Instances
Agility's Microsoft Azure hosting platform, encryption standards (TLS 1.2/1.3 in transit, AES-256 at rest), key management, certifications, and the shared-responsibility model.
Agility CMS is a SaaS platform hosted on Microsoft Azure, using Azure's globally compliant infrastructure as its backbone. Content data is encrypted in transit (TLS) and at rest (AES-256), with cryptographic keys held in a secure managed key-management service. Agility maintains SOC 2 Type II compliance, and the underlying Azure platform carries broad certifications including ISO 27001, ISO 27018, and CSA STAR. Security is delivered under a shared-responsibility model: Agility secures the platform, infrastructure, and content APIs, while the implementation partner and customer secure their own front-end application, deployment pipeline, secrets, and end-user access.
Agility runs on Microsoft Azure, which provides the compute, storage, and network backbone for content storage, media/asset delivery, and key management. Instances are provisioned into one of five regions (see Data Residency & Data Regions). Building on Azure means Agility inherits Azure's physical security, network controls, and the broadest cloud-compliance coverage in the industry.
| Layer | Standard | Notes |
|---|---|---|
| In transit | TLS 1.2 minimum (1.3 supported) | All API and management traffic served over HTTPS/TLS; TLS 1.2 is the enforced minimum. |
| At rest | AES-256 | Provided by the Azure platform; all stored data is encrypted by default. |
| Secrets & keys | Managed key-management service | Keys and secrets handled by a secure managed store; industry-standard hashing for credentials. |
Cryptographic keys and application secrets are held in a secure, managed key-management service on Azure. At-rest encryption keys are managed within the Azure platform. Customer-managed keys (BYOK) are not available at this time.
This distinction matters in an RFP: SOC 2 Type II is Agility's own attestation, while the wider ISO/CSA certifications are Azure platform certifications that Agility builds on.
Agility operates a formal information-security program. A governing Information Security Policy sits over a comprehensive set of supporting policies covering the standard control domains expected of an enterprise vendor, including:
In practice this means Agility enforces multi-factor authentication (MFA) for administrative and remote access to its systems, maintains a defined security-incident reporting and response process, classifies and protects data according to its sensitivity, builds security into its development lifecycle, and reviews its policies and verifies compliance through periodic internal and external audits. Detailed control specifics are confidential and shared under NDA as part of a security review rather than published.
The substance of individual policies and control implementations is confidential; for a security questionnaire or to review specifics under NDA, contact Agility.
Agility supports enterprise authentication and role-based access:
Security follows a cloud shared-responsibility split. Agility (with Azure beneath it) secures the platform; the implementation partner and customer secure what they build and operate on top.
| Layer | Agility (and Azure) | Implementation partner / customer |
|---|---|---|
| Physical & network infrastructure | ✅ Azure data centres, network controls | — |
| Platform & content APIs | ✅ Patching, hardening, encryption at rest/in transit, key vault | — |
| Platform certifications (SOC 2, etc.) | ✅ Maintains Agility attestation | Reviews reports; maps to its own compliance program |
| API keys & secrets | ✅ Issues keys; secure storage server-side | ✅ Stores Fetch/Preview/Management keys securely; never exposes Management/Preview keys client-side; rotates on staff change |
| Front-end application & hosting | — | ✅ Secures the website/app, its hosting, headers, and its own CDN |
| User & role administration | ✅ Provides RBAC, SSO, workflows | ✅ Configures roles/least-privilege, manages joiners/movers/leavers, enforces MFA at the IdP |
| Custom code / integrations | ✅ Provides APIs/SDKs/webhooks | ✅ Secures custom scripts, webhook endpoints, and integration credentials |