
Sitecore Content Hub
By Sitecore A/S

The typical implementation process for Content Hub by Sitecore software, which manages digital assets, content creation, and marketing, follows these steps:
Sitecore Content Hub can be extensively customized to fit specific business needs. Here are several data points that demonstrate its customization capabilities:
Customizable portal languages: Content Hub allows you to add and customize portal languages as required, enabling localization for different regions or markets.
Visual themes: Users can create new themes or modify existing ones to match their branding and style, allowing for a personalized look and feel of the Content Hub interface.
Customizable home page: The home page can be customized by adding items to the News and What's new sections, ensuring users are kept engaged and up-to-date with the latest developments.
Flexible content planning: Content Hub allows businesses to plan content creation by subject, persona, campaign, or any other way that fits their specific needs.
Custom content models: While Content Hub offers predefined content models out of the box, organizations can create custom models tailored to their specific business requirements.
API-first approach: Content Hub's API-first approach allows for seamless integration with other Sitecore products and third-party platforms, enabling businesses to leverage their existing tech stack.
Customizable workflows: The platform supports agile workflows and approvals that can be tailored to stay on-brand and match specific business processes.
Authoring permissions: Content Hub allows for customization of authoring permissions, enabling businesses to set up collaboration and approval processes that align with their organizational structure.
Metadata customization: Administrators can add custom metadata to each file and piece of content, making it available for quick discovery and supporting personalization and localization efforts.
Customizable analytics: Content Hub provides analytics tools that can be tailored to measure impact and performance, informing asset prioritization and campaign strategies specific to the business.
Extensibility through cloud development: Content Hub offers cloud development capabilities, allowing businesses to extend or customize their Content Hub solution and integrate it with other tools.
Free E-Learning Courses: Sitecore provides free learning courses for new users on their learning platform. These courses are described as limited and entry-level, but can be a good starting point.
Sitecore Content Hub Developer Certification Bundle: This is a comprehensive offering that includes:
eLearning materials
Virtual training sessions
Study guides
A voucher for the certification exam
Official Documentation: Sitecore provides extensive documentation for Content Hub, covering various aspects like getting started, managing digital assets, content management, project management, content delivery, cloud development, and API references.
User Training and Documentation: Implementation partners like Fishtank offer demos, user training, and documentation to help users learn the ins and outs of Content Hub.
Community Support: There are blogs and community resources available where users can seek help and information.
Ongoing Support: Implementation partners often provide post-migration support, helping with adjustments and changes to ensure Content Hub serves the organization's needs.
Video Tutorials: Sitecore provides video demonstrations, such as the one for Content Hub ONE, which offers step-by-step instructions on how to model content, create content, upload media items, and deliver content to channels
Sitecore Content Hub implements several robust security measures to protect data and ensure the integrity of digital assets:
Industry-standard security methods: Content Hub integrates industry-standard security methods and best practices to protect data against potential attacks.
Role-based security model: Sitecore employs a role-based security model where access to resources and functionalities is controlled based on user roles and permissions.
Authentication and authorization: Content Hub supports various authentication mechanisms, including username/password authentication, Active Directory integration, and OAuth authentication.
Encryption and data protection: Sitecore provides built-in encryption capabilities for securing data at rest and in transit, using strong cryptographic algorithms and key management practices.
Web Application Firewall (WAF): Content Hub uses a WAF to protect against malicious attacks such as SQL injection (SQLi) and Cross-site scripting (XSS) using an OWASP ModSecurity Core Rule Set.
DDoS protection: Unmetered DDoS protection is provided for web assets (HTTP/HTTPS), powered by the intelligence from Content Hub's global network.
Demilitarized zone: Content Hub implements technical and organizational controls, including system monitoring using Security Information and Event Management (SIEM) to detect intrusion or data leakage.
Intrusion Protection Service (IPS): Perimeter controls, including firewalls and access control lists, are used to secure the Content Hub network against external attacks.
Traffic segregation: All cloud environments have dedicated isolated web, data, and processing components, with traffic from outside only allowed for HTTP/HTTPS towards web components.
Security Operation Center (SOC): Content Hub maintains a SOC function that performs regular scanning on various logs and systems.
Network security testing: Regular vulnerability assessment tests and network security penetration testing are performed on cloud environments.
Sitecore Content Hub Updates:
Automatic upgrades: As of Content Hub version 4.2 and onwards, Sitecore has introduced automatic upgrades, meaning that upgrades are performed automatically and on a regular cadence.
Versionless SaaS model: Content Hub has moved to a versionless Software-as-a-Service (SaaS) model. This means customers will always be on the latest version without the need for complex and time-consuming manual upgrades.
Regular update cadence: Updates will be deployed automatically to Content Hub instances on a regular cadence. The exact frequency is not specified, but it appears to be more frequent than traditional manual upgrades.
Update identification: Instead of version numbers, updates will be identified by dates.
Notification for breaking changes: If an upcoming release contains breaking changes, customers will be notified at least one month in advance.
Staged deployment: For updates with breaking changes, the update will be deployed to non-production environments first, then 14 days later to production instances. This gives customers time to test and mitigate any breaking changes before they affect production.
