How secure is Bubble?
Bubble complies with the SOC 2 Type II standard for security and offers a GDPR-compliant data processing agreement (DPA).
Does the SOC 2 Type II report apply to all Bubble plans?
Yes — the SOC 2 Type II report applies to the entire platform. All apps on Bubble's main cluster and dedicated instances benefit from this compliance, regardless of plan type.
What cloud hosting provider does Bubble use?
Bubble hosts its infrastructure on Amazon Web Services (AWS), which is SOC 2, CSA CAIQ, and ISO/IEC 27001 compliant.
Can I choose where the AWS server for my app is hosted?
If you're on an Enterprise Dedicated plan, you can specify the region where your server and data are located from Bubble's growing list of AWS data center regions (found here). For all other app plans, Bubble's servers and data are hosted on AWS West Region. More information about how apps on the main cluster are hosted can be found in this article.
How does Bubble encrypt user data?
Your data is safeguarded in transit with TLS and at rest with AES-256 encryption through RDS.
Does Bubble conduct third-party security audits and penetration testing?
Yes. Bubble conducts automated code testing, vulnerability testing (OWASP Top 10), and continuous monitoring. We also conduct pen tests at minimum annually, following OWASP WSTG.
Does Bubble provide data backup and recovery?
Yes. Bubble uses point-in-time backups to enable recovery for Bubble apps and their underlying databases.
Do you support multi-factor authentication and SSO?
All Bubble users can enable two-factor authentication (2FA) on their account. The Enterprise plan allows admins to streamline user management with SSO account provisioning.
How securely does Bubble integrate with external systems?
Bubble can connect with any system through the API Connector, which supports a variety of secure authentication methods including OAuth, Bearer Auth, Basic Auth, and more.
Who owns my data?
You own your data — including your app's design and the data your users upload (subject to your own agreement with them).
Can Bubble employees access my app data?
You control this. In your app's General Settings under Privacy & Security, you can toggle whether Bubble employees can access the Data – App data tab. Only the app owner can change this setting.
Even with access disabled, Bubble employees can still view and edit the app itself, and can see data exposed in app preview, the deployed live app, or logs.
How does Bubble protect against DDoS attacks?
Bubble apps follow the principle of least privilege in their default API configurations to minimize the DDoS attack surface. We also use Cloudflare and an in-house monitoring system to detect and block attacks — so all apps on Bubble get industry-standard DDoS protection, with our team available to help if issues arise.
How do I protect my users' data in my app?
The most effective step is configuring Privacy Rules. These rules are enforced server-side and let you control who can access which data types and fields — for example, restricting sensitive fields to specific user roles. You can also use the security dashboard to audit your app for vulnerabilities.
What should I do if I discover a security breach?
If you think you've found a vulnerability in Bubble itself, report it to our team so we can address it.
If the breach is in your own app — for example, due to misconfigured privacy rules — consult the applicable privacy laws in your and your users' regions to understand your obligations. In general, if a breach poses a risk to an individual's rights, you may need to notify affected users promptly. We can't provide legal advice, but acting quickly is important.
How long are Bubble's session cookie storage windows?
Non-logged-in users: 3 days
Logged-in users who opt to stay logged in: up to 1 year (memory pressure can log users out earlier)
Logged-in users who do not opt to stay logged in: 1 day
What are Bubble's security standards?
Bubble adheres to industry-leading standards — including encryption protocols, regular security audits, and compliance with GDPR and other global data protection regulations. You can review Bubble's full security posture at bubble.io/security.
