Xperience by Kentico is a mid-market digital experience platform built on .NET that can serve pages itself or deliver content headlessly.
Umbraco is the natural .NET alternative. It is cheaper and simpler to build on, with a clear lead on total cost and ease of implementation. Xperience by Kentico is far stronger on built-in capabilities, thanks to its customer data platform, personalization, automation, email and commerce. It also releases on a steadier monthly schedule. Pick Umbraco for a lean CMS and Kentico for an integrated marketing suite.
Full Comparison →Both are .NET marketing platforms. Xperience by Kentico leads on release pace and vendor momentum, ease of operation and cost, reflecting its monthly SaaS Refreshes and more predictable pricing. Sitefinity is stronger on fit for common use cases and on readiness for regulated industries.
Full Comparison →Optimizely PaaS is the enterprise .NET step up. It leads on core content management, architecture, AI capability, readiness for regulated industries and experimentation. Xperience by Kentico is meaningfully cheaper and easier to run. It is the pragmatic mid-market choice when built-in experimentation and enterprise AI are not requirements.
Full Comparison →Contentful is the headless-first alternative. It leads on architecture, AI capability, readiness for regulated industries and SDK coverage across programming languages. Xperience by Kentico counters with built-in personalization, a customer data platform, marketing automation, forms, email and commerce. Contentful covers these with add-ons or third parties. Kentico is also slightly ahead on fit for common use cases.
Full Comparison →The changelog shows a named Refresh in every month of 2026, from January through version 31.9.0 on Sept 24, with weekly hotfixes in between. Every release lists obsolete APIs, known issues and security fixes in fixed sections. A published support policy guarantees at least 12 months of backward compatibility after a feature is deprecated. A public roadmap with Released, Preview and Planned tabs shows buyers what is coming.
Each headless channel gets an automatically generated, strongly typed GraphQL endpoint. SaaS delivery runs through the Cloudflare CDN, with fine control over which cached content is refreshed when something changes. On the .NET side, developers can add custom modules, global events, builder components and custom data types. Custom automation triggers and conditions were added in July 2026. Images stored as content item assets are converted to WebP or AVIF, and administrators can define image variants.
The SaaS offering is ISO 27001 certified and SOC 2 Type II audited, with a SafeBase trust center. Customers can pick from 20 Azure regions, and their data is held in an account dedicated to them in the chosen region. Deployment options cover Kentico SaaS, documented private cloud on Azure or AWS, and self-hosting. Uptime is designed for 99.9%. Published targets are recovery in about 1 hour with data loss limited to between 1 and 24 hours, backed by annual disaster recovery tests.
The G2 listing averages about 4.4 out of 5 across roughly 355 reviews, and Gartner Peer Insights about 4.5 out of 5. Info-Tech reports a Net Promoter Score of +77. Kentico reports 2025 revenue of $56.7M, up 35%, and its G2 Leader status continued into 2026. Profitable private ownership and no reported layoffs support stability. Some of the growth, though, comes from KX13 customers who are required to migrate.
Configurable multi-stage workflows cover every content type, with transitions tied to roles, comments at each step, Workspaces and page permissions. Versioning with restore and scheduled publishing applies to pages, reusable items, headless items and emails. Page Builder lets marketers compose pages by drag and drop from widgets that developers build. Approvals are routed to the right role at each step.
Unified Profiles and identity matching that administrators can configure (April 2026) support segmentation by rules and by behavior. They merge visitor records into single customer profiles, as a customer data platform (CDP) does. Page Builder and Email Builder can personalize individual widgets by contact group. The Form Builder now exports submissions to CSV, and the Automation Builder gained custom actions, triggers and conditions in June and July 2026. All of this is included in the product, not sold as add-ons.
The rebuild dropped the intranet and social features Kentico had in earlier versions. There is no employee directory or org chart, no integration with learning management systems and no social collaboration. There are no internal communications tools such as read receipts, and no Microsoft 365, Teams or Slack integration. Any intranet would be a fully custom build.
Kentico's own migration guide says A/B testing is not supported in the product. Experiments go through the official VWO Tag Manager integration and run only in the visitor's browser. There is no engine that recommends content to site visitors, which is a real gap for a platform sold on personalization.
AIRA, Kentico's AI assistant, runs only on Azure OpenAI credits managed by Kentico. Customers cannot bring their own model or key. All four agents in the Agentic Marketing Suite are marked as Preview features that may change without notice. Semantic search requires an Azure AI Search resource that the customer sets up. There is no audit trail of who used AI or what it generated.
Kentico's How to Buy page publishes no dollar figures, and the widely quoted prices come only from third-party listings. Contracts are annual only, and reviewers report annual increases of up to 25%. The only free options are a 7-day hosted trial and a 30-day local license. Custom code cannot be carried to another platform, which adds moderate lock-in.
The only official content library (SDK) is for .NET. JavaScript, Python and mobile clients call GraphQL directly, and there is no TypeScript type generation. Kentico maintains no Next.js or React starter, so headless frontends rely on community guides. Outbound webhooks, which notify other systems when content changes, do not exist and must be built with .NET global event handlers.
In May, Kentico disclosed a critical SQL injection flaw (CVSS 9.4) and a bypass of multi-factor authentication. Further advisories followed almost every month. They included three more SQL injections, an Email Builder flaw that allowed files to be read, and exposure of protected assets through a shared cache. September brought an administrator account takeover through account recovery and a flaw that exposed workspace objects to the wrong users. Most affect every release back to version 22.0.0. Fixes arrive within days, but each one means a NuGet package update and a redeploy, and the login process was hit twice.
Xperience by Kentico supports four content type targets (reusable content, pages, emails, headless items) with a broad field-type set and reusable field schemas for composition across types. The August 20, 2026 refresh (31.8.0) let reusable field schemas use developer-registered custom data types (via the new SupportedTargets property), so shared schemas can carry serialized structured JSON values that come back as typed C# objects. Types are still defined in the UI and serialized for CI/CD rather than authored as code, which keeps it below headless-first platforms.
Content types support references to other content items including polymorphic references (linking to a large number of possible content types — addressed with a GraphQL EnableUnionQueryOptimization key). Standard one-to-many references with reverse traversal through GraphQL. The May 2026 content reuse locator surfaces where a content item is referenced across channels but does not change the underlying relationship model.
Page Builder provides a widget/section/zone system for composing structured pages. Headless channels support structured content items with defined content types. The May 14, 2026 refresh extended the Management API to retrieve and manage Page Builder components (widgets, sections, and their data) plus retrieve page templates, enabling programmatic access to structured page composition. Structured output for headless is GraphQL JSON (Headless REST API in preview) — no native Portable Text equivalent.
Standard field-level validations (required, regex, min/max length, file type) are built in. Custom validation is extensible via .NET code. The Management MCP server now performs content type field validation matching the administration UI — including validation rules and visibility conditions — improving programmatic consistency but not adding new validation primitives. No no-code cross-field validation rule engine or webhook pre-save hooks for marketers.
Content versioning is supported across all content types — reusable content, headless items, web pages, and emails — with headless items exposing Draft (Initial), Published, and Draft (New version) statuses. The version history UI allows review and restore of earlier versions. Scheduled publishing is available, including for content sync batches. The May 14, 2026 refresh added granular content synchronization with detailed/dependency selection between environments, letting authors selectively choose which versioned items to promote.
Page Builder provides drag-and-drop widget management described as an 'almost WYSIWYG experience' — marketers can rearrange and configure developer-prepared widgets on live page layouts without code. This is a genuine in-context page editor for non-technical users, though widget types must be pre-built by developers. Not a full freeform visual editor like Webflow.
Rich text editing is powered by Froala WYSIWYG editor (v5.0.0), with inline rich text editors available within Page Builder widgets. AIRA refinements went GA in April 2026, and the May 14, 2026 refresh expanded AIRA generation/refinement to text fields across pages, emails, headless items, and reusable content items — using linked items and page previews as context. Output remains HTML-based rather than a portable AST, limiting channel portability.
Asset management is consolidating into Content Hub content item assets. Support for legacy Media Libraries ended July 24, 2026, and they are hidden in the admin UI for projects that don't use them (31.8.0). Full removal was planned for September 2026 but has been postponed (31.9.0). Content item assets support image variants, now generated on demand even in read-only deployments, plus AIRA focal-point suggestions and a first-party Bynder integration. There is still no documented URL-based transformation pipeline for arbitrary resizing or WebP/AVIF, which keeps it below 75.
There is no real-time co-editing with presence indicators. Conflict handling now covers the whole product: content overwrite protection (May 2026), opt-in global content locking for pages, reusable items and headless items (June 29, 2026), and, from the July 28, 2026 refresh (31.7.0), locking for emails as well, including Email Builder, properties and plain-text tabs. It has override permissions, automatic lock release and workflow comment notifications. This is solid lock-based collaboration, but it is not Google-Docs-style co-authoring.
Configurable multi-stage workflows are supported across all content types with role-based transitions and comment-enabled step notifications. The April 2026 refresh added a Role management app with permission evaluation API for the admin UI. The May 14, 2026 refresh added Workspaces and page permission management for hierarchical access control, a Content reuse locator surfacing cross-channel usage during editorial decisions, granular content synchronization between environments, and content publishing workflows with notifications — together a substantial editorial-governance upgrade.
Each headless channel auto-generates a strongly-typed GraphQL API endpoint for content delivery, with union/polymorphic query optimization. The April 2026 refresh (31.4.0) introduced a Headless REST API in preview for retrieving content items over HTTP with JSON responses, closing the previous GraphQL-only gap. Both REST and GraphQL are now available for delivery (REST still preview; GraphQL read-only, no mutations/subscriptions), and the May 2026 Management API additions for Page Builder components further round out the API surface.
SaaS deployments integrate Cloudflare CDN for performance and DDoS protection. Cache dependency builder (added March 2025) provides granular cache invalidation keyed to content changes. Security events from Cloudflare are visible in Xperience Portal. CDN is SaaS-only — self-hosted deployments require customers to configure their own CDN.
The .NET global event system supports custom code handlers for object create/update/delete and lifecycle events on content items, web pages, and headless items. Zapier integration Phase 2 added inbound actions in 2026, providing webhook-like data exchange with 6,000+ external tools by triggering create/update/delete based on Xperience events. Native webhook documentation still lacks public detail on HMAC signing, filtering, retry logic, and delivery logs — Zapier brokers much of the integration surface rather than the platform exposing a first-class webhook framework.
Xperience by Kentico is a hybrid DXP — Page Builder for traditional website channels plus headless channels with GraphQL and (as of April 2026) a preview Headless REST API for external apps. Primary SDK is .NET/ASP.NET Core with an official Next.js integration. The May 2026 Management API additions for Page Builder components plus granular content synchronization improve programmatic multi-channel publishing flows. Rich text output is HTML (not AST), limiting format-agnostic portability versus purpose-built headless platforms.
Xperience by Kentico ships a native CDP with rule-based Contact Groups, behavioral activity-based conditions, and unified Profiles that merge customers, contacts, and members. The April 16, 2026 refresh added admin-configurable identity resolution with flexible matching on external identifiers or native fields plus new segmentation tools and extensible APIs. Not higher because B2B firmographic enrichment and pre-built Segment/mParticle/Tealium connectors remain absent.
Page Builder widgets support native content personalization rules tied to contact groups with in-editor preview per segment, and the June 2025 refresh added Email Builder widget-level personalization for email campaigns. G2 Winter 2026 reports 90% personalization satisfaction. Held below 75 because variant-level visual preview for arbitrary headless frontends remains less seamless than top-tier DXPs.
