generated: '2026-07-19' method: searched source: https://www.optimizely.com/trust-center/compliance notes: >- Standards conformance for Optimizely (formerly Episerver). Security/compliance certifications are searched from the Optimizely trust center; API-shape standards are asserted from the developer docs (OIDC/OAuth2 identity via Opti ID, GraphQL Content Graph, REST content APIs, webhooks). standards: - id: soc2 conforms: true evidence: SOC 2 listed on optimizely.com/trust-center/compliance - id: iso-27001 conforms: true evidence: ISO 27001 listed on trust center - id: iso-27017 conforms: true evidence: ISO 27017 listed on trust center - id: iso-27018 conforms: true evidence: ISO 27018 listed on trust center - id: pci-dss conforms: true evidence: PCI DSS listed on trust center (Commerce) - id: hipaa conforms: true evidence: HIPAA listed on trust center - id: gdpr conforms: true evidence: GDPR data-protection posture described in trust center - id: oauth2 conforms: true evidence: OAuth2 / bearer-token access on Feature Experimentation + Graph - id: oidc conforms: true evidence: OpenID Connect via Opti ID identity platform - id: graphql conforms: true evidence: Optimizely Graph (Content Graph) is a GraphQL API - id: webhooks conforms: true evidence: webhooks documented for Feature Experimentation and Optimizely Graph