Security at Strapi
Strapi is trusted by the best developers to build, release, and maintain their websites and apps.
Security is a top priority at Strapi and we live it in our day-to-day activities. The flexibility of Strapi enables a range of sensitive and mission-critical use cases. As such, we consider privacy and security to be core functions of our platform, as well as foundational requirements for all new feature development. Earning and keeping the trust of our users is our top priority, so we hold ourselves to the highest privacy and security standards.
How We Secure Our Business
At Strapi, safeguarding customer data isn't just a requirement; it's central to who we are as a company. Our dedicated security experts collaborate with teams across Strapi to proactively identify risks, put best practices in place, and continuously strengthen our security measures.
Security Program
Strapi has established a privacy page and is focused on ensuring the confidentiality, integrity, and availability of your data. We use a variety of network and endpoint security tools to prevent unauthorized access to customer information. Our security policies cover key areas such as access control, risk management, change management, and incident response.
People Security
Strapi is equally committed to maintaining high standards in hiring and staff development. All employees are required to sign and adhere to a code of conduct and an Acceptable Use Policy. Regular performance evaluations ensure that team members are consistently aligned with Strapi's objectives. Any violation of our policies is met with appropriate disciplinary action.
Policies and Procedures
Strapi employs a comprehensive security approach that includes the utilization of a mobile device management (MDM) system to oversee and secure mobile devices connected to our services. We enforce a stringent password policy in line with our internal standards for all system components within our scope. To further bolster our security measures, we mandate the use of two-factor/multi-factor authentication (2FA/MFA) to ensure that access to our systems is protected by an additional layer of verification beyond just passwords. Additionally, we maintain an up-to-date inventory of all assets within our production system.
Security Awareness Training
Strapi is committed to maintaining a robust and traceable Security Awareness program to ensure that our team members fully grasp and adhere to our security guidelines and protocols. This training covers essential topics like information security policies, individual accountability, and specific measures such as password protection. It also outlines the proper channels for escalating any security or privacy concerns.
At Strapi, we've adopted Vanta's comprehensive compliance solution to assist us in achieving our SOC2 certification, a testament to our dedication to security. In addition to Vanta, we've also partnered with Riot Security and integrated their innovative bot "Albert" – the industry's first cybersecurity companion that actively promotes security awareness and offers enhanced protection. By ensuring every member of our team undergoes annual security awareness training and leveraging state-of-the-art tools like Albert, we empower them to detect and alert us to any potential security risks, thereby fortifying our company's security framework for all our users.
Payment Security
Strapi's commitment to ensuring the utmost security for its users is evident in its choice to integrate with Chargebee for payment processing. Chargebee is renowned for its rigorous approach to data integrity and security, acting both as a data controller and processor. Recognizing the critical nature of payment, billing, subscription, and customer data, Chargebee has instilled security as an intrinsic part of its product, processes, and team culture.
For more information, visit Chargebee's security page.
PCI-DSS Certification
Chargebee's security measures are multifaceted. Firstly, it ensures the safety of customers' payment and personal information by adhering to the PCI compliance standard. The PCI-DSS Level 1 Service Provider certification of Chargebee guarantees that sensitive card information is encrypted and managed securely. This is further reinforced by annual audits that protect sensitive data.
ISO, SOC 1 and 2 Certification
Additionally, Chargebee's commitment to internal data security is evident through its adherence to ISO, SOC 1 & SOC 2, and MFA standards. The SOC attestation, which includes both SOC 1 type II and SOC 2 type II reports, assures businesses of Chargebee's robust internal controls over financial reporting. Moreover, the ISO 27001:2013 certification of Chargebee signifies a comprehensive framework of policies and procedures dedicated to information risk management.
GDPR and HIPAA Compliance
Chargebee also prioritizes network security, implementing stringent network, application, and operational level security policies. Furthermore, its dedication to global data protection standards is showcased by its GDPR commitment, ensuring the protection of personal data and aligning with global privacy goals. Chargebee's HIPAA compliance further emphasizes its capability to handle sensitive healthcare data with utmost care.
