Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Enonic

VERIFIED
Headless CMS · Norway
Founded 2000 · enonic.com ↗

Norwegian headless/hybrid CMS (Oslo, est. 2000); founder-owned, ISO 27001 + 9001 certified — but managed Enonic Cloud runs on Google Cloud + Azure + Fastly.

In short

Enonic, in the Headless CMS category, offers EU hosting with Norway as its hosting location, but a US parent or sub-processor leaves material CLOUD Act exposure.

Assessment notes

Enonic (Enonic AS, Oslo, founded 2000) is ISO 27001:2022 + ISO 9001:2015 certified (annual external audit of the 93 InfoSec controls), GDPR-compliant with a named Data Privacy Officer, DORA-aligned, and publishes both a downloadable DPA and a public sub-processor list — strong governance posture. Norway is EEA/EFTA but not EU, and ownership is founder-led (Morten Øien Eriksen + Thomas Sigdestad) with no identified VC/PE/US capital — hence ownership_signal: other (clean Norwegian local-hero on paper). The procurement caveat is the managed Enonic Cloud stack itself: per its own third-party-suppliers page the production IaaS is Google Cloud Platform (US-owned, EU region) with Microsoft Azure for encrypted off-site backups (Sweden) and Fastly (US) as CDN — data-at-rest lives on US-owned hyperscaler infrastructure inside the EEA, which is textbook material CLOUD Act exposure despite the Norwegian cap table. The escape hatch is self-hosting the open-source Enonic XP runtime on EU-sovereign infra, which removes Google/Azure/Fastly entirely.

CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
CLOUD Act by deployment

Exposure depends on how you run this product.

Hosted SaaS (default)

Vendor-operated — the sub-processors below apply.

Self-hosted (open-source)

Deploy on your own EU infrastructure and you control hosting and every sub-processor.

Verified signals
Jurisdiction
  • EU / adequacy hosting
  • EU / adequacy operator
  • No US CLOUD Act exposure
Transparency
  • Public DPA
  • Sub-processors disclosed
  • Open-source clients
  • Third-party certification
JUMP TO
OVERVIEW

About Enonic

Enonic (Enonic AS, Oslo, founded 2000) is Norway's largest Norwegian-owned CMS vendor — a hybrid headless / visual-editing content platform built on its open-source Enonic XP runtime, positioned directly against Optimizely, Contentful and Sanity. Founder-owned by Morten Øien Eriksen and Thomas Sigdestad with no identified VC or PE capital, it is one of the cleaner ownership stories in the category. Compliance posture is genuinely strong: ISO 27001:2022 (annually externally audited against all 93 controls) and ISO 9001:2015 certified, GDPR-compliant with a designated Data Privacy Officer, DORA-aligned, a publicly downloadable DPA, and a public sub-processor list. The important nuance for sovereignty buyers is the managed Enonic Cloud infrastructure: Enonic's own third-party-suppliers page lists the production IaaS as Google Cloud Platform (US-owned, EU region), Microsoft Azure for encrypted off-site backups (Sweden), Fastly (US) for CDN, plus Mailgun (DE), Auth0 and Zendesk (EU), and Slack (US) for community support. So while the company is Norwegian and bootstrapped, the hosted data at rest sits on US-owned hyperscalers within the EEA — material CLOUD Act exposure. Buyers who need true sovereignty can instead self-host the open-source XP runtime (GPL-3.0 with a linking exception) on Hetzner / OVH / Scaleway, which removes the US sub-processors from the data path. Pricing: a free tier (5 GB), with Professional and Enterprise tiers quoted on request (no public EUR price).

SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications

ISO/IEC 27001
ACTIVE
ISO9001
ACTIVE
FEATURES

Capability matrix

Self-hostable Yes
Version history Yes
GraphQL API Yes
REST API Yes
Visual editor Yes
Localization (i18n) Yes
Media library Yes
API / webhooks Yes
INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option Yes
PRICING

Pricing & tiers

FREEMIUM
Custom pricing

Contact vendor for tier or volume pricing.

View pricing page ↗
PUBLIC DOCUMENTS

Public documents

  • Data Processing Addendum (DPA)
    www.enonic.com/platform…
    Open ↗
  • Sub-processors list
    enonic.com/cloud…
    Open ↗
ALTERNATIVES

Alternatives in this category

DatoCMS
Italy · Founded 2015
EU-BASED

Italian developer-friendly headless CMS (Milan); 25K+ businesses; bootstrapped feel, no US PE.

Public DPA Sub-processors Open source
FROM
€39/mo
CLOUD ACT
MINOR
Hygraph
Germany · Founded 2017
EU-BASED

Berlin GraphQL-native headless CMS (formerly GraphCMS, founded 2017); enterprise clients incl. Samsung, LEGO; mostly EU-funded.

Public DPA Sub-processors Open source
FROM
€39/mo
CLOUD ACT
MINOR
Prismic
France · Founded 2013
EU-BASED

Paris headless CMS / page-builder (founded 2013); Slice Machine + Next.js / Nuxt / SvelteKit focus; from €7/mo.

Public DPA Sub-processors Open source
FROM
€7/mo
CLOUD ACT
MINOR