Kentico's own K13 migration guide states that A/B tests are not supported natively in Xperience by Kentico yet, and its feature-mapping guide routes A/B testing to the official VWO integration delivered through the built-in Tag Manager, with AI-driven experimentation only on the roadmap. The previous 55 relied on a claim of native page and email A/B testing that the product docs do not support; the docs corpus has no A/B testing feature at all. Scored 35 at the top of the external-tool band because VWO is a supported, first-party Tag Manager integration rather than a custom embed.
No evidence of a built-in algorithmic or ML-based content recommendation engine in Xperience by Kentico for audience-facing personalized recommendations. AIRA provides AI-assisted content operations (which belong in cat10) but not native recommendations served to site visitors. Recommendations would require a third-party engine or custom development.
Xperience by Kentico ships no search engine in core: Lucene.NET is an external Kentico-maintained module (NuGet, GitHub repo) that auto-indexes content through code-defined indexes and provides results retrieval. The March 2026 refresh let SaaS deploy without rebuilding Lucene indexes, an operational gain rather than a relevance one. Scored 42 at the low end of basic full-text, below the previous 48, because relevance tuning, faceting UI and autocomplete are all developer-built and the module is optional rather than built-in.
Official Algolia integration with code-first index creation, page content type indexing, .NET API, JavaScript API, and InstantSearch.js support is on Kentico's officially supported roadmap with a 7-day bug-fix policy. Azure AI Search is also a documented integration path with semantic and geo search capabilities. Held at 72 because configuration remains code-first rather than UI-driven.
Native digital commerce includes a product catalog, cart, orders, customers, multi-currency, a customizable price calculation pipeline, and catalog and order discounts. The September 24, 2026 refresh (31.9.0) added free-shipping promotions as a new pipeline step that store managers configure like the other discounts. Held at 59 because commerce is still a framework: the storefront UI, tax calculation and payment processing need custom implementation, unlike turnkey commerce platforms.
An official Shopify integration delivered as a NuGet package connects via Storefront and Admin APIs with product synchronization every 15 minutes, shopping cart management, discount coupons, and direct checkout on Shopify. The integration carries Kentico's 7-day bug-fix SLA indicating first-party support. Held at 65 because BigCommerce, commercetools, and Salesforce Commerce Cloud connectors are not documented as first-party.
Products are modeled as content items in the Content Hub rather than fixed SKU objects, giving fully customizable schema, versioning, localization, and workflow, plus taxonomy-based organization by category/brand/custom attributes and SEO-friendly descriptions reusable across channels. This is a stronger pattern than generic content types repurposed for products. Held at 65 because product-specific UI patterns (variant pickers, attribute matrices) still require developer setup.
Native analytics are marketing-centric: Customer Journeys give funnel-stage progression and drop-off analysis, emails get open/click statistics, Campaigns track conversion KPIs, and the contact activity log records page visits and form submissions per profile. Kentico's own feature-mapping guide sends web analytics to Google Analytics, GTM or Clarity through the Tag Manager, and the previous 68 cited Power BI reports and web analytics pages that belong to Kentico Xperience 13. Scored 55 because there is no native page-view or content-performance dashboard and no author-productivity or content-lifecycle metrics.
The built-in Xperience Tag Manager ships predefined snippet types for GA4, Google Tag Manager, Microsoft Clarity, VWO and Intercom per website channel. Official CRM packages for Dynamics 365 Sales and Salesforce Sales Cloud sync contacts both ways, and the Zapier module fires on contact and workflow events. Held at 62 because Segment, Amplitude and other event-streaming analytics connectors are not first-party, and content-operation event streaming requires custom global event handlers.
Xperience by Kentico supports multiple website channels under a single instance with a shared Content Hub, enabling reuse of reusable content items across sites while keeping per-channel page structures, locales, and publishing config independent. The architecture is regularly cited in customer multisite consolidations. Held at 70 because cross-site governance tooling (enforced component constraints, global style policies) requires developer configuration rather than first-class brand governance UI.
Content items, pages, emails and headless items have per-language variants with configurable fallback languages, per-language publishing, AIRA translation and taxonomy tag translations. The September 2026 refresh added language-specific domains per website channel, though only for new private-cloud channels, alongside the existing language-prefix URL format. Held at 70 because localization is variant-per-item rather than per-field shared/translatable control, and the domain-per-language format cannot be adopted by SaaS or already-live sites.
A Translations queue supports bulk and linked-item translation, and AIRA translates pages (including Page Builder content) and content items directly into new language variants. The XTM Cloud connector is built and listed by XTM, not documented in Kentico's own integrations list. Scored 58, below the previous 60, because Kentico documents no first-party TMS connector and Phrase, Smartling and Lokalise have none.
The Content Hub provides centralized content governance with RBAC across multiple website channels and headless channels. Shared component libraries (widgets, page templates) enable brand consistency, and channel-level permissions restrict editor access. Held at 62 because native multi-brand policy enforcement (enforced style guides, cross-brand approval gates) requires custom configuration.
Legacy Media libraries will be removed July 24, 2026, with the Content Hub serving as the unified DAM going forward: metadata schemas via content types, custom tagging/taxonomy, folder structures, asset reuse tracking, smart cropping with focal points, and AIRA-assisted auto-tagging. The Bynder integration extends to full enterprise DAM. Held at 62 because Content Hub assets do not support file versioning (only the latest file is retained) and rights/expiry management of purpose-built DAMs is still missing.
SaaS delivery runs through Cloudflare CDN. Content item assets support per-image format conversion to WebP and AVIF, quality and compression settings applied non-destructively to the original, and admin-defined image variants with aspect ratios and pixel sizes for art direction and resolution switching. Focal points can be set by keyboard or auto-selected by AIRA. The August 2026 refresh made variants generate on demand even in read-only deployments. Raised from 65 because modern-format support and responsive variants are documented, first-class features; held at 70 because variants are pre-configured presets rather than arbitrary URL-parameter transforms.
Videos can be uploaded and stored as content item assets in the Content Hub, but there is no native video transcoding, adaptive bitrate streaming, thumbnail generation, or captions management. Production video workflows require embedding YouTube/Vimeo or integrating Mux/Cloudinary. Scored at the low end for basic video upload/storage without native streaming infrastructure.
Page Builder provides drag-and-drop widget placement into configurable sections, in-context editing with live preview, non-technical page composition, and per-widget personalization variants. The May 2026 refresh added Management API support for Page Builder enabling programmatic component retrieval. Held below 75 because the .NET-rendered frontend is the first-class target; full visual editing of arbitrary headless React/Next.js frontends is not equivalent to Sitecore Pages or Contentful Compose.
Xperience by Kentico has marketer-configurable workflows with custom steps, role-based authorization per step, applied to reusable content, web pages, emails, and headless items. The July 2025 refresh added workflow step comments and notification emails for contextual handoffs. Held below 75 because multi-step parallel approval paths and SLA/due-date enforcement on tasks are not explicitly documented.
Pages and content items support scheduled publishing, scheduled unpublishing (with an optional redirect for pages), and cascade publishing that pushes unpublished linked items with the parent. Content Sync Detailed Selection (May 2026) promotes chosen items and their dependencies between environments. Held at 58 because Xperience by Kentico has no content calendar view and no first-class release bundles for atomic multi-item publishing.
Content locking now covers web pages, reusable content items and headless items (June 2026) plus emails, including their properties and plain-text tab (July 28, 2026 refresh). It has a role-based override and releases on publish, workflow change or revert, and basic overwrite protection applies even when locking is off. Workflow step comments add some asynchronous discussion. Still 40 because there is no simultaneous co-editing, presence indicators or inline commenting.
Form Builder covers custom forms, field visibility conditions (January 2026), smart fields that skip already-known contact data, autoresponders, consent capture, CAPTCHA, submission storage, CRM lead pushes and automation triggers. The August 20, 2026 refresh added CSV export of form submissions, with an Export permission, custom-component text extractors and an AfterExportListingEvent hook. Held below 70 because multi-step forms and full progressive profiling still need custom work.
Native email marketing capability with subscriber lists, email campaigns, Email Builder with widget personalization (June 2025), templated emails, autoresponders, and automation-triggered sequences. Native A/B testing for emails with built-in analytics. Held at 65 rather than 70+ because deep bidirectional sync with enterprise ESPs (Marketo, Salesforce Marketing Cloud, Mailchimp) as first-party connectors is not confirmed.
The native Automation Builder supports behavioral triggers, drip sequences with waits, rule-based branching, and scheduled time-based triggers. Custom automation actions shipped in June 2026, followed by custom triggers and custom conditions in the July 28, 2026 refresh, so processes can start from any project event (purchases, inbound webhooks) and branch on code-evaluated logic, and KentiCopilot skills generate these steps. Held at 66 because there is no native lead scoring (Kentico's own examples compute a contact score in a custom step) and multi-channel orchestration beyond web and email is thin.
Built-in CDP unifies customers, contacts, and members into a single profile with admin-configurable identity resolution (April 2026), new segmentation tools, and extensible APIs. Identity resolution matches on external identifiers or native fields (e.g., member email) to merge profiles across touchpoints, enabling unified data for personalization and automation. Held at 71 because external CDP connectors (Segment, mParticle, Tealium) remain absent and B2B firmographic enrichment is limited.
Community Integrations Hub offers official and community integrations across search (Algolia, Azure AI Search), commerce (Shopify), DAM (Bynder), CRM, analytics, optimization (VWO), and TMS (XTM). First-party integrations carry 7-day bug-fix SLAs, and Zapier extends to 6000+ apps. Held at 55 because the directory is smaller than Sitecore or AEM marketplaces.
Xperience by Kentico has no native outbound webhook system. Integrations subscribe to global system events (content, form and object events) in .NET code, and the Zapier module exposes contact-created and workflow-step events to external apps. The only webhooks in the product docs are inbound ones that start automation processes. Scored 42, down from 52, because topic selection, signed payloads, retries and delivery logs must be built by hand, and the earlier outbound-webhook claim does not appear in the product documentation.
Shareable preview URLs let people without admin access view unpublished pages and emails. The URLs can be revoked system-wide and invalidate when the canonical URL changes. The SaaS plan includes a dedicated STG environment, with Content Sync promotion between environments and granular dependency selection (May 2026). Page Builder gives in-context preview for .NET-rendered channels. Raised from 65 because shareable draft links are a documented first-class feature; held below 70 because preview is tied to Xperience-rendered channels rather than arbitrary headless frontends, and there are no per-branch preview environments.
Custom role definition, ACL-based web page permissions, channel-level access control, content-type and workflow-step role assignments, and SSO via any OAuth/OIDC provider (Microsoft Entra, Okta, Auth0, Duo) are supported. Xperience Portal access is managed via Auth0 RBAC. Held below 70 because field-level permissions and SCIM provisioning for user lifecycle management are not confirmed as built-in features.
Content delivery for headless channels is a GraphQL API per channel with an auto-generated schema, API-key security and a built-in query browser; .NET consumers get the Content Item Query API and IContentRetriever (which gained IncludeContentTypeFields projection in v31.7.0). The previously credited 'preview Headless REST API' could not be found anywhere in the changelog or docs and has been removed; the only REST surfaces are headless tracking and the OpenAPI-described Management API, which is scoped to local development. Not higher because GraphQL is retrieval-only with no mutations or subscriptions and there is no REST content delivery API.
GraphQL responses are dynamically cached, EnableUnionQueryOptimization prevents timeouts on fields linking many content types, and SaaS plans include a CDN with dynamic routing (100 GB on standard plans). 2026 Refreshes fixed several retrieval performance problems, including language-fallback queries where fetching one item by GUID cost as much as fetching every item of the type. Not higher because there are no published delivery rate limits, response-time targets or large-dataset sync patterns.
