In Sitefinity SaaS, the application's security is treated with highest priority. Mechanisms for securing your project are available on both application and infrastructure level.
Sitefinity has an out-of-the-box Web security module that you can use to configure HTTP security headers, redirect, and referrer validation. This way, you protect your Sitefinity sites against attacks.
There are various types of attacks that you can prevent – Cross-site scripting (XSS), clickjacking, code injection, stealing or modifying data in transit (man-in-the-middle), content sniffing. HTTP protocol defines headers that all modern browsers understand and use to protect user or site data. Additionally, built-in redirect and referrer validation mechanisms add further protection against Open Redirect and Cross-site Request Forgery types of attacks.
For more information, see Web security module.
Sitefinity SaaS adds an extra layer of infrastructure security to complement the out-of-the-box security capabilities, provided on application level. This extra layer of security is implemented utilizing Cloudflare and Microsoft Azure services and components.
Multi-tenancy
Sitefinity SaaS architecture provides a multi-tenant setup where customers share some of the underlying infrastructure resources. Progress utilizes strong tenant isolation security and control capabilities to maintain segregation. Different services and components for each customer subscription (project) are logically isolated using network policies. For more information, see Architecture.
Access control policies are implemented for each type of resource used. For more details, see Azure connectivity section below. Customers do not have access to any of the Azure services, except for read access to Application Insights.
All Sitefinity SaaS user accounts are protected with Microsoft Entra ID (formerly, Azure AD) Multi-factor Authentication.
Distributed denial of service (DDoS)
Such attacks represent one of the biggest security concerns for customers and vendors alike. A DDoS attack targets an application’s resources, making the application unavailable to legitimate users. Sitefinity SaaS takes advantage of the automatically enabled DDoS protection for the entire Azure platform. Always-on traffic monitoring, and real-time mitigation of common network-level attacks, provide the same defenses utilized by Microsoft’s online services. The Cloudflare WAF is the entry point for all application traffic and provides additional DDoS protection (see Cloudflare connectivity section below).
Network traffic filtering
Security rules that control network traffic to and from the Azure resources that constitute the Sitefinity SaaS setup for a given project/tenant.
Encryption at rest
Website file content, database backups, and system logs are stored in Azure Storage, which automatically encrypts the content at rest.
Database backups and point-in-time restore
The Azure SQL database service protects all databases with an automated backup system. These backups are retained for 35 days by default. Point-in-time restore is a capability, allowing to restore a database from these backups to any minute within the retention period. Database restore is performed only after an explicit request from the customer.
Transparent data encryption for databases
Encrypts your databases, backups, and logs at rest, without any changes to your application.
Advanced Data Security (SQL Servers)
Includes Data Discovery & Classification, Vulnerability Assessment, and Advanced Threat Protection.
SQL database auditing
Helps to maintain regulatory compliance and to gather insights into any database discrepancies and anomalies.
In Sitefinity SaaS, Cloudflare is the entry point for all the client requests to the customer’s web applications. The following security checks are performed before the request is passed to the Azure Kubernetes Service (AKS) origin servers:
Access to any environment can be restricted based on an IP whitelist provided by the customer.
The Cloudflare web application firewall (WAF) keeps applications and APIs secure and productive, prevents DDoS attacks, keeps bots at bay, detects anomalies and malicious payloads, all while monitoring for browser supply chain attacks.
Virtual Network integration with AKS.
To submit feedback, please update your cookie settings and allow the usage of Functional cookies.
Your feedback about this content is important