Pitt Digital Approved Website Hosting Options

Body

Websites are an important method by which the various schools, departments, labs, researcher teams, faculty, and staff communicate information with both the outside world and within the University community.  While these sites provide valuable information, if not properly maintained, the integrity of the sites can be compromised.  Website compromises can included: malicious redirects, malware infections, data theft, spam and ads, and defacement or content changes. 

The risks of a compromised site can range from a negative impact on a site and it’s owners reputation to a data breach which could impact a research team’s ability to recruit participants or even continue the project. 

In order to reduce the risks of compromised sites, the University requires the options in the chart below be used to host websites. 

Using these options provides better security controls and monitoring, ensures sites are scanned and updated, and can lead to quicker response times in the case of incident.

Please note:  To reduce University data security and reputational risks, using Pitt Digital approved website hosting options to redirect to non-approved hosting options is not permitted.  Any site found redirecting to non-approved hosting providers will have the redirect site retired.  The site redirected to will be required to be hosted on a Pitt Digital approved option.  

 

Hosting Option

Use Case Public Private

FERPA

Non-Directory

GLBA

 

HIPAA

NIST 800-171

CUI

PCI DSS

CampusPress 
 

See CampusPress site for use cases.

OpenScholar
 

See OpenScholar site for use cases.

Pantheon 
 

See Pantheon site for use cases.

Azure App services Only for web-enabled applications in which the application webpages are not separable from the application code, or restricted data types that cannot be hosted on CampusPress, OpenScholar, or Pantheon. Supports .NET, Java, Node.js, Python, and PHP
Azure Virtual Machine Only for web-enabled applications that cannot be hosted on Azure App Services, or sites that work with restricted data types that cannot be hosted on CampusPress, OpenScholar, or Pantheon. Preferred for Windows based web servers, but can also run Linux.
Amazon Web Services (AWS) EC2 Only for web-enabled applications in which the application webpages are not separable from the application code, or restricted data types that cannot be hosted on CampusPress, OpenScholar, or Pantheon. Should only be used to host Linux based web servers.

Google Cloud

Platform (GCP)

Not a standard offering for web hosting and is managed by Burwood. Should only be used if Azure and AWS are not viable and with security's approval.
Enterprise Web Infrastructure (EWI) Not approved for use.
Departmental Server Hosted Only for web-enabled applications in which the application webpages are not separable from the application code, or restricted data types that cannot be hosted on CampusPress, OpenScholar, or Pantheon

Requires

Security

Approval

Requires

Security

Approval

Requires

Security

Approval

Andrew File System Not approved for use.

Oracle Cloud Infrastructure (OCI)

 

Hosts Human Resources sites only.

Not approved for other uses.

Other Third-Party Hosting
(Wix, GoDaddy, Squarespace, etc.)
Not approved for use.

 

Details

Details

Article ID: 3046
Created
Tue 9/9/25 3:26 PM
Modified
Tue 3/31/26 12:45 PM