How We Protect Your Content
Endpoint Security
Strapi ensures that client data is not stored on any of our company workstations, laptops, or removable media. Data is solely housed in our production environment, which is rigorously controlled. Our device management framework keeps a close eye on company hardware through every stage of its lifecycle. This includes checking all workstations for antivirus and anti-malware software that is regularly updated via Vanta’s agent.
Data Management and Storage
Backups, Data Retention and Disposal
We maintain backups and revision histories based on the client's chosen plan. Once data is permanently deleted, it cannot be recovered unless required by law.
Access Control
Strapi Cloud is hosted on DigitalOcean and utilizes DigitalOcean’s Identity and Access Management (IAM) capabilities. This allows us to effectively manage who has access to our production environment. Access permissions are guided by the principles of "least privilege" and "separation of duties," and are reviewed on a quarterly basis.
In Strapi's security architecture, JSON Web Tokens (JWT) with default HS256 cryptography are employed for session IDs. This choice means that there aren't typical session ID changes; however, whenever a user logs out, a new JWT token is generated. As for session duration, if a user selects the "remember me" option, the JWT token remains valid for 30 days. If not, its validity lasts only as long as the session remains open. This approach is crucial for understanding access control within Strapi.
Encryption
We employ robust encryption measures to safeguard client data. This includes managing the creation, storage, retrieval, and destruction of sensitive information like encryption keys and service account credentials.
Self-Hosted
Strapi doesn't directly store any data. Instead, data within a Strapi instance is kept in the user-connected database. Aspects like Data Loss Prevention, encryption (both at rest and during transfer), and recovery are managed by the database provider.
Strapi doesn't automatically encrypt data entered through its dashboard. However, when transferring data using Strapi’s Data Transfer System, you can add an encryption key using OpenSSL. Users need to create this key themselves during the export, as it's not done automatically. For more details, you can check out the provided information.
Cloud
The Strapi Cloud database server and backups are encrypted at rest using AES-256 algorithm (encryption key stored on AWS KMS).
Only social connects are available on the platform so no password hashes are stored.
Custom environment variables of hosted projects are encrypted using the AES-256 algorithm (encryption key stored on a self-hosted Hashicorp Vault server, a per project salt is used).
How We Keep Our Code Secure
Strapi incorporates various protection mechanisms at the application level. We utilize libraries or middleware such as Koa Helmet to set security-related HTTP headers and bolster app-level protection. Additionally, Strapi is committed to regular updates; new versions are announced both in the terminal and the admin panel. Typically, feature additions are introduced monthly, with occasional minor bug fixes in between.
Open Source
Open-source software, like Strapi, has a security edge because its code is out there for everyone to see and improve. When many eyes from the global developer community are on the code, it's easier to spot and fix potential issues. This makes open-source projects often more secure than their closed-source counterparts. Strapi is fully open-source, which means it benefits from this wide-scale review and collaboration, ensuring users get a reliable and safe platform.
Secure Coding Practices
Strapi’s security hardening steps are rooted in standard Linux guidelines, ensuring a robust foundation. Furthermore, we're deeply committed to adhering to industry standards, and as such, our development and review processes are in line with the OWASP Top 10 recommendations.
Secure Software Development Life Cycle (SDLC)
By embracing a "security by design" approach, security is integrated within our product's core, ensuring both current and future features are vulnerability-free.
Developers take full responsibility for their code, ensuring consistent high-quality and secure outputs. Strapi is fostering a culture of responsibility that consistently upholds superior code quality and robust security.
Strapi adheres to a standard Git workflow, ensuring a consistent and structured approach to code versioning, collaboration, and deployment. This workflow allows the team to effectively track changes, collaborate seamlessly, and manage releases, ensuring the integrity and reliability of the platform.
Code Peer Review
At Strapi, we use GitHub's pull request feature for our code reviews. When our developers add new code, they create a pull request for the team to review and give feedback. This approach lets us discuss and fix any issues before finalizing the changes. We're committed to maintaining high code quality, and this process ensures every update meets our standards.