The only official content SDK is .NET (Kentico.Xperience.* NuGet packages), which is well maintained with typed generated classes and LINQ-style queries. The npm package @kentico/management-api-mcp is an MCP server for AI agents, not a content delivery client. JavaScript, Python and mobile consumers have to call the GraphQL endpoint directly with no official client library.
The Community Integrations Hub lists NuGet-distributed integrations from Kentico, partners and the community. Official packages cover Algolia, Azure AI Search, Zapier, Tag Manager (GA4/VWO/Intercom/Clarity) and Application Insights, and the SaaS plans include CDN, SendGrid email and WAF. The KentiCopilot repository adds AI coding plugins but not customer-facing integrations. Not higher because the catalog is small, with thin DAM and translation-service coverage compared with larger ecosystems.
Extensibility is deep and .NET-based: custom modules and object types, global event handlers, Page/Form/Email Builder components, custom data types and React admin UI pages. The Refreshes since July added custom Marketing Automation triggers and conditions (v31.7.0), custom data types in reusable field schemas (v31.8.0), and an opt-in CSV Export action for any admin listing page (v31.9.0). The main constraint is that every extension requires C#/.NET and React skills; there is no low-code path.
Admin SSO works with any OAuth/OIDC provider, with documented setups for Entra ID, Auth0 and Okta, but only one external provider can be active at a time and SAML is not supported natively. Admin MFA and token-bucket rate limiting protect the user-management endpoints, and the headless API uses API keys. Scored down because a second authentication-flow advisory followed the May MFA bypass: an account-recovery flaw (CVSS 8.6, v22.0.0–31.8.4, self-hosted only) that could grant unauthorized admin access.
RBAC supports custom roles with application-level permissions, per-page permission management in the content tree, and workspaces that scope Content hub access. There are no field-level permissions, and a September 2026 IDOR advisory (CVSS 7.1) showed workspace boundaries could be crossed for limited metadata and folder moves. Stays at 65: custom roles with content scoping, but without field-level control.
Xperience by Kentico SaaS is ISO 27001 certified and SOC 2 Type II audited, with evidence, pentest reports and policies in a SafeBase Trust Center. SaaS plans include WAF, DDoS and bot mitigation, database encryption, and region choice across NA, EU and APAC Azure regions. Not higher because no HIPAA BAA is documented.
The 2026 advisory wave has continued past the May SQL injection (CVSS 9.4) and MFA bypass (8.6). Since July there have been three more SQL injections (segments builder 8.6, content sync 7.5, a macro 8.6), arbitrary file read through Email Builder MJML includes (7.1), shared-cache exposure of authenticated assets (8.2), an account-recovery admin takeover (8.6) and a workspace IDOR (7.1). Most issues span v22.0.0 to the current release. Communication is good: dedicated advisories with researcher credit and fast hotfixes. It is penalized for sustained frequency and severity in the active product line, on top of the older KX13 CVEs in CISA KEV and a disclosure program with no paid bounty.
Three deployment options: Kentico-managed single-tenant SaaS on Azure (NA/EU/APAC), documented private cloud deployments on Azure or AWS (S3 file providers), and standard self-hosted ASP.NET Core, including containers. The feature set is the same across models; v31.9.0 added language-specific domains specifically for private cloud channels. This option set suits regulated buyers, but SaaS is Azure-only.
The SaaS service plan table lists 'Uptime Service Level Availability: Designed for 99.9%'. SaaS also includes 24/7/365 availability management, root cause analysis, a public status page with opt-in notifications (status.xperience-portal.com), and per-channel uptime checkers. Down 2 because the uptime figure is a design target, not a contractual SLA with credits, and 99.9% trails the 99.95%+ tier.
Multi-instance ASP.NET Core deployments are supported with shared storage and server synchronization tasks, and SaaS includes a CDN with dynamic routing. Standard SaaS plans describe auto-scaling as 'temporary... in case of a rare peak in workload', not elastic scaling. Several 2026 fixes addressed multi-instance sync tasks piling up and timing out deployments and updates. No scale limits or enterprise benchmarks are published.
Kentico publishes SaaS targets of RTO ≈ 1 hour and RPO 1–24 hours with annual DR testing. Production and staging database and blob storage are backed up daily and geo-redundantly, with self-service restore points, exports and on-demand backups in Xperience Portal. Not higher because standard plans keep daily backups for only 3 days (7 on Custom) and weekly backups for 30, and the RPO can be as long as 24 hours.
The full platform runs locally from dotnet new templates with production parity, hot reload and .NET CLI code generation. Since July: the Management MCP server went GA for local agentic development and can start before the host app; the Dancing Goat template ships with preconfigured MCP servers and instruction files; and a --kxp-db-status command reports database readiness. Not 70+ because a local SQL Server is required and there is no lightweight emulator.
Continuous Integration serializes database objects to XML for source control, and Continuous Deployment restores them to target environments. SaaS offers QA, optional STG and (on Custom plans) UAT environments, a deployment API with personal access tokens, zero-downtime slot-swap deployments and content sync between instances. The new --kxp-db-status command lets pipelines branch on database state, and the KentiCopilot project-lifecycle plugin generates CI/CD repository configuration. Not higher because there are no branch-per-PR content environments or standalone schema migration CLI, and content sync broke in 31.8.0 until hotfix 31.8.1.
docs.kentico.com is comprehensive and current: detailed changelogs per Refresh and hotfix, dedicated security advisories, API reference, guides, and the Learn portal. Every page is also available as Markdown, with llms.txt indexes and whole-area llms-full.txt dumps for AI tooling. Not higher because code samples are C# only and there is no interactive playground beyond the per-channel GraphQL browser.
There is no first-party TypeScript SDK or type generation from content schemas; type safety comes from C# classes generated by the .NET CLI. TypeScript/React is used only for admin UI extensions, whose shared React Router dependency moved to v7 in v31.8.0. Frontend teams using the GraphQL API have to rely on third-party GraphQL codegen.
The official changelog shows a named Refresh every month of 2026 so far (Jan 22, Feb 23, Mar 23, Apr 16, May 14, Jun 29, Jul 28 31.7.0, Aug 20 31.8.0, Sep 24 31.9.0). Weekly hotfixes, SaaS updates and AIRA model updates land in between (31.8.1–31.8.4 in Aug–Sep). Each Refresh ships real features: the Sept one added Management MCP tool groups, free-shipping promotions, CSV export on every listing page and a DB status CLI. Not higher because individual Refreshes are incremental rather than platform-shifting.
The docs changelog is a single versioned feed with fixed sections per release: New features, Updates and changes, Known issues, Manual update steps, Newly obsolete API, Fixed issues, and Fixed issues – security, which links to a dated security advisory. Upcoming removals are announced ahead of time with migration guides (media libraries → Content hub assets, .NET 8/9 end of support, KX13 end of support). The whole feed is also published as Markdown. Not higher because there is no per-change machine-readable feed or codemod linkage.
Kentico maintains a public product roadmap at roadmap.kentico.com with 'Released', 'In Preview', and 'Planned' tabs visible to all. Regular community blog posts provide roadmap Q&A and expert chat series. The CEO published a public 2026 outlook. Not scoring 85+ because community voting/Canny-style prioritization is not strongly evidenced.
The published support policy guarantees at least 12 months of backward compatibility after a feature is deprecated or an API is marked obsolete, with the replacement running alongside it. Each release lists its obsolete APIs. Removals are staged: media library support ended Jul 24, 2026 and the removal was then postponed past the Sept Refresh. Migration tooling covers the KX13 exit (Migration Tool plus the KentiCopilot kx13-migration plugin). Not higher because AI tooling (Management MCP/API) is explicitly exempt and was renamed without notice in 31.9.0, and 31.8.0 shipped a content sync regression that needed a hotfix four days later.
Kentico runs a community portal (community.kentico.com) with MVP and Community Leader programs, and active GitHub repositories (e.g., Kentico/community-portal). The platform has ~10,000 customers and 355 G2 reviews (substantial for a DXP), but GitHub star counts are modest given the .NET/commercial nature of the product. Not a large open-source community.
The community portal publishes content on a sustained near-monthly cadence (through the June 29, 2026 Refresh), runs an MVP/Community Leaders recognition program that grew its cohort into 2026, and held Community Program Summits in 2026. Kentico team members actively contribute to the community blog and run UX feedback and early-access sessions with program members. Engagement appears genuine for a mid-market B2B product; forum response times not independently verified.
Kentico has a formal partner program with certified agencies and an annual Partner Connection conference (Prague 2025). The website lists partner integrations created by Kentico, partners, and community. No evidence of major global SIs (Accenture, Deloitte) at the level of tier-1 DXPs, but a solid mid-market agency network is evident.
There is a reasonable volume of community tutorials, blog posts, and YouTube content (especially from partners), but Xperience by Kentico is not widely covered on Udemy or Pluralsight. The platform is .NET-specific and mid-market, limiting the breadth of third-party educational content compared to larger open-source or headless platforms.
Kentico targets the .NET/C# developer ecosystem, which is large in absolute terms but niche for DXP specialization. A certification program exists, and LinkedIn shows active job postings for Kentico developers particularly in mid-market agencies. Not widely recognized in Stack Overflow developer surveys, limiting talent pool compared to platforms like Drupal or WordPress.
Kentico reported 2025 revenue of $56.7M, up 35% from $42M in 2024, plus record ARR growth driven by Xperience by Kentico SaaS uptake. CMS Critic and eCommerceNews both carried it, though the figures are self-reported. G2 Leader status continued into the Summer 2026 DXP grid. Part of the growth is a captive migration of KX13 customers ahead of its Dec 31, 2026 end of support, and enterprise logo announcements remain sparse.
Kentico is privately held and backed by Expedition Growth Capital (2022). It reports $56.7M revenue in 2025 (+35%), a stated focus on profitability, and roughly 226 employees, with no layoff reports found. The CEO's year-end 2025 letter describes steady execution through a soft US market. Not higher because there is no recent growth round and all financials are self-reported.
Xperience by Kentico holds G2 Leader status in DXP (through the Winter 2026 report), Gartner Peer Insights 4.5/5, and Info-Tech Research Group Champion (Composite 8.3/10, NPS +77, 85% likely to recommend). The platform differentiates on ease of use, .NET developer experience, and mid-market fit with integrated digital commerce and agentic AI (AIRA). Not in the 80+ tier because Gartner Magic Quadrant inclusion is not confirmed.
The G2 listing (~355 reviews) is rated about 4.4/5 in current reports, with a high share of 4–5 star reviews and strong ease-of-use and support scores. Gartner Peer Insights averages about 4.5/5 and the Info-Tech NPS is +77. Scored at the low end of the 75–85 band because the G2 average sits just under 4.5 and the listing mixes KX13 and Xperience by Kentico reviews. No systemic pricing or reliability complaints were found.
Kentico's official How to Buy page (now kentico.com/platform/how-to-buy; /pricing redirects there) lays out the four-step structure — channels, Standard vs Advanced tier, AIRA credit package, SaaS cloud level — but a fetch on 2026-09-28 found no dollar figures and no pricing PDF link, and every path ends in 'Speak to an expert'. The widely quoted 'from $990/mo self-managed, $1,990/mo SaaS' figures now come only from third-party listings, so buyers can see the price structure but not verifiable vendor prices. Not lower because the structure is public and third-party starting prices are consistent across sources.
Fixed-cost SaaS subscription based on pre-defined cloud levels avoids consumption spikes — a strong predictability signal — and channel-based licensing (one main channel included, add-ons for more) is predictable for most buyers. Newer AIRA/Agentic Marketing Suite runs on a credit consumption model with a monthly allocation plus opt-in expansion, introducing a metered element that a new Usage tab helps track. Penalized for multi-channel and AI credit add-ons that may not surface until scoping.
