How your trust story reads from the public web
vs. Netlify, Render, Fly.io
One in a series benchmarking how funded B2B SaaS companies present trust to enterprise buyers. Everything below is publicly observable — the same view an enterprise buyer's procurement and InfoSec reviewers get. This is not a security assessment; it says nothing about Vercel's actual security.
This edition documents a ceiling rather than a gap; Vercel was not asked and is not being pitched.
The short version
Vercel is the most findable trust story this series has benchmarked — 16 of 20 questionnaire topics publicly answerable, a public DPA, three years of SOC 2 reports behind a self-serve gate, Security and Trust Center both footer links. The one seam: vercel.com/security still reads "Vercel is ISO 27001:2013 certified" while the docs and the linked public certificate say ISO 27001:2022.
Before a questionnaire is ever sent, a reviewer does a public first pass. Replaying it for Vercel, on 2026-09-02:
At this point the reviewer has formed a first impression of Vercel as a vendor — before anyone at Vercel knows the review has started. Unusually, it is nearly complete.
All cells observed 2026-09-02, public web only. Published / Partial / Not found = what a logged-out visitor can reach; it says nothing about what exists internally.
| Observable artifact | Vercel | Netlify | Render | Fly.io |
|---|---|---|---|---|
| Public trust/security page | Publishedvercel.com/security, footer-linked, plus the trust center at security.vercel.com | Publishednetlify.com/security plus a trust center at trust.netlify.com | Publishedrender.com/security, footer-linked, with subprocessors on-page | Publishedfly.io/security |
| SOC 2 visibility & report path | PublishedType 2 attestation stated on site and docs; reports for 2024–2026 behind a self-serve request gate (security.vercel.com) | Published"AICPA SOC 2 Type 2" stated; reports via the trust center's request-access flow (netlify.com/security) | PartialType 2 stated; "SOC 2 & ISO documentation" is a plan-table feature served in-dashboard, absent on lower tiers (render.com/security, render.com/pricing) | Partial"SOC 2 Type 2" stated on fly.io/security; reports via the $99/month Compliance plan or a signed-in documents page (fly.io/pricing, fly.io/documents) |
| Security answers available publicly | topics (vercel.com/security, /docs/security/compliance, /pricing, /legal/dpa, security.vercel.com) | topics (netlify.com/security, /pricing, /gdpr-ccpa, trust.netlify.com, docs.netlify.com) | topics (render.com/security, /pricing, /dpa, render.com/docs) | topics (fly.io/security, /pricing, /legal/sub-processors, fly.io/docs) |
| Subprocessor list & DPA | Publishedsubprocessors public on the trust center; full DPA text at vercel.com/legal/dpa, updated 2026-03-17 | Publishedsubprocessors named on the trust center; DPA downloadable from netlify.com/gdpr-ccpa | Publishedsubprocessors listed on render.com/security; DPA at render.com/dpa, also a pricing-table row | Partial29 sub-processors at fly.io/legal/sub-processors; DPA pre-signed but issued on request via sign-in (fly.io/documents) |
| Enterprise signals on pricing page | PublishedSAML SSO, audit logs, Directory Sync/SCIM, platform SLAs, HIPAA BAA, SOC 2 Type 2, ISO 27001 as plan rows (vercel.com/pricing) | Partial"SSO & SCIM" and a 99.99% SLA on Enterprise; no compliance rows (netlify.com/pricing) | PublishedSAML SSO, SCIM, audit logs, GDPR DPA, SOC 2 Type II, ISO 27001, HIPAA BAA, support response SLAs as plan rows (render.com/pricing) | Publisheda $99/month Compliance plan "from BAAs to SOC2s", SSO authentication, enterprise SLA arrangements (fly.io/pricing) |
| Column summary | 4/4 published · 16/20 topics | 3/4 published · 9/20 topics | 3/4 published · 10/20 topics | 2/4 published · 10/20 topics |
Vercel is the only company here with no Partial row and leads publicly answerable topics by six; the peers cluster within a point, with the closest race on the pricing page, where Render's plan table nearly matches Vercel's.
Exhibit
ISO 27001:2013 · stated on the security page
Compliance
“Vercel is ISO 27001:2013 certified”
The docs page reads ISO 27001:2022 and links the public certificate — one surface trailing its own program.
Recreated from vercel.com/security as observed 2026-09-02. The 27001:2022 certificate is public in Schellman's directory; the security page still names the 2013 standard.
Nothing in this section needs a citation; it is the mechanics of the review itself. Every topic a reviewer can't answer from the public web becomes a questionnaire question: sent by email, routed to whoever holds the answer, written up, sent back, read. Each round-trip adds days, and the days accumulate while the deal sits in review. On today's table, Vercel starts with 16/20 topics answerable self-serve; Render starts at 10/20 — the difference is round-trips.
Topic-by-topic (public web only):
Publicly answered (16): encryption at rest — AES-256 — and in transit — HTTPS/TLS 1.3 (vercel.com/docs/security/compliance); SSO/SAML — $300/month on Pro, included on Enterprise (vercel.com/pricing); uptime SLA — platform SLAs on Enterprise (pricing); data residency — "Where does my data live?": customer-selected regions, U.S. default (docs); backups — every two hours, kept 30 days, globally replicated (vercel.com/security); subprocessor list — public on the trust center; DPA — full text at vercel.com/legal/dpa, updated 2026-03-17; pentest cadence — annual third-party tests plus ongoing assessments (vercel.com/security); access control — role-based, team and project level (pricing); vulnerability management — posture scanning, static analysis, dependency scanning (vercel.com/security); BCP/DR — failover strategy, recurring resiliency testing (docs); change management — change control via infrastructure as code (docs); logging/monitoring — audit logs on Enterprise (pricing); physical/hosting security — AWS across 20 regions (docs); compliance report access path — self-serve request gate at security.vercel.com.
Not publicly answerable (4): incident response process, employee security training, vendor risk management, data retention/deletion specifics — each a titled policy behind the trust center's request gate; a title behind a gate counts as not answerable.
Reads well: most of it — which is why this edition exists. Security and Trust Center are footer links; the docs page is current and links the public ISO 27001:2022 certificate; the DPA and subprocessor list are public; the pricing table carries compliance rows on every tier; the HIPAA BAA is self-serve on Pro; TISAX Assessment Level 2 is stated with its scope; and the April 2026 bulletin is an owned, dated disclosure.
Which topics counted toward each company's publicly answerable score in the table above.