Aller au contenu
Vérifié indépendamment · Ré-audit trimestriel
EU VETTED

Strapi

VéRIFIé
CMS headless · France
Founded 2017 · strapi.io ↗

Paris-based open-source headless CMS (founded 2017); MIT-licensed core, Strapi Cloud PaaS, US-VC-funded (Insight, CRV).

Pourquoi ce score ?

Strapi (Paris FR, founded 2017) is the leading open-source headless CMS (MIT license) with Strapi Cloud (PaaS) and Enterprise self-hosted editions; SOC 2 certified, GDPR compliant; but Series C 2022 was led by Insight Partners (US PE/VC) with CRV (US) and Index — material US-VC control flips signal to eu_hq_us_funded; no public ISO 27001 attestation.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About Strapi

**Strapi** (Paris, France, founded 2017) is the most-installed open-source headless CMS — **MIT-licensed core**, **Strapi Cloud** PaaS-hosted offering, and **Enterprise Edition** self-hosted with extended features. The OSS community is significant (>60K GitHub stars). Compliance: **SOC 2 certified, GDPR compliant** (no public ISO 27001 attestation surfaced at time of research). The procurement-grade caveat is funding: Series C 2022 was led by **Insight Partners** (US growth-PE, $90B AUM, New York) with **CRV** and Index. So the company is French-operated but US-PE-controlled at cap-table level. Effective story when self-hosted (MIT) on EU infra: customer data never reaches Strapi, so cap-table US influence is moot for that deployment.
SUB-PROCESSORS

Carte des sous-traitants · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Référentiels & certifications

SOC 2
ACTIVE
Informational · US framework
FEATURES

Matrice de fonctionnalités

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option Yes
PRICING

Tarifs & paliers

FREEMIUM
à partir de €15/mois
Voir la page tarifs ↗
PUBLIC DOCUMENTS

Documents publics

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
ALTERNATIVES

Alternatives dans cette catégorie