Standard tier covers single-channel web projects; Advanced tier unlocks multi-channel and enhanced digital marketing features, and AIRA (agentic AI marketing) is a separate paid credit add-on that launched Feb 1, 2026 with pricing not public. Splitting multi-channel and AI marketing behind higher tiers/add-ons is a meaningful gate for real DXP use cases, though core CMS functionality is accessible at the base tier.
Pricing is annual-only (third-party minimums ~$23,880/yr SaaS, ~$11,880/yr self-managed) with no monthly billing option, and no startup, nonprofit or education program is documented publicly. G2 reviews cited by 2026 pricing analyses flag recurring subscription increases, with some reporting annual hikes of up to 25%, and no exit provisions are published beyond the trial. Enterprise DXP norm, but rigid next to SaaS competitors with monthly terms.
Only a 7-day hosted trial and a 30-day local evaluation license are available; there is no permanent free tier and the core platform is not open source (though Kentico publishes MIT-licensed companion repos). Compared to open-source DXPs like Drupal or headless CMS with free-forever tiers, this is a significant gap for solo developers or small teams evaluating the platform.
SaaS cloud infrastructure is described as ready in 30 minutes, and the Kickstart .NET CLI workflow gives developers a running local instance quickly. However, content type modeling, channel setup, and Kentico-specific conventions add a half-day to full day before a working site is live for an experienced .NET developer. The ongoing monthly refresh cadence (Mar/Apr 2026 releases) keeps shipping DX improvements but doesn't fundamentally accelerate first-value.
Partner reports place typical KX13→XbK migrations and agency implementations at 3–6 months and 6–12 months for highly customized/enterprise scopes, with KX13 end-of-life on Dec 31, 2026 driving a wave of time-sensitive replatforming. Migration is a controlled replatform (not an upgrade) requiring custom code to be rewritten for .NET Core, adding months to brownfield projects; greenfield .NET shops trend faster. Scores near the DXP average — adequate but not strong.
.NET/C# is mainstream, which limits the talent premium versus proprietary-language DXPs like Sitecore or AEM. However, Kentico-specific certification, proprietary content modeling conventions, and the relatively niche XbK platform mean a moderate premium over generic .NET developers. Dedicated certification programs and specialist consultancies confirm a non-trivial expertise gap.
The SaaS tier bundles hosting (pre-defined Cloud Levels) into the subscription with no additional infrastructure spend, while the self-managed tier requires customer-provisioned Azure/AWS hosting estimated at $10K–$30K/yr additional. For buyers choosing SaaS — the primary positioning and starting point in Kentico's published pricing — hosting is included and fixed-cost.
SaaS deployment is fully managed — no server patching, scaling, or monitoring burden — with the monthly refresh cadence auto-applied to SaaS tenants. Content ops still require trained editors and periodic upgrade attention, and self-managed adds DevOps overhead. Scoring reflects the SaaS majority path; ops burden is modest compared to on-premise DXPs like AEM or HCL DX.
Kentico provides an open-source Migration Toolkit on GitHub and supports content/data export, reducing content migration costs materially. However, code migration is explicitly not handled — all bespoke development must be manually rewritten on exit or version upgrade — and proprietary content modeling plus API conventions create moderate data-layer lock-in.
XbyK uses ASP.NET Core MVC patterns that map well for .NET developers, but developers must learn platform-specific abstractions: Page Builder (widgets, sections, templates), content types vs. page types vs. reusable content, channels, and a proprietary content repository API (not Entity Framework). The certification exam covers content modeling, custom modules, Page Builder, and CI/CD — a non-trivial concept surface, and KentiCopilot AI scaffolding helps navigate but does not reduce it. Cleaner than KX13's Portal Engine hybrid but still meaningfully proprietary.
Kentico maintains a structured Developer Learning Map, Developer Kickstart guide, training-guides repo and a Certified Developer path, and has layered AI-assisted onboarding on top: the KentiCopilot marketplace was reorganized in July 2026 into workflow plugins (kentico-web-development walks agents from wireframe through bootstrapping, content modeling and implementation), and the Management MCP server came out of preview on Sept 3, 2026 (31.8.3) with a recommendation to use it on all projects. Not higher because there is still no in-app interactive developer tour and no framework-specific (Next.js) guided learning path.
The primary development model is ASP.NET Core MVC (new projects target .NET 10 since 31.0.0), which is mainstream in enterprise .NET circles but a non-starter for JS-only developers. Headless delivery is a GraphQL channel (Hot Chocolate) that supports decoupled Next.js builds, but Kentico maintains no Next.js/React starter or SDK, so that path is community-documented and secondary. The platform uses its own content retriever API rather than a standard ORM, and Page Builder widget registration is proprietary.
The .NET CLI project templates were substantially modernized in 2026: the August 20 refresh (31.8.0) rebuilt Dancing Goat with Tailwind CSS, an esbuild pipeline, reworked Page Builder content, better SEO, and pre-configured MCP servers plus AI instruction files, and moved all templates to Central Package Management. The September 24 refresh (31.9.0) updated its visual design again. Alongside xperience-component-starter and the Admin Design Components reference project, this is a real example-content starter. Not higher because there is still no vendor-maintained Next.js/Nuxt/Astro starter for the headless channel.
Setup requires the .NET SDK, .NET CLI template registration, SQL Server provisioning, and admin/presentation wiring, which is moderate for experienced .NET developers. 2026 tooling trims friction: templates use Central Package Management, the KentiCopilot project-lifecycle plugin generates CD repository.config, and 31.9.0 added a --kxp-db-status command so scripts and agents can check database readiness without starting the app. That same release made SystemEmailOptions.ServiceDomain or AllowedHosts mandatory on self-hosted projects for user-invite and password-reset emails, adding one more non-obvious config value, so the score holds.
XbyK uses a structured content type system with code-generated C# models, making schema changes type-safe and refactorable, with CI/CD serialization for schema-as-code. The Management MCP server (GA Sept 2026) manages content types, reusable field schemas, and as of 31.9.0 custom module classes and UI forms. 31.8.0 also let custom data types be used in reusable field schemas. There are no documented severe field-count limits, but the reusable-content vs. page vs. headless-item split needs upfront planning, and media library removal forces an asset-model migration on older projects.
Page Builder has built-in preview and edit modes plus a read-only inspection mode, so editors preview unpublished changes at high fidelity with no extra developer work on the standard ASP.NET Core presentation model. Headless channels only provide a configurable Preview URL button: the Next.js side still needs custom middleware to fetch draft content over GraphQL, and there is no visual editing for headless. Not higher because the plug-and-play path covers only the .NET MVC model.
A Certified Developer exam still exists and is strongly expected for agency partners, covering Page Builder internals, custom modules, content modeling, GDPR, and CI/CD — not just general .NET skills, and the platform remains inaccessible to JS/Python-only developers. Kentico's 2026 AI-dev push (KentiCopilot skills, MCP servers, Claude Code/Cursor/Copilot support) explicitly aims to 'lower the seniority bar,' modestly reducing the platform-specific expertise needed before first delivery. Not higher because the proprietary Page Builder/module model and certification expectation persist.
XbyK is designed for professional development teams, not solo developers. Migration guides reference 3–6 month timelines (6–12 for large/customized solutions) and costs from $10K to $150K+, implying dedicated dev + ops + solution architect roles. The architecture (Page Builder, custom modules, SQL Server, CI/CD, two-application topology) typically needs a 2–3 person team minimum; solo deployments are possible for simple sites but not typical.
Page Builder lets marketers self-serve page layout, widget placement, and content edits post go-live, with read-only inspection reducing editor friction, and AIRA now assists marketers directly: the April 2026 refresh added SEO & GEO Specialist and Campaign Manager agents plus segment-condition building, and the May 14, 2026 refresh (31.5.0) extended AIRA text-field assistance across all content type targets including headless items. Not higher because new widget types, page templates, and new content types still require developers.
Monthly Refreshes shipped every month of 2026 (31.7.0 Jul 28, 31.8.0 Aug 20, 31.9.0 Sep 24) as NuGet package updates plus a database update, and 31.9.0 added a `--kxp-db-status` command so pipelines can detect a required database update without starting the app. But updates are not frictionless: 31.5.0 bumped Microsoft.Data.SqlClient across majors 6 and 7 with possible breaking changes, and upgrading to 31.7.0–31.7.3 could fail with a command timeout on databases with many orphaned sync tasks (the fix is to skip to 31.7.4). Not higher because every update, even on SaaS, needs a developer to update NuGet, update the database and redeploy.
Kentico has published at least one security advisory almost every month of 2026 for its own codebase, most rated high: SQL injection in Form Builder (CVSS 8.7, Jun 4), Segments condition builder SQLi (8.6) and content-sync SQLi (7.5) (Jul 9), macro input validation (8.6, Aug 13), shared-cache leakage of media resources (8.2, Sep 10), and an account-recovery flaw (8.6, Sep 24). That follows May's critical 9.4 admin-UI SQLi. Most affect every version back to 22.0.0, and the only fix is updating to the latest version, so each one means a NuGet update and a redeploy. Not lower because advisories are clear and scoped, fixes ship within a week through hotfixes, Kentico runs the SaaS infrastructure, and some flaws (e.g. the Sep 24 account-recovery issue) did not affect SaaS.
Kentico publishes a support policy guaranteeing at least 12 months of backward compatibility after a deprecation. Media Libraries followed it: marked obsolete in 30.8.0 (Jul 2025), support ended Jul 24, 2026, hidden in 31.8.0 for projects that don't use them, and full removal, first planned for the September Refresh, has been postponed. There is a migration guide to Content hub assets. Separately, projects must move to .NET 10 before .NET 8/9 lose Microsoft support on Nov 10, 2026. The Management MCP/API, which left preview in 31.8.3, is explicitly exempt from the policy and can break without notice. Not higher because a forced media-asset migration and a framework retarget both land in 2026.
On SaaS, Kentico runs the infrastructure dependencies (Azure SQL, Blob Storage, Cloudflare CDN). The application layer is still an ASP.NET Core/NuGet tree whose version must match the database, and 2026 forced several dependency moves: Microsoft.Data.SqlClient 6→7, a HotChocolate GraphQL security update, repeated transitive-dependency vulnerability hotfixes, and a required .NET 10 retarget by Nov 2026. Not lower because SaaS removes the infrastructure burden and Kentico documents how it handles transitive vulnerabilities; not higher because version-locked NuGet and database updates add friction every month.
Xperience Portal gives SaaS customers custom uptime checkers with alerting (added April 2026, with an admin/logon checker created automatically for existing projects), metrics for server errors, response time, CPU and memory, and a Security events view of Cloudflare events. Application Insights is bundled, AIRA credit use appears on a Usage tab, and 31.9.0 made the event log exportable to CSV by default. Not higher because self-hosted and private-cloud deployments have no built-in monitoring, and SaaS customers still need their own application-layer APM and alert tuning.
Built-in workflows, content locking (June 2026), form usage tracking ('Used in' tab) and the AIRA agents (Content Strategist, SEO & GEO Specialist) reduce day-to-day editorial overhead, and 31.9.0 adds CSV export on listing pages, which helps with manual audits. There is still no native broken-reference detection, orphaned-content alerting, stale-content identification or content health dashboard, so hygiene remains manual or depends on paid third-party tools such as Siteimprove. Not lower because locking and the AIRA agents lighten the load; not higher because content hygiene is not automated.
SaaS deployments get Cloudflare CDN edge caching, DDoS protection and Kentico-managed scaling, and Portal response-time metrics show degradation without extra setup. Output caching and cache dependencies are still the developer's job, and 31.9.0 fixed a memory leak in the cache-dependency Tag Helper, a reminder that app-layer caching needs attention. Not higher because output caching and SQL tuning remain the customer's responsibility, and self-hosted deployments need full tuning.
