Webflow adheres to state of the art web application security practices, with on-going, third party audits on our hosting infrastructure and on Webflow.com itself. CSRF, XSS, XFS, SQL Injection, and other web application attack vectors are thoroughly screened as part of our engineering and QA processes.
While no internet service is completely safe from attacks, Webflow has Advanced DDOS protection measures in place to alleviate the most common attacks.