Continuous improvement: This model allows customers to benefit from new features, bug fixes, and improvements without the need for manual upgrades.
Rollback procedure: If issues are found, Sitecore plans to fix them in the following version for every client. They suggest that clients and partners move away from testing every release and instead put together a test plan at a defined frequency to ensure custom logic still works as expected.
Sitecore Content Hub policy on data ownership and portability generally adheres to the following principles:
Data Ownership: Sitecore Content Hub customers retain full ownership of all content and data uploaded to and managed within the platform. This includes digital assets, metadata, and any custom content created using the software. Sitecore acts as the service provider and does not claim ownership of customer data.
Data Portability: Sitecore Content Hub allows for data portability, meaning customers can export their data and digital assets at any time. The platform typically provides tools or APIs to enable the extraction of content, assets, and metadata in standard formats, ensuring seamless migration to another platform or local storage when needed. This ensures that users can maintain control over their data without being locked into the Sitecore ecosystem.
The terms and conditions for contract renewal and cancellation for Sitecore Content Hub typically depend on the specifics of the contract between Sitecore and the customer. However, several common data points apply:
Auto-Renewal Clauses: Sitecore Content Hub contracts include an automatic renewal clause, which means the contract will renew for an additional term (often one year) unless either party provides notice of non-renewal within a specified period.. Customers are typically required to notify Sitecore 30 to 90 days before the contract's expiration date if they wish to cancel or negotiate new terms.
Renewal Pricing: Pricing for renewal may be subject to change. Sitecore might increase fees based on usage, additional services, or inflation adjustments. These changes are often communicated in advance, usually 30-60 days before renewal..Renewal pricing may also reflect new licensing tiers or packages if Sitecore has updated its offerings.
Negotiation Window: Customers can negotiate terms or modify their subscription plans before renewal. Sitecore may offer discounts or adjustments based on the length of the commitment or additional services purchased.
Service Levels and Support: Any agreed-upon service level agreements (SLAs) regarding uptime, response times for support, and performance will typically roll over into the renewed contract unless renegotiated.
Notice Period: For cancellation, Sitecore typically requires a written notice of intent to cancel within a specified time frame, usually 30 to 90 days before the end of the contract term. Failure to provide timely notice may result in automatic renewal or penalties.
Early Termination: Some contracts allow for early termination, but this usually involves penalties or fees. The customer may be required to pay a prorated amount based on the remaining months of the contract or a percentage of the total contract value. Early termination might be allowed without penalty if Sitecore fails to meet certain performance metrics, such as SLAs related to uptime or support.
Data Retrieval Upon Cancellation: Customers are typically given a limited time to retrieve their data after cancellation, usually ranging from 30 to 90 days. During this period, customers can export digital assets, metadata, and content. After this period, Sitecore may delete the data in compliance with data retention policies, so customers must ensure data portability before the deadline.
Refund Policy: Refunds are generally not provided for early cancellation unless explicitly stated in the contract. Sitecore typically operates under a no-refund policy for unused subscription terms, but there may be exceptions for significant service failures.
Post-Termination Access: After cancellation, access to the platform is revoked, except for the agreed-upon period for data retrieval. If additional time is required to retrieve data, customers may negotiate for an extension, potentially at a cost.
Contract Downgrade: If a customer wishes to scale down their usage or subscription plan, this often requires negotiation before the renewal date. Sitecore might allow downgrades but will generally not refund fees for unused services.
Compliance with Obligations: Both parties are obligated to comply with the contract terms until the effective cancellation date. Failure to comply can result in penalties or legal action.
Breach of Contract: Either party can terminate the contract for cause if the other party materially breaches the contract. Examples might include failure to pay fees on time or failure by Sitecore to deliver promised services.
Remedy Period: In cases of breach, the offending party is often given a remedy period (typically 30 days) to correct the issue. If the issue is not resolved within this time frame, the contract may be terminated without penalty to the non-breaching party.
Non-Renewal Option: Customers always have the option not to renew the contract at the end of its term, provided they give the required notice.
Adjustments to Services: Contracts can be adjusted in scope before renewal, allowing clients to add or remove features, integrate additional services, or modify their subscription tier.
Governing Law: The contract will typically specify the governing jurisdiction for any disputes. Sitecore often includes clauses related to arbitration or mediation before legal proceedings.
Sitecore Content Hub meets several important compliance standards and certifications:
ISO 27001:2013: This is a security standard for Information Security Management Systems (ISMS). It covers implementation, monitoring, maintenance and continuous improvement of the ISMS.
ISO 27017:2015: This standard provides guidance on information security aspects specific to cloud computing. Sitecore uses this to supplement ISO 27001:2013 for its public cloud environment.
ISO 27018:2014: This code of practice focuses on protection of personally identifiable information (PII) in public clouds. Sitecore uses this to protect PII it processes for customers.
CSA STAR Certification: This leverages ISO 27001:2013 requirements along with the Cloud Security Alliance's Cloud Controls Matrix to ensure compliance with cloud security issues.
SOC 2: Sitecore undergoes SOC 2 audits to demonstrate the operating effectiveness of its controls for security, confidentiality, and availability of its public cloud environment.