G2 reviewers keep Xperience by Kentico in Leader status (Winter 2026), with about 98% rating it 4–5 stars and 92% recommending it, and 'ease of support' is one of its best-scoring areas. Reviews repeatedly mention fast responses from in-house engineers, and both Standard and Premium tiers include 24/7 support. Not higher because a dedicated CSM and the best SLA terms require Premium, and some reviewers want faster turnaround on development-service requests and more detailed technical documentation.
The Kentico Community Portal has a Q&A forum where Kentico staff answer questions, a monthly Refresh blog (most recently September 24, 2026) and an MVP/Community Leaders program, and the open-source KentiCopilot plugins and Migration Tool on GitHub add another place to get help. The community is still small compared with WordPress, Drupal or the large headless CMS platforms, so niche integration questions often go without an answer. Not lower because staff take part actively and the monthly releases keep developers informed.
Weekly hotfixes (four per Refresh cycle through 31.8.4) deliver bug and security fixes quickly with a detailed list of fixed issues each time, and every 2026 security advisory shipped with a patched version the same day. Reviewers praise how fast fixes arrive. Not higher because the volume of recurring high-severity flaws suggests QA debt, and some hotfixes caused new problems (e.g. the 31.7.0–31.7.3 update timeout) that needed further fixes.
Xperience by Kentico includes a Page Builder with drag-and-drop widget placement and pre-defined page templates, enabling marketers to create landing pages from existing templates without developer involvement. Version history for pages (March 2025) allows marketers to restore prior widget configurations. Content sync enables staging-to-production promotion with one click (May 2025). Developers must define new layouts and widgets first, so net-new page structures still require developer work. Scores at the lower end of the 65+ tier.
A dedicated Campaigns feature (March 2026) combines campaign briefs, associated digital assets, and linked customer journeys with AIRA Campaign Insights for AI-driven KPI evaluation. The May 2026 refresh added a guided campaign-brief authoring flow: the Campaign Manager Agent asks marketers a structured series of questions (brand, goals, audiences, KPIs, channels, messaging) and restructures the answers into a formatted brief. The production-ready Campaign Manager Agent (April 2026) evaluates campaign performance against KPIs, audience groups, and journey metrics and generates final reports comparing success across multiple campaigns — a significant step toward portfolio-level campaign orchestration. Email Builder (production March 2025) provides visual drag-and-drop email authoring. Marketing automation with conditional branching is native. Multi-channel coordination and a dedicated content calendar UI are still absent.
The SEO & GEO Specialist Agent (April 2026, production-ready) reviews pages for both classic SEO attributes and AI readability/comprehension, provides keyword-based scoring and prioritized recommendations — closing the previously noted gap of no in-box SEO audit/scoring tool. Multiple vanity URLs per page with canonical URL selection (June 2025), URL management application for centralized redirect management (May 2025), and forward-slash support in custom URLs (July 2025) give solid SEO URL hygiene. Standard meta title/description fields are on all content types. The community XperienceCommunity.SEO package adds automatic sitemap generation, dynamic robots.txt, and llms.txt. GEO scoring for AI crawler readability is a forward-looking differentiator.
Native Form Builder supports lead capture with validation rules, conditional logic, and field visibility conditions (January 2026). Lead scoring, email marketing, and marketing automation with value-based activity signals (January 2026) are all native. 'Used in' tracking shows which pages each form appears on across channels. Form Builder improvements shipped October 2025. Form submissions can be exported to CSV (August 2026), and the official CRM package pushes form submissions to Salesforce or Dynamics as leads. Not a marketing automation powerhouse, but well above headless CMS baseline with genuine out-of-the-box lead capture, scoring, and nurture.
Identity Resolution (April 2026, production-ready) unifies customer, contact, and member profiles under single identities and automatically merges profiles when visitors log in with existing accounts — a meaningful upgrade from the earlier preview-only CDP unified profiles. AIRA Segment Condition Builder (April 2026, production-ready) uses AI to assist marketers in defining complex multi-rule segment conditions. Widget-level personalization in Page Builder delivers separate content variants per contact group based on behavioral, demographic, and activity-based segments. Email widget personalization (June 2025) allows per-segment email variants. Membership Roles (March 2026) enable tiered channel-specific content access. No full page-level rules engine or real-time behavioral personalization yet.
Xperience by Kentico has no native content-level or server-side A/B testing — all first-party A/B testing documentation still references legacy KX12/KX13 only, and the XbK changelog contains no native experimentation feature. However, Kentico now maintains an official Tag Manager package (github.com/Kentico/xperience-by-kentico-tag-manager) that lets marketers enable a VWO integration directly from the administration UI, injecting VWO SmartCode into a website channel for front-end A/B testing and experimentation (added December 2025). This is client-side experimentation via a tight third-party integration: experiment design, targeting, and statistical significance/winner selection all live in VWO's own platform, and the integration can manipulate only front-end data (no backend experimentation). Email Builder subject/content variants remain per-segment personalization, not statistically validated experiments. This fits the 'experimentation via tight integration' tier at the lower end — a real optimization path exists, but nothing native or content-model-aware.
Page Builder with template-based page creation, version history for pages, content sync from staging to production (May 2025), and shareable preview URLs (December 2025) support a reasonable content velocity workflow. AIRA inline text generation and transformation was expanded to text fields across all content type targets including headless items (May 2026), extending assisted authoring beyond the rich text editor. Content overwrite protection (May 2026) and globally configurable content locking (June 2026) prevent lost edits and rework from concurrent editing, and a content reuse locator surfaces cross-channel usage during editorial decisions. Drag-and-drop asset uploading during content creation (November 2025) reduces friction. 'Save and create another' (August 2026) creates the next page or content item with the previous page's content type, template and tree position already filled in, which speeds up batch authoring. Content locking was extended to emails (July 2026). True bulk editing is still not featured, and new page types still require developer setup of widgets.
XbK natively supports website channels, email channels (Email Builder), and headless delivery via GraphQL for mobile apps and SPAs — covering web, email, and headless channels from a single content hub. Order status notifications extend commerce content to transactional email channels. Structured content in the Content Hub enables reuse across any API-connected surface. Social media publishing from KX13 was not ported to XbK. Native 4+ channel support without social.
The official Tag Manager package (github.com/Kentico/xperience-by-kentico-tag-manager) lets marketers enable Google Analytics 4, Google Tag Manager, and Microsoft Clarity (session recording, heatmaps, scrollmaps) directly from the administration UI per website channel — first-class configuration of standard analytics tags without developer template edits, though the metrics themselves still live in the external tools. In-platform, customer journey analytics (March 2025) visualizes contact progression and drop-off through journey stages with date-range filtering, AIRA Campaign Insights evaluates KPI performance across campaigns (March 2026), and the Campaign Manager Agent (April 2026) generates final reports comparing success across multiple campaigns. Form submission tracking with channel and language metadata (October 2025) surfaces form performance. Still no native web analytics module comparable to KX13's visitor tracking — page views, sessions, and source attribution remain in GA4/GTM.
Widget-based Page Builder naturally constrains authors to developer-defined components — marketers can only place pre-built widgets, preventing arbitrary HTML or off-brand layout choices. This enforces structural consistency indirectly. However, there is no platform-level design token management, approved color palette enforcement, or style locking system. Brand consistency relies on developers building a constrained widget palette and CSS, not on platform-enforced guardrails. Moderate consistency through architectural constraint, not explicit brand governance tooling.
The social media publishing module from KX13 (Facebook/Twitter/LinkedIn posting, analytics) was not ported to Xperience by Kentico. Standard meta fields on content types support Open Graph and social card metadata through developer-configured fields. No dedicated social scheduling workflow, push-to-social workflow, or social preview management UI exists in XbK. Authors can configure OG meta fields but there is no native social channel integration beyond standard meta tags.
Content Hub replaced KX13's media library as the centralized asset repository with taxonomy-driven organization, AIRA auto-tagging of images (March 2025), AI focal point detection for smart cropping (February 2025), dimension-specific image variants, auto-scaling on upload (April 2025), CDN link generation, and 'Used in' tracking to see where assets are referenced. Media library support ended July 2026 and the libraries are hidden in the admin UI (August 2026); their removal was postponed. Bynder DAM official connector covers enterprise DAM needs. No built-in rights management or video transcoding, but meaningfully above basic media library tier.
Language variants are available on all content types — pages, reusable content items, headless items, and products. Language fallback prevents blank content. Translation workflow with multi-step review and approval is built in. Phrase Localization Platform and XTM Cloud official connectors support professional TMS-driven translation workflows. Admin UI fully localized (July 2025). AIRA provides translation assistance. Per-channel language strategies allow separate locale approaches per brand/region. Limited locale-specific campaign calendar or transcreation workflow tooling — localization applies to content generally, not with marketing-specific campaign variant management.
Kentico maintains an official, fully supported CRM integration (github.com/Kentico/xperience-by-kentico-crm, 7-day bug-fix policy, active September 2026) with plug-and-play packages for Salesforce Sales Cloud and Microsoft Dynamics Sales. It sends form submissions to the CRM as leads and shows sync status in the admin UI. Earlier scoring runs missed this connector, so the old claim that XbK had no Salesforce connector was wrong. The official Tag Manager package covers analytics and engagement tags (GA4, GTM, Clarity, VWO, Intercom). Bynder (DAM), Phrase/XTM (localization), Campaign Monitor (email sending) and Zapier round out the pre-built connectors. Marketing automation became much more extensible in 2026: custom actions (June 2026), then custom triggers and custom conditions (July 2026). All three show up in the marketer's Automation Builder, and triggers can start processes from external-system inputs or purchases. There is still no MAP connector (Marketo, HubSpot, Pardot), no CDP or ad-platform connector, and no native outbound webhooks. The CRM connector syncs leads one way and does not sync contacts both ways. Pre-built connectors now cover CRM, analytics/tags, DAM and email, with code-level event triggers, which puts this item in the middle of the 35–55 band.
Products are managed as content types in the Content Hub, allowing reuse of descriptions and assets across websites, emails, mobile apps, and headless channels — production-ready as of July 2025. Content-type architecture is flexible: physical goods, digital goods, memberships, and gated content are all supported. However, the framework is architecturally modern but less feature-complete than KX13's mature e-commerce module — dedicated attribute modeling depth, product bundle configuration, and product taxonomy richness require custom implementation. Not a purpose-built PIM.
Kentico's native digital commerce includes catalog discounts, order discounts (December 2025), and generic coupon codes (January 2026), plus order and customer management applications — more than most CMS platforms. However, dedicated merchandising tooling — category page ranking, search result merchandising, cross-sell/upsell content surfaces, product spotlight modules — is not evident. The commerce framework remains extensible but thin on native merchandising UI for non-developers. No 'Buy X Get Y' or product bundle discounts yet (these existed in KX13).
XbK's digital commerce is a native framework, not an integration layer for leading external commerce platforms. No native connectors to Shopify, commercetools, Salesforce Commerce Cloud, or BigCommerce are confirmed. The extensible architecture supports custom ERP/PIM/CRM connections via API but these are custom integration work. Commerce Migration Tool added support for migrating KX13 customers and orders (January 2026) — this is a legacy migration path, not live federation with third-party commerce platforms.
Because products are modeled as content types in the Content Hub, Page Builder pages can blend editorial content and product references in the same authoring surface — buying guides, feature spotlights, and product-adjacent editorial are structurally natural. However, there are no first-class shoppable content patterns: no 'shop the look' widget, no inline add-to-cart embedded in editorial content, no lookbook authoring mode. Editorial-commerce blending is architecturally possible but not an out-of-the-box authoring pattern for non-developers.
