GRANWORTH Benchmarked 2026-09-02 · Public web only
THE GRANWORTH INDEX Enterprise Trust Benchmark · 2026-09-02 edition

How your trust story reads from the public web

Vercel

vs. Netlify, Render, Fly.io

One in a series benchmarking how funded B2B SaaS companies present trust to enterprise buyers. Everything below is publicly observable — the same view an enterprise buyer's procurement and InfoSec reviewers get. This is not a security assessment; it says nothing about Vercel's actual security.

This edition documents a ceiling rather than a gap; Vercel was not asked and is not being pitched.

The short version

Vercel is the most findable trust story this series has benchmarked — 16 of 20 questionnaire topics publicly answerable, a public DPA, three years of SOC 2 reports behind a self-serve gate, Security and Trust Center both footer links. The one seam: vercel.com/security still reads "Vercel is ISO 27001:2013 certified" while the docs and the linked public certificate say ISO 27001:2022.

What an enterprise security reviewer sees in the first 5 minutes

Before a questionnaire is ever sent, a reviewer does a public first pass. Replaying it for Vercel, on 2026-09-02:

  1. Search "Vercel security" / "Vercel trust center": the first results are owned — vercel.com/security, vercel.com/docs/security, and security.vercel.com; page one also carries Vercel's own bulletin on an April 2026 security incident (vercel.com/kb/bulletin/vercel-april-2026-security-incident).
  2. Site footer/nav: Security and Trust Center links, sitewide (vercel.com footer).
  3. Certification path: SOC 2 Type 2 attestation and ISO 27001 stated on site and docs; the docs page (updated 2026-08-26) links the ISO 27001:2022 certificate in Schellman's public directory while vercel.com/security still names ISO 27001:2013; reports behind a self-serve gate at security.vercel.com.
  4. Standard questionnaire topics answerable publicly: 16/20 — encryption at rest and in transit, backups, pentest cadence, and the full DPA text all self-serve; incident response, employee security training, vendor risk management, and data retention/deletion are the 4 not answerable (full list in the appendix).
  5. Pricing page, enterprise tier: SAML SSO, audit logs, Directory Sync/SCIM, platform SLAs, HIPAA BAA, SOC 2 Type 2, and ISO 27001 as plan rows (vercel.com/pricing); the BAA is a self-serve Pro add-on at $350/month.

At this point the reviewer has formed a first impression of Vercel as a vendor — before anyone at Vercel knows the review has started. Unusually, it is nearly complete.

Side by side

All cells observed 2026-09-02, public web only. Published / Partial / Not found = what a logged-out visitor can reach; it says nothing about what exists internally.

Observable trust artifacts, Vercel compared with Netlify, Render, Fly.io
Observable artifact Vercel Netlify Render Fly.io
Public trust/security page Publishedvercel.com/security, footer-linked, plus the trust center at security.vercel.com Publishednetlify.com/security plus a trust center at trust.netlify.com Publishedrender.com/security, footer-linked, with subprocessors on-page Publishedfly.io/security
SOC 2 visibility & report path PublishedType 2 attestation stated on site and docs; reports for 2024–2026 behind a self-serve request gate (security.vercel.com) Published"AICPA SOC 2 Type 2" stated; reports via the trust center's request-access flow (netlify.com/security) PartialType 2 stated; "SOC 2 & ISO documentation" is a plan-table feature served in-dashboard, absent on lower tiers (render.com/security, render.com/pricing) Partial"SOC 2 Type 2" stated on fly.io/security; reports via the $99/month Compliance plan or a signed-in documents page (fly.io/pricing, fly.io/documents)
Security answers available publicly topics (vercel.com/security, /docs/security/compliance, /pricing, /legal/dpa, security.vercel.com) topics (netlify.com/security, /pricing, /gdpr-ccpa, trust.netlify.com, docs.netlify.com) topics (render.com/security, /pricing, /dpa, render.com/docs) topics (fly.io/security, /pricing, /legal/sub-processors, fly.io/docs)
Subprocessor list & DPA Publishedsubprocessors public on the trust center; full DPA text at vercel.com/legal/dpa, updated 2026-03-17 Publishedsubprocessors named on the trust center; DPA downloadable from netlify.com/gdpr-ccpa Publishedsubprocessors listed on render.com/security; DPA at render.com/dpa, also a pricing-table row Partial29 sub-processors at fly.io/legal/sub-processors; DPA pre-signed but issued on request via sign-in (fly.io/documents)
Enterprise signals on pricing page PublishedSAML SSO, audit logs, Directory Sync/SCIM, platform SLAs, HIPAA BAA, SOC 2 Type 2, ISO 27001 as plan rows (vercel.com/pricing) Partial"SSO & SCIM" and a 99.99% SLA on Enterprise; no compliance rows (netlify.com/pricing) PublishedSAML SSO, SCIM, audit logs, GDPR DPA, SOC 2 Type II, ISO 27001, HIPAA BAA, support response SLAs as plan rows (render.com/pricing) Publisheda $99/month Compliance plan "from BAAs to SOC2s", SSO authentication, enterprise SLA arrangements (fly.io/pricing)
Column summary 4/4 published · 16/20 topics 3/4 published · 9/20 topics 3/4 published · 10/20 topics 2/4 published · 10/20 topics

