At GLIDE, we understand the critical importance of security in today's digital landscape. As part of our commitment to secure, reliable services, we rely on the security measures provided by our preferred hosting partner, WP Engine. If you use a different host, we recommend consulting their security documentation.
SSL (Secure Sockets Layer): SSL encryption keeps communication between a website and its visitors secure, safeguarding sensitive information such as personal data and payment details. Most WP Engine plans include a free Let's Encrypt SSL certificate.
Global Edge Security: This feature adds protection against DDoS attacks and improves performance through a global content delivery network (CDN). It is an add-on for most WP Engine plans, and we recommend it.
Security monitoring: For clients on an active support plan, we include ongoing security monitoring through our WP Umbrella account. This gives us a consistent view across the sites we maintain, so we can spot and address issues early. Monitoring covers uptime and performance, plugin and theme updates, vulnerability and malware checks, and backups. Monitoring reduces risk; it does not guarantee that a site can never be compromised.
To further strengthen security on your marketing website, we recommend these best practices:
Multiple administrators: Keep more than one administrator on both hosting and your content management system (CMS), so access is never tied to a single person.
Secure passwords: Use strong, unique passwords and update them regularly.
Malware scans: Run regular malware scans to catch and address threats early.
Security plugins: If you are not on a support plan, a dedicated security plugin (such as Wordfence) is a good option. Look for firewall protection, login-attempt monitoring, file-integrity checks, and malware scanning. Use our referral link for Wordfence >>.
Regulatory Frameworks
SOC 2 and ISO certifications are not mandated by any specific country; they are internationally recognized industry standards. GLIDE is SOC 2 Type II compliant, and we recommend an experienced vendor like Sprinto or Vanta for organizations that need to achieve and maintain their own certifications.
SOC 2 (System and Organization Controls 2): Developed by the American Institute of CPAs (AICPA), SOC 2 focuses on controls for the security, availability, processing integrity, confidentiality, and privacy of customer data. It is not required by law, but organizations that handle sensitive customer information often pursue it to demonstrate their commitment to security.
ISO (International Organization for Standardization): ISO standards span many areas, including information security (ISO/IEC 27001). They are not legally mandated but are widely adopted as benchmarks for best practice. ISO/IEC 27001 in particular provides a framework for establishing and maintaining an information security management system.
PCI DSS (Payment Card Industry Data Security Standard): Unlike SOC 2 and ISO, PCI DSS is mandated by the major card brands (Visa, Mastercard, American Express, Discover, and JCB) for any organization that processes, stores, or transmits payment card data. It is a contractual obligation rather than a law, and non-compliance can lead to penalties, reputational damage, and loss of payment processing privileges. Adhering to PCI DSS is essential for any site that handles payment card transactions.
Recommended PCI DSS payment processors:
WordPress: Stripe, PayPal
Shopify: Shopify Payments, PayPal