XbK's checkout is a developer-configured flow with configurable extension points — the IOrderCreationService orchestrates order creation (October 2025). Trust badges, shipping callouts, or upsell banners within cart/checkout are not managed from the CMS as a first-class feature. Content from the Content Hub could theoretically be injected into checkout templates via developer code, but there is no marketer-facing UI for cart content management. Commerce content lives in the Content Hub but transactional flow customization is developer territory.
Order status email notifications are managed from the CMS via the Email Builder with commerce-specific merge tags/placeholders (June 2025). Order confirmation, processing, and delivery status emails can be designed and managed by marketers using the visual email builder. Beyond email notifications, post-purchase content (product onboarding sequences, review solicitation, loyalty content) is not featured as a native capability — it would require custom marketing automation sequences.
Membership Roles (March 2026) enable gated content access by role, which can be applied to restrict product catalogs or pricing content to authenticated B2B buyers. The content-type product model supports custom pricing tiers via the extensible pricing pipeline. However, there are no purpose-built B2B commerce features: no account-based pricing portal UI, no RFQ/quote workflow, no buyer/seller account hierarchy, no gated spec sheet management system. B2B patterns are achievable with significant custom development.
Core XbK has no built-in site search. Kentico does ship three official, fully supported search integrations (7-day bug-fix policy, all updated September 2026): Algolia, Azure AI Search and Lucene.NET. Each one indexes content tree pages and reusable items using a code-first approach. Developers can build faceted and relevance-tuned search, including blended content-product results, on Algolia or Azure AI Search, and those engines provide synonym management. That configuration happens in the search service and in code, though. There is no marketer-facing search merchandising, no CMS-managed search landing pages and no commerce-specific product discovery layer. Basic search with enrichment through official connectors puts this item in the lower-middle of the 35–55 band.
Catalog discounts and order discounts are production-ready (December 2025), and generic coupon codes are native (January 2026) — covering core promotional mechanics. The February 2026 refresh added promotion targeting flexibility, letting marketers scope a promotion to all customers or only those authenticated through member accounts — a step toward audience-specific promotional targeting. Free shipping promotions (September 2026) join catalog and order discounts: they remove shipping cost above a cart threshold, can be limited to specific shipping methods, and store managers configure them like any other promotion. Content scheduling via workflow and scheduled publishing allows time-activated promotional banners, and Page Builder widgets can display promotional content. However, dedicated countdown timer widgets, tiered pricing tables with display logic, and channel-specific promotional content targeting are still not documented as native features.
XbK's multi-channel architecture supports multiple website channels from a single instance, each with its own domain, page tree, and configuration. The Content Hub provides shared product content (descriptions, images, attributes) accessible across all storefront channels, while per-channel page trees control storefront-specific editorial and legal content. Language variants per channel allow region-specific pricing and content. This is architecturally sound for multi-storefront but requires developer configuration and there is no storefront-specific governance UI for non-technical teams.
Content Hub with AI focal point detection (February 2025) and dimension-specific image variants provides solid image management for product photography. Video can be embedded via content items. Maximum dimension auto-scaling on upload prevents oversized images. CDN delivery for all assets. However, 360-degree product views, AR/3D model hosting, image hotspots, and zoom functionality are not native — these require custom frontend development or third-party plugins. Basic image galleries and video embeds are possible.
XbK has no marketplace or multi-vendor commerce features. There are no seller profile management tools, seller-contributed product description workflows, or content moderation at marketplace scale. Multi-author content is technically possible via RBAC permissions, but this is generic collaborative editing rather than marketplace-specific tooling. The native commerce framework is single-vendor by design.
All product content types support language variants, enabling locale-specific product descriptions. The extensible pricing pipeline supports multi-currency display (via custom implementation). Per-region tax configuration is supported. Phrase and XTM connectors enable professional translation of product content. However, currency-aware content blocks, regulatory content templates (EU labeling, CA Prop 65), and market-specific promotional calendar management are not native — they require custom development.
Customer journey analytics visualizes progression and drop-off through marketing journeys including commerce touchpoints (March 2025). AIRA Campaign Insights evaluates KPIs including conversion metrics (March 2026). However, there is no dedicated content-to-revenue attribution within the CMS — connecting which content pages assisted or drove purchases requires external analytics tools (GA4 with enhanced ecommerce integration). Commerce analytics data is not surfaced as content performance metrics within the editorial interface.
Workspaces segregate Content Hub content into distinct role-scoped areas, with granular per-workspace permissions (View, Create/Update, Delete) assigned per role and per application — e.g., full Content hub permissions in Workspace A but View-only in Workspace B — so editors only see and act on the content in their workspace. Page permission management adds hierarchical page-level access control. This moves beyond simple content-type RBAC toward content-instance/area-based visibility control. SSO with OAuth/OIDC providers (Microsoft Entra ID, Auth0, Okta) is native, and Membership Roles (March 2026) add tiered visitor-facing content access with channel-tree inheritance. Fine-grained department/team partitioning for classic intranet use is still primarily an editorial-governance construct rather than audience-org-unit content targeting, so it lands solidly above content-type RBAC but short of full audience-based visibility.
Content lifecycle features including workflows, content versioning with full history, and multi-step approval processes are available. The Content Hub provides taxonomy-driven content organization. However, dedicated knowledge management features are absent: no content expiry/review scheduling, no stale content flagging, no structured knowledge article lifecycle distinct from standard content, no internal search quality tuned for knowledge retrieval at scale. Xperience is marketed as a marketing/commerce DXP — knowledge management is not a strategic use case.
Xperience by Kentico is purpose-built for marketing and commerce use cases, not employee intranets. Legacy Kentico versions (K8/K9) had explicit intranet feature sets, but the Xperience rebuild focuses entirely on digital marketing, commerce, and headless delivery. Membership Roles (March 2026) provide tiered content access which marginally supports restricted internal portals, but there are no native employee directory integrations, news feed widgets, social/community features, push notifications, or org chart tools. Building a full employee portal requires substantial custom frontend work.
XbK has no native internal communications features. A website channel could be configured as an employee news site with access-controlled content, but there are no targeted announcement tools, read receipts, acknowledgment tracking, or mandatory-read workflows. Audience segmentation exists for marketing (contact groups) but these are visitor-facing, not employee-department-targeted. Internal comms beyond basic intranet pages require custom frontend development.
No native employee directory, skills/expertise database, org chart, or team page management exists in Xperience by Kentico. Content Hub could theoretically model employee profiles as content items, but there is no out-of-the-box directory UI, org chart visualization, or HR system integration (Workday, BambooHR). This requires complete custom development from scratch.
Content versioning and workflow-based approval are available for all content — policies could be modeled as content types and managed through standard editorial workflows with version history. However, there are no purpose-built policy management features: no document acknowledgment tracking, no mandatory-read enforcement, no automated review/expiry reminders, no audit trail specific to policy acceptance. Standard CMS versioning is present but policy lifecycle management is absent.
No native onboarding journey or structured role-based content path features exist in XbK. Marketing automation with customer journeys could theoretically be adapted for employee onboarding sequences, but the automation is designed for marketing contacts/customers, not employee data integration. Progressive disclosure over 30/60/90 days, HR-triggered new-hire portals, and task checklists would all require substantial custom development without native platform support.
XbK has no built-in search engine. The official Lucene.NET, Algolia and Azure AI Search integrations (fully supported, active September 2026) index channel content, so internal search with facets and AI-assisted relevance is possible on Azure AI Search or Algolia. All of it is code-first and aimed at public website search. There is no federated search across SharePoint, Confluence or Drive, and nothing tunes search for internal knowledge volumes. Intranet search quality depends entirely on custom implementation.
All XbK website themes/templates are responsive and mobile-accessible via browser. However, there is no native mobile app for employee portal access, no offline content synchronization, and no push notification capability for intranet content. Headless delivery via API could enable custom mobile apps but this is custom development. The platform is designed for responsive web delivery to public visitors, not native mobile experience for frontline workers.
No LMS integration or native micro-learning features exist in Xperience by Kentico. The platform's integration catalog does not include Cornerstone, Workday Learning, or any LMS. Course assignment, completion tracking, and certification management would require full custom development with a separate LMS platform.
No community or social features exist in Xperience by Kentico. The social and community modules from legacy Kentico versions were removed in the XbK rebuild and have not been reintroduced. There are no comments, reactions, discussion forums, peer recognition, polls/surveys, or idea submission features. The platform is positioned exclusively for marketing and commerce, not community or collaboration.
No native Microsoft 365/Teams, Google Workspace, or Slack integration exists in XbK. The integration catalog does not list any workplace tool connectors. KentiCopilot provides MCP integration with developer tools (Claude Code, Cursor, GitHub Copilot) but this is a developer experience feature, not an employee communication integration. Webhook-based connections to workplace tools would require custom development.
Content versioning with full history is available for pages and content items. Workflow-based approval processes provide review stages before publishing. Content sync (staging to production) adds a promotion mechanism, and content overwrite protection (May 2026) plus globally configurable content locking (June 2026) reduce collaboration conflicts. However, automated review date scheduling, stale content flagging, ownership assignment for content freshness accountability, and archival workflows are still not documented as native features. Content lifecycle management remains manual — editors must proactively archive or review content without automated nudges.
XbK's analytics capabilities (customer journey analytics, campaign insights) are designed for external visitor and customer measurement, not internal employee content consumption. There are no department-level content view dashboards, failed intranet search term reports, employee engagement heatmaps, or adoption dashboards for intranet ROI. Internal analytics is not a supported use case.
XbK supports multiple website channels within a single instance, each with separate content models (namespaced content types), separate domains, and separate page trees. The Xperience Portal is multi-tenant by architecture, with SaaS support for multiple website channels from one instance. This is silo-based channel isolation within a shared application instance — not true per-tenant environment isolation. Organizations requiring completely separate environments (separate databases, separate deployments) must provision separate XbK instances.
The Content Hub enables shared reusable content items and assets across all website and headless channels — a genuine cross-brand content sharing mechanism as a first-class architectural feature. Developers can create Razor Class Libraries (RCLs) to organize components shared between channels. The multichannel sample repository demonstrates this pattern officially. This is a workable content-sharing model, but shared component libraries require developer setup of RCLs and are not self-service for brand managers.
Centralized user management, advanced permissions with page-tree-level ACLs, and workflow approvals are available across all channels within a single XbK instance. Workspaces add content-area governance: content can be segregated into workspaces with per-workspace role permission scoping (View/Create/Update/Delete per application), giving central teams a first-class way to enforce who can act on which content across brands while preserving per-channel autonomy. Content publishing workflows with notifications and a content reuse locator further strengthen editorial governance. Cross-brand content-standard enforcement (schema policies per brand) and cross-brand approval routing remain limited; governance is primarily at the user/permission/workspace level rather than enforced per-brand content schemas.
XbK uses channel-based licensing: one main channel included in the platform license, with additional channels purchased separately. This creates approximately linear per-brand cost scaling — each new brand channel adds incremental cost. No evidence of volume tiers or economies of scale for large many-brand portfolios. Not super-linear (no separate high-cost per-brand licenses), but not economically advantaged for large multi-brand deployments either.
Each XbK website channel has its own dedicated frontend (separate Razor Class Library, separate CSS/static assets, separate logo and visual identity). Per-channel theming is architecturally clean with genuine visual isolation between brands. However, this is all developer-managed CSS and component configuration — there is no platform-level design token management, no visual theme editor for brand managers, and no version-controlled brand style propagation system. Per-brand visual identity is achievable but requires developer implementation.
Per-channel language configurations allow each brand to have its own language strategy. Language variants per content item enable brand-specific translated content. The Phrase and XTM connectors support professional translation workflows. However, brand-specific translation approval chains are not documented — translation governance appears to be a single shared workflow rather than per-brand translation routing. No brand-locale governance matrix with per-brand translation approval chains and regional legal content governance is confirmed.