Vercel is the only company here with no Partial row and leads publicly answerable topics by six; the peers cluster within a point, with the closest race on the pricing page, where Render's plan table nearly matches Vercel's.

Exhibit

ISO 27001:2013 · stated on the security page

Compliance

“Vercel is ISO 27001:2013 certified”

The docs page reads ISO 27001:2022 and links the public certificate — one surface trailing its own program.

Recreated from vercel.com/security as observed 2026-09-02. The 27001:2022 certificate is public in Schellman's directory; the security page still names the 2013 standard.

What this costs in a security review

Nothing in this section needs a citation; it is the mechanics of the review itself. Every topic a reviewer can't answer from the public web becomes a questionnaire question: sent by email, routed to whoever holds the answer, written up, sent back, read. Each round-trip adds days, and the days accumulate while the deal sits in review. On today's table, Vercel starts with 16/20 topics answerable self-serve; Render starts at 10/20 — the difference is round-trips.

Full findings

Topic-by-topic (public web only):

Publicly answered (16): encryption at rest — AES-256 — and in transit — HTTPS/TLS 1.3 (vercel.com/docs/security/compliance); SSO/SAML — $300/month on Pro, included on Enterprise (vercel.com/pricing); uptime SLA — platform SLAs on Enterprise (pricing); data residency — "Where does my data live?": customer-selected regions, U.S. default (docs); backups — every two hours, kept 30 days, globally replicated (vercel.com/security); subprocessor list — public on the trust center; DPA — full text at vercel.com/legal/dpa, updated 2026-03-17; pentest cadence — annual third-party tests plus ongoing assessments (vercel.com/security); access control — role-based, team and project level (pricing); vulnerability management — posture scanning, static analysis, dependency scanning (vercel.com/security); BCP/DR — failover strategy, recurring resiliency testing (docs); change management — change control via infrastructure as code (docs); logging/monitoring — audit logs on Enterprise (pricing); physical/hosting security — AWS across 20 regions (docs); compliance report access path — self-serve request gate at security.vercel.com.

Not publicly answerable (4): incident response process, employee security training, vendor risk management, data retention/deletion specifics — each a titled policy behind the trust center's request gate; a title behind a gate counts as not answerable.

Reads well: most of it — which is why this edition exists. Security and Trust Center are footer links; the docs page is current and links the public ISO 27001:2022 certificate; the DPA and subprocessor list are public; the pricing table carries compliance rows on every tier; the HIPAA BAA is self-serve on Pro; TISAX Assessment Level 2 is stated with its scope; and the April 2026 bulletin is an owned, dated disclosure.

Appendix — topic ledger

Which topics counted toward each company's publicly answerable score in the table above.

Vercel 16/20
encryption at rest · encryption in transit · SSO/SAML · uptime SLA · data residency · backups · subprocessor list · DPA · pentest cadence · access control · vulnerability management · BCP/DR · change management · logging/monitoring · physical/hosting security detail · compliance report access path
Netlify 9/20
encryption at rest · encryption in transit · SSO/SAML · uptime SLA · subprocessor list · DPA · access control · logging/monitoring · compliance report access path
Render 10/20
encryption in transit · SSO/SAML · uptime SLA · backups · subprocessor list · DPA · access control · logging/monitoring · physical/hosting security detail · compliance report access path
Fly.io 10/20
encryption at rest · encryption in transit · SSO/SAML · uptime SLA · backups · subprocessor list · pentest cadence · access control · physical/hosting security detail · compliance report access path