Automatic Static Code Analysis
To catch security issues, Strapi uses tools like Snyk and DependaBot from GitHub. These tools help spot vulnerabilities in our dependencies. Plus, we've got CodeFactor on our side for analyzing the quality of the code, making sure it's not just secure but also well-written.
Quality Assurance (QA)
Strapi’s got a dedicated team that uses a tool called Squash TM for manual testing and setting the groundwork for automating tests on Strapi's features. Additionally, quality assurance takes place in a separate environment, distinct from production, to ensure full isolation. And before we roll out any release, our QA team gives it a green (Go) or red (NoGo) light, ensuring everything's up to the mark and secure for our users.
Vulnerability Management
Strapi follows a rigorous vulnerability process to handle reported security issues, in addition to managing all vulnerabilities internally using a dedicated vulnerability management tool. Upon detection, vulnerabilities are scored using the Common Vulnerability Scoring System (CVSS) system and assigned an owner. These reported vulnerabilities, especially those via GitHub's Advisory system, undergo initial tracking, communication, and internal validation. Critical issues activate a "Crisis process." A patch is developed, validated both internally and by the original reporter, and then a Common Vulnerability Exposure (CVE) request is made. The disclosure process entails notifying Strapi Enterprise customers first, followed by a comprehensive public disclosure after a 2-4 week waiting period post-patch release. For all vulnerabilities, there's an internal SLA determining resolution deadlines. Progress is meticulously tracked using tools, and post-mortems might be organized as learning opportunities to enhance code security.
Penetration Tests
To ensure robust security, Strapi doesn't rely on a dedicated third-party firm for formal penetration tests. Instead, we benefit from our vast and highly knowledgeable open-source community, where cyber-analysts frequently conduct tests. Although we don't have a contract with a preferred company for this, any vulnerabilities identified are evaluated using the CVSS and are publicly shared through CVE. Our response and remediation strategies are based on the severity and risk rating of these findings.
Software Dependencies
Strapi's CLI uses NPM or Yarn to download its source files and their dependencies, both of which have integrated integrity checks during installation. While additional manual processes can be aligned with NPM guidelines, Strapi actively updates its direct dependencies to address any known issues. The team remains cautious of breaking changes, especially from nested dependencies beyond their direct control. Instead of solely relying on NPM Audit or Yarn Audit, which offer compounded risk assessments, Strapi's Security Team prioritizes updating dependencies with significant potential impact on Strapi. Emphasizing security, the team values CVEs, which provide detailed vulnerability information, though it's noted that not all NPM/Yarn packages have specific CVE assignments.
Plugin Security
The security of Strapi plugins is paramount; they must not contain malicious content or cause harm. Guidelines specify that plugins should not collect Strapi secrets, must handle credential storage appropriately, should be protected against common web vulnerabilities, should not expose sensitive APIs, and their dependencies should be up-to-date without known vulnerabilities. Please see the plugin guidelines for more details
Single Sign-On (SSO) and Two-Factor Authentication (2FA)
Strapi's Enterprise Edition features a Single Sign-On (SSO) capability, supporting any method backed by PassportJS. This versatile SSO simplifies user access, letting users authenticate once for multiple applications. The feature's adaptability allows businesses to connect a range of third-party authentication systems, enhancing user experience and bolstering security.
Regarding Two-Factor Authentication (2FA), it's managed by the SSO provider in Strapi's Enterprise Edition, ensuring an added layer of security. However, it's worth noting that the Users and Permissions plugin in Strapi does not currently offer 2FA functionality.
Audit Logs
Strapi's Enterprise Edition provides a feature known as Audit Logs, which records user and administrative actions. These logs specifically track activities related to content and dashboard items, excluding network items. The events logged include actions like creating, updating, and deleting for content types such as entry (draft/publish), media, login/logout processes, roles/permissions, and users. These logs are retained for 90 days in the connected database, though this duration can be adjusted by discussing with a Customer Success Manager. As for accessing these logs, they are available through the Strapi dashboard or directly in the database, and dashboard access can be restricted using RBAC. However, Strapi currently lacks the functionalities to export these logs or send notifications based on them.