XbK's analytics (customer journey analytics, campaign insights) are scoped per channel/campaign, not aggregated at portfolio level. There is no cross-brand dashboard showing content velocity, publishing cadence, or engagement comparison across the brand portfolio. Each brand/channel team sees their own metrics. Portfolio-level aggregation requires manual external analytics work.
Workflow configurations are available per channel in XbK — approval chains and review stages can be configured independently for each brand channel. Central admin retains audit visibility across all channels. This provides meaningful per-brand workflow autonomy within a centrally auditable system. However, the configurability of per-brand workflows is not extensively documented as a self-service feature — it appears to require admin-level configuration rather than brand-team-managed workflow design.
The Content Hub enables sharing of reusable content items across all channels — press releases, product descriptions, and legal copy can be authored once and referenced (not duplicated) by multiple brand channels. This is structural content reuse, not a formal syndication system with override points and push-update workflows. Corporate-to-brand content syndication with controlled local adaptation (e.g., the brand can override a product blurb but can't override a legal disclaimer) is not a documented native capability.
Basic compliance configuration is available per channel — cookie consent and GDPR handling are supported via standard web mechanisms (consent banners configurable per channel). Cloudflare security event monitoring is surfaced in the Portal (January 2026). However, there are no platform-enforced publishing guardrails that prevent non-compliant content from going live per brand, no per-brand accessibility standard enforcement, and no data residency controls per channel. Compliance is primarily developer/admin configured, not platform-enforced guardrails.
The RCL (Razor Class Library) pattern in XbK supports a shared component library maintained centrally with per-channel brand extensions — a documented and officially sample-supported pattern. However, this design system lives entirely in code: there is no platform-level design system management UI, no component versioning system, no update propagation mechanism, and no brand-extension workflow for non-developers. Central component libraries require developer discipline and code-level versioning (Git), not platform tooling.
A single XbK instance provides a central admin who can manage users across all brand channels. Workspaces let central teams give brand/project groups autonomous content areas with role permissions scoped per workspace (View/Create/Update/Delete per application), so brand teams operate independently while central admin retains oversight. Per-channel role scoping allows brand teams autonomous editorial permissions within their channel. SSO via OAuth/OIDC (Microsoft Entra ID, Auth0, Okta) works across all channels from a single identity provider, and users can hold roles across multiple channels. Comfortably meets the central-admin-with-autonomous-brand-teams-and-SSO bar.
Content types in the Content Hub are shared across channels by default, providing a common baseline model accessible to all brands. Per-channel namespacing allows channels to have unique content types extending the shared model. However, a formal model extension pattern — where Brand A adds video fields to a global product page type and Brand B adds comparison tables without forking the base type — is not a documented platform-native capability. It requires developer-managed code-level inheritance, not a platform-managed model extension workflow.
No portfolio-level reporting dashboard exists in XbK. Metrics (customer journey analytics, campaign insights) are scoped per campaign or per channel. There is no executive view of content freshness across the brand portfolio, publishing SLA adherence tracking, cost allocation per tenant, or capacity planning data. Multi-brand deployments would require custom reporting built externally (BI tools, external analytics aggregation) to achieve portfolio-level visibility.
EU residency is real (West/North Europe, Germany West Central, Switzerland North, UK regions) and Kentico's privacy policy relies on the EU-U.S. Data Privacy Framework and SCCs for transfers. Consent management is built in. However, the Data protection application is only a framework: the docs say that by default Xperience provides no personal data collection or erasure functionality, so developers must implement collectors and erasers. No public DPA or sub-processor list could be fetched; the trust center sits behind a Cloudflare challenge. That keeps the score in the 60–78 band.
No HIPAA BAA is offered and there is no HIPAA-eligible SaaS documentation. The only HIPAA mentions on kentico.com are general explainers in marketing blogs and a healthcare ebook. The docs corpus mentions healthcare only once, as a generic example of why 2FA may be required. Without a vendor-executed BAA, covered entities cannot use the SaaS for PHI.
The security page claims GDPR, CCPA and Australia Privacy Act alignment. It also claims DORA alignment and Digital Services Act readiness, and a dedicated Australian Privacy Act page maps Kentico's practices to the Australian Privacy Principles. These are self-attested alignments, not audited frameworks. There is no FedRAMP, IRAP, C5, PCI-DSS or HITRUST, and no LGPD or PIPEDA commitment specific to Kentico. That puts it modestly above the GDPR + CCPA baseline.
Kentico holds a SOC 2 Type II attestation, with controls verified annually and continuous monitoring, and the report is distributed through the Kentico Trust Center. Which Trust Service Criteria are covered, and the report period, could not be verified because the trust center blocks non-browser access. That holds the score below the 85+ tier.
Kentico is ISO 27001 certified at the company and ISMS level, and the SaaS docs state it applies to the SaaS offering. That is more than inheriting Azure's certificate. There is no ISO 27018 or ISO 27701 certification, which blocks the 80+ tier.
SOC 2 Type II and ISO 27001 are the only formal attestations. DORA alignment and DSA readiness are self-declared postures, not certifications. There is a public Vulnerability Disclosure Program, but no CSA STAR, PCI-DSS, Cyber Essentials Plus, FedRAMP, IRAP, ENS or C5 was found.
The SaaS offering supports 20 Azure regions across the US, Canada, the EU, UK, Switzerland, East Asia, Japan, Australia and the UAE. Kentico states that all customer data is stored in a single-tenant account in the region the customer picks at provisioning. Two things leave the chosen region: Xperience Portal account data (usernames, project names, Auth0, logs) always sits in Kentico's European data center, and Cloudflare CDN caching is global. No contractual residency guarantee could be verified.
Xperience Portal offers self-service manual and automatic exports: the database as a bacpac file plus blob storage, in separate Restore points and Exports apps since 30.1.0. That gives customers complete data portability. However, personal-data erasure is not built in, because developers must write custom erasers. No post-termination retention or deletion period is published.
With 'Log object actions' enabled, the Event log records create, edit and delete actions on objects, and an AfterExportListingEvent hook supports auditing of data exports. Retention is set by entry count through the Event log size setting and CMSLogKeepPercent, not by time. Logging goes through Microsoft.Extensions.Logging providers, and SaaS adds an Application Insights integration viewable in Xperience Portal, so logs can reach Azure Monitor and SIEM tools. There is no dedicated audit-log product, native SIEM connector or compliance reporting.
There is still no WCAG 2.1 AA conformance statement or stated conformance target for the administration UI. The changelog does show ongoing accessibility work. The September 24, 2026 Refresh made AIRA guidance fully keyboard accessible and added focus rings to dashboard tiles and the image focal-point control. An earlier refresh gave date/time inputs keyboard navigation and ARIA. That is concrete progress, but it is incremental and not measured against a standard.
No VPAT, ACR, Section 508 statement or ATAG assessment exists for Xperience by Kentico. kentico.com/accessibility returns 404. Kentico's accessibility messaging covers only helping customers make their delivered websites WCAG-compliant (alt text, content validation), not the authoring tool. That is a procurement gap for public-sector buyers.
AIRA's GA 'Generate content' feature generates and refines text in page, email, content item, and headless item fields, using per-field AIRA instructions and item context. It also offers in-place rich text refinements with predefined or custom prompts and a global 'Tone of voice guidelines' setting, and generated output lands as a reviewable draft. Scores below 70 because there is no bulk or mass generation, and brand controls amount to one global tone field plus per-field instructions rather than governed prompt templates.
AIRA image processing (GA) auto-selects focal points for image variants on upload, and during mass upload it generates SEO-friendly image descriptions and assigns taxonomy tags based on image content. Neither the docs nor the product pages mention any native image generation. That puts it in the 40–60 band for auto alt text and tagging without generation.
AIRA translations are a native MT feature, not a TMS hookup. They translate pages (including Page Builder content) and content items into new language variants as reviewable drafts, and bulk jobs run through mass translation and a Translation queue application. Admins can configure brand terminology, words to leave untranslated, formatting rules, custom instructions, and the global tone of voice. Held just below 70 because there is no translation quality scoring and links are not re-targeted automatically.
Mass-upload image description (alt text) and auto-tagging to taxonomy fields are GA. The SEO & GEO Specialist agent analyzes pages for keyword targeting, SEO best practice, and AI readability, but the docs mark it as a Preview feature, and it returns recommendations in chat rather than auto-writing metadata. Nothing in the docs covers dedicated meta-description, OG, or schema-markup generation (editors can only enable generic 'Generate content' on such fields), so this is partial automation at 40–60, not the 67 previously credited on the assumption the agent was GA.
Several AI assists sit inside editorial and marketing work: auto-tagging and description of images on mass upload, bulk AIRA translation through the Translation queue, the AIRA Segment Condition Builder (off by default and requiring the CDP), and the Campaign Manager's asset-readiness checks. These count as multiple lightweight assists, but there is no AI-driven duplicate detection, content routing, smart scheduling, or stale-content lifecycle automation. The June 2026 extensible automation actions are developer extensions, not AI.
The AIRA Agentic Marketing Suite now names four agents: SEO & GEO Specialist, Content Strategist, Customer Journey Optimization Specialist, and Campaign Manager. Kentico's docs flag every one of them as a 'Preview feature' subject to breaking changes, even though the previous score treated them as GA. They have real governance: an admin-managed Agents tab with enable/disable and custom instructions, 'Allow' approval prompts that since August 2026 persist until answered, and permission-aware tool use. Because the agents are chat-invoked, single-scenario, and all in preview, this sits in the early/beta band rather than the GA 55–75 band.
AIRA Customer Journey Insights shows contact-group progression and the best and worst performing segments per journey stage. The Customer Journey Optimization Specialist (Preview) diagnoses drop-offs on page and email stages, and the Campaign Manager (Preview) produces campaign reports and cross-campaign comparisons. There is no content intelligence dashboard with topic clustering, content health scoring, stale-content detection, or editorial priority queues.
The Content Strategist agent audits a page against a stored Content Strategy artifact for style compliance, tone, and voice alignment, returning findings graded Critical/Major/Minor/Suggestion with quoted text and suggested fixes. The SEO & GEO Specialist adds SEO and AI-readability audits. Both agents are Preview, work one page at a time, and have no accessibility scanning or site-scale duplicate or thin-content detection. That is one dimension done well, at the low end of 45–60.
There is no native vector search, embedding generation, or semantic search in the XbyK core. Semantic ranking comes from the official, fully supported Kentico/xperience-by-kentico-azure-ai-search integration, which requires the customer's own Azure AI Search resource, alongside the Algolia and Lucene integrations. The only hybrid vector search Kentico ships is inside the Documentation MCP server, which searches product docs, not customer content. That makes semantic search a paid external add-on, in the 35–55 band.
The AIRA Segment Condition Builder turns natural-language descriptions into CDP segment condition rules, and the Customer Journey Optimization Specialist recommends page or email fixes for drop-off stages. Execution stays rule-based, so this is AI-assisted personalization in the 40–60 band. There is no ML scoring, predictive segment assignment, or next-best-content engine comparable to Bloomreach Loomi or Sitecore CDP.
The official Management MCP server (@kentico/management-api-mcp) left preview on 2026-09-03. It exposes schema-aware CRUD over content types, content items, pages, Page Builder components, channels, languages, and, since September, custom modules and classes, with tool groups (--enabled-groups). Kentico's docs, however, restrict it to local development instances with only basic authentication and no per-operation authorization, and say not to enable it in production. That means it lacks the permissions and production publish path the 75+ tier requires. A Documentation MCP server and a Content Modeling MCP server complete the roster, which keeps it at the top of the official-GA-with-limits band.
