform—starting with the very first line of code and continuing throughout the life of the product.


Secure software development

We incorporate industry-leading security practices throughout the entire development process via rigorous information governance and best practice organizational procedures.

Secure software development lifecycle

Through automated scanning, continuous patch deployment, and whitebox/blackbox penetration testing, we constantly monitor for—and mitigate—any vulnerabilities. 

Vulnerability management

All third-party apps are subject to a rigorous quality assurance process to ensure the highest level of performance, quality, and reliability without compromising site security.

Hand-selected integrations

Your data is in good hands

Through a thoughtful system of engineering and organization safeguards, your data, and your customer’s data, is locked down and safe from prying eyes.

Secure information practices

Duda implements a comprehensive and continuously improving information security policy in accordance with ISO 27001 to maintain the highest level data security.



Robust user permissions

Account owners can tailor the level of access each client and teammate has down to the individual feature, so edit access is only available to those who need it.


Password safety built-in

Enforce an added level of security and mitigate phishing and other password-related risks with multi-factor authentication (MFA) and single sign-on (SSO).

Privacy and consent management

All Duda sites come with Privacy and Privacy Settings pages available right out of the box, alongside support for Cookie Notifications and tracking toggles.



GDPR ready

With support for Europe-only hosting in Frankfurt and advanced cookie compliance integrations, Duda lets you build sites that stand up to the strictest privacy regulations.


Delete and destroy

Customer Data is only retained so long as Duda and the partner or customer have an active agreement—after that it’s destroyed.

FAQs

  • How often does Duda go down?

    The Duda professional website builder is highly stable with a 99.9% uptime guarantee. Uptime status is monitored and reported live.

  • Do I need to buy an SSL certificate?

    No. Duda provides, and automatically renews, SSL certificates for every site published at no additional cost.

  • Do I need to get DDoS protection?

    No. Duda provides robust DDoS protection for every site published, and the editor itself, at no additional cost.

  • What data encryption methods does Duda use?

    Duda uses HTTPs and TLS to encrypt data in transit, while data at rest is protected by AES-256 encryption.


Does your organization need additional, or more specific, information regarding Duda’s security practices? Let us know what you need. Technical security information may be available upon request.

Dive into the details