Roles and Permissions
Strapi fully supports Role Based Access Control (RBAC), allowing admin users to create diverse roles with specific access to different Collection or Single Types, even down to individual field types. Moreover, this RBAC system can be tailored with custom conditions. However, while roles and their permissions are managed exclusively within the Strapi dashboard, there's a useful "default role" feature in Strapi's SSO that assigns a pre-selected role to new users, emphasizing a secure approach of starting with minimal privileges and expanding as necessary. For dynamic administrative needs, Strapi also offers the flexibility of scheduling permission changes through Cron tasks. This capability enables the automatic granting or removal of specific permissions based on various triggers or events.
How to Report Vulnerabilities
Strapi adheres to a well-defined Incident Response Plan that outlines the protocols for initiating response actions, elevating issues, collaborating with external experts, conducting investigations, analyzing the situation, implementing corrective measures, restoring services, and reviewing lessons learned. Our dedicated Information Security team actively works to identify and patch vulnerabilities and gives utmost importance to any reported security concerns.
Business Continuity and Disaster Recovery
Strapi has instituted a comprehensive Business Continuity and Disaster Recovery Plan, which lays out high-level strategies for re-establishing crucial business operations. This includes protocols for communication among core team members and action plans for data and service restoration.
Whenever there are indications of potential vulnerabilities, such reports are promptly channeled to our dedicated Security Team at Strapi. We maintain a Incident Response Team equipped with a structured notification system which is committed to addressing these concerns with urgency.
If our in-depth analysis confirms a security discrepancy, Strapi's robust crisis management protocol is set into motion. This protocol is characterized by precise role designations to adeptly trained team members, guaranteeing rapid and coordinated interventions. A carefully crafted escalation methodology, anchored in a criticality matrix, ensures our reactions are proportionate to the situation's severity. Alongside, a systematic communication blueprint is executed, ensuring all our partners, stakeholders, and users are kept informed and reassured.
Post-identification, our priority shifts to rectification. Strapi is dedicated to swiftly deploying a solution, and while the exact time frame can depend on the issue's intricacies, our history reflects resolutions typically achieved within days. We annually test and update these plans to ensure their effectiveness.
Strapi's Business Continuity and Disaster Recovery plans, along with our procedures and processes, are on its way to being routinely audited and Strapi is actively working towards being certified under SOC 2 Type 2 and ISO 27001 standards, affirming our commitment to compliance and security.
How to Report Vulnerabilities
Please report (suspected) security vulnerabilities via GitHub's security advisory reporting system: Submit your vulnerability via this link.
Please note the following requirements (all are required):
- Summary of the suspected vulnerability
- Detailed information as to what the suspected vulnerability does and what it has access to
- Proof of Concept (Code samples at minimum, reproduction video optional)
- POC must include how the vulnerability can actually access sensitive data, simply triggering an alert popup in a browser is not a security vulnerability
- Impact summary (who does this impact and how)
Optionally you may also add your estimated CVSS 3.1 score, though we may adjust. There is no need to submit a CVE request as we will do that as part of the advisory process.
You will receive a response from us within 72 hours. If the issue is confirmed, we will release a patch as soon as possible depending on complexity but historically within a few days.
Please note that we follow a very strict internal and public disclosure policy, typically a patch will be issued and included in a release. We then will place a warning that a security vulnerability has been patched and delay detailed disclosure from 2 to 8 weeks depending on the severity of the issue. If you have any resources such as blog posts that you intend to publish on and would like us to include these in our disclosure please advise us ASAP.
Before doing any public disclosure we do ask that you speak to us first to ensure we are not releasing too much information before a patch is available and time has been given to users to upgrade their projects.
Security at Strapi
Want to know more about our security measures? Chat with one of our engineers to understand your security needs and find out how Strapi can fit into your application.