AIRA is a Kentico-managed, credit-metered service running on Microsoft Azure OpenAI and Azure Image Analysis. Neither the AIRA configuration docs nor the pricing and policies page offers any setting to supply your own API key, provider, or model. The Kentico/xperience-module-openai-azure repo cited previously has been archived since February 2025, and the plugin that swaps the LLM provider is community-built. KentiCopilot does let developers bring their own coding assistant (Claude Code, Copilot, Cursor), but the platform's AI features stay locked to the vendor model.
KentiCopilot has become a real agent-oriented developer toolkit: a GA Management MCP with an OpenAPI spec that agents are expected to discover, Documentation and Content Modeling MCP servers, a docs corpus published as llms-full.txt, and plugins and skills for automation actions, triggers, and conditions. Recent additions (July–September 2026) include a KX13 migration plugin, a --kxp-db-status CLI command built for agents and pipelines, and a Dancing Goat template with MCP servers and instruction files pre-configured. Held below 70 because this tooling targets development-time coding agents, and there are no agent-optimized content delivery or RAG endpoints and no LangChain or LlamaIndex guides.
Governance covers brand guardrails (global tone of voice, per-agent custom instructions, and the Content Strategy artifact behind View/Manage artifacts permissions), human-in-the-loop 'Allow' prompts before agents save, AI output created as drafts, permission-aware tool use, and per-feature or per-agent disable switches. Privacy terms state that prompts and responses are neither stored nor used for training. The docs say nothing about an AIRA audit trail of who invoked AI and what it generated (the earlier 'logs all agent activity' claim is unsupported), and there is no hallucination scoring or IP indemnification, which puts it at the bottom of the 50–70 band.
The AIRA application's Overview tab shows the credit balance and the next renewal. The Usage tab breaks down consumed credits and request counts by source for the last 30 days or since renewal, and admins can export 90 days of usage as CSV. That is basic usage and cost visibility. It scores below 65 because there are no per-user metrics, prompt-effectiveness analytics, or quality trend monitoring.
How composite scores (0–100) have changed over time. Click legend items to show/hide metrics.
Xperience by Kentico is modestly improving, led by Build Simplicity (+1.1), Compliance & Trust (+0.9) and Platform Velocity (+0.6), as Kentico keeps shipping its AI and developer tooling, most visibly the Management MCP server, which left preview on 2026-09-03 with schema-aware content operations. Collaboration is the clearest practical gain: content locking now covers web pages, reusable and headless items and emails, and conflict handling spans the whole product, though there is still no real-time co-editing with presence indicators. Evaluators should note that experimentation rose sharply but still has no native content-level or server-side A/B testing, and the small dip in Operational Ease (-0.4) means the day-to-day running story is not improving alongside the feature work.
Score Changes
Xperience by Kentico has no native content-level or server-side A/B testing — all first-party A/B testing documentation still references legacy KX12/KX13 only, and the XbK changelog contains no native experimentation feature. However, Kentico now maintains an official Tag Manager package (github.com/Kentico/xperience-by-kentico-tag-manager) that lets marketers enable a VWO integration directly from the administration UI, injecting VWO SmartCode into a website channel for front-end A/B testing and experimentation (added December 2025). This is client-side experimentation via a tight third-party integration: experiment design, targeting, and statistical significance/winner selection all live in VWO's own platform, and the integration can manipulate only front-end data (no backend experimentation). Email Builder subject/content variants remain per-segment personalization, not statistically validated experiments. This fits the 'experimentation via tight integration' tier at the lower end — a real optimization path exists, but nothing native or content-model-aware.
There is no real-time co-editing with presence indicators. Conflict handling now covers the whole product: content overwrite protection (May 2026), opt-in global content locking for pages, reusable items and headless items (June 29, 2026), and, from the July 28, 2026 refresh (31.7.0), locking for emails as well, including Email Builder, properties and plain-text tabs. It has override permissions, automatic lock release and workflow comment notifications. This is solid lock-based collaboration, but it is not Google-Docs-style co-authoring.
The official Management MCP server (@kentico/management-api-mcp) left preview on 2026-09-03. It exposes schema-aware CRUD over content types, content items, pages, Page Builder components, channels, languages, and, since September, custom modules and classes, with tool groups (--enabled-groups). Kentico's docs, however, restrict it to local development instances with only basic authentication and no per-operation authorization, and say not to enable it in production. That means it lacks the permissions and production publish path the 75+ tier requires. A Documentation MCP server and a Content Modeling MCP server complete the roster, which keeps it at the top of the official-GA-with-limits band.
The AIRA application's Overview tab shows the credit balance and the next renewal. The Usage tab breaks down consumed credits and request counts by source for the last 30 days or since renewal, and admins can export 90 days of usage as CSV. That is basic usage and cost visibility. It scores below 65 because there are no per-user metrics, prompt-effectiveness analytics, or quality trend monitoring.
Content locking now covers web pages, reusable content items and headless items (June 2026) plus emails, including their properties and plain-text tab (July 28, 2026 refresh). It has a role-based override and releases on publish, workflow change or revert, and basic overwrite protection applies even when locking is off. Workflow step comments add some asynchronous discussion. Still 40 because there is no simultaneous co-editing, presence indicators or inline commenting.
Workspaces segregate Content Hub content into distinct role-scoped areas, with granular per-workspace permissions (View, Create/Update, Delete) assigned per role and per application — e.g., full Content hub permissions in Workspace A but View-only in Workspace B — so editors only see and act on the content in their workspace. Page permission management adds hierarchical page-level access control. This moves beyond simple content-type RBAC toward content-instance/area-based visibility control. SSO with OAuth/OIDC providers (Microsoft Entra ID, Auth0, Okta) is native, and Membership Roles (March 2026) add tiered visitor-facing content access with channel-tree inheritance. Fine-grained department/team partitioning for classic intranet use is still primarily an editorial-governance construct rather than audience-org-unit content targeting, so it lands solidly above content-type RBAC but short of full audience-based visibility.
With 'Log object actions' enabled, the Event log records create, edit and delete actions on objects, and an AfterExportListingEvent hook supports auditing of data exports. Retention is set by entry count through the Event log size setting and CMSLogKeepPercent, not by time. Logging goes through Microsoft.Extensions.Logging providers, and SaaS adds an Application Insights integration viewable in Xperience Portal, so logs can reach Azure Monitor and SIEM tools. There is no dedicated audit-log product, native SIEM connector or compliance reporting.
The native Automation Builder supports behavioral triggers, drip sequences with waits, rule-based branching, and scheduled time-based triggers. Custom automation actions shipped in June 2026, followed by custom triggers and custom conditions in the July 28, 2026 refresh, so processes can start from any project event (purchases, inbound webhooks) and branch on code-evaluated logic, and KentiCopilot skills generate these steps. Held at 66 because there is no native lead scoring (Kentico's own examples compute a contact score in a custom step) and multi-channel orchestration beyond web and email is thin.
Kentico has published at least one security advisory almost every month of 2026 for its own codebase, most rated high: SQL injection in Form Builder (CVSS 8.7, Jun 4), Segments condition builder SQLi (8.6) and content-sync SQLi (7.5) (Jul 9), macro input validation (8.6, Aug 13), shared-cache leakage of media resources (8.2, Sep 10), and an account-recovery flaw (8.6, Sep 24). That follows May's critical 9.4 admin-UI SQLi. Most affect every version back to 22.0.0, and the only fix is updating to the latest version, so each one means a NuGet update and a redeploy. Not lower because advisories are clear and scoped, fixes ship within a week through hotfixes, Kentico runs the SaaS infrastructure, and some flaws (e.g. the Sep 24 account-recovery issue) did not affect SaaS.
The official Tag Manager package (github.com/Kentico/xperience-by-kentico-tag-manager) lets marketers enable Google Analytics 4, Google Tag Manager, and Microsoft Clarity (session recording, heatmaps, scrollmaps) directly from the administration UI per website channel — first-class configuration of standard analytics tags without developer template edits, though the metrics themselves still live in the external tools. In-platform, customer journey analytics (March 2025) visualizes contact progression and drop-off through journey stages with date-range filtering, AIRA Campaign Insights evaluates KPI performance across campaigns (March 2026), and the Campaign Manager Agent (April 2026) generates final reports comparing success across multiple campaigns. Form submission tracking with channel and language metadata (October 2025) surfaces form performance. Still no native web analytics module comparable to KX13's visitor tracking — page views, sessions, and source attribution remain in GA4/GTM.
The SaaS offering supports 20 Azure regions across the US, Canada, the EU, UK, Switzerland, East Asia, Japan, Australia and the UAE. Kentico states that all customer data is stored in a single-tenant account in the region the customer picks at provisioning. Two things leave the chosen region: Xperience Portal account data (usernames, project names, Auth0, logs) always sits in Kentico's European data center, and Cloudflare CDN caching is global. No contractual residency guarantee could be verified.
KentiCopilot has become a real agent-oriented developer toolkit: a GA Management MCP with an OpenAPI spec that agents are expected to discover, Documentation and Content Modeling MCP servers, a docs corpus published as llms-full.txt, and plugins and skills for automation actions, triggers, and conditions. Recent additions (July–September 2026) include a KX13 migration plugin, a --kxp-db-status CLI command built for agents and pipelines, and a Dancing Goat template with MCP servers and instruction files pre-configured. Held below 70 because this tooling targets development-time coding agents, and there are no agent-optimized content delivery or RAG endpoints and no LangChain or LlamaIndex guides.
Kentico maintains a structured Developer Learning Map, Developer Kickstart guide, training-guides repo and a Certified Developer path, and has layered AI-assisted onboarding on top: the KentiCopilot marketplace was reorganized in July 2026 into workflow plugins (kentico-web-development walks agents from wireframe through bootstrapping, content modeling and implementation), and the Management MCP server came out of preview on Sept 3, 2026 (31.8.3) with a recommendation to use it on all projects. Not higher because there is still no in-app interactive developer tour and no framework-specific (Next.js) guided learning path.
Kentico maintains an official, fully supported CRM integration (github.com/Kentico/xperience-by-kentico-crm, 7-day bug-fix policy, active September 2026) with plug-and-play packages for Salesforce Sales Cloud and Microsoft Dynamics Sales. It sends form submissions to the CRM as leads and shows sync status in the admin UI. Earlier scoring runs missed this connector, so the old claim that XbK had no Salesforce connector was wrong. The official Tag Manager package covers analytics and engagement tags (GA4, GTM, Clarity, VWO, Intercom). Bynder (DAM), Phrase/XTM (localization), Campaign Monitor (email sending) and Zapier round out the pre-built connectors. Marketing automation became much more extensible in 2026: custom actions (June 2026), then custom triggers and custom conditions (July 2026). All three show up in the marketer's Automation Builder, and triggers can start processes from external-system inputs or purchases. There is still no MAP connector (Marketo, HubSpot, Pardot), no CDP or ad-platform connector, and no native outbound webhooks. The CRM connector syncs leads one way and does not sync contacts both ways. Pre-built connectors now cover CRM, analytics/tags, DAM and email, with code-level event triggers, which puts this item in the middle of the 35–55 band.
Centralized user management, advanced permissions with page-tree-level ACLs, and workflow approvals are available across all channels within a single XbK instance. Workspaces add content-area governance: content can be segregated into workspaces with per-workspace role permission scoping (View/Create/Update/Delete per application), giving central teams a first-class way to enforce who can act on which content across brands while preserving per-channel autonomy. Content publishing workflows with notifications and a content reuse locator further strengthen editorial governance. Cross-brand content-standard enforcement (schema policies per brand) and cross-brand approval routing remain limited; governance is primarily at the user/permission/workspace level rather than enforced per-brand content schemas.
The security page claims GDPR, CCPA and Australia Privacy Act alignment. It also claims DORA alignment and Digital Services Act readiness, and a dedicated Australian Privacy Act page maps Kentico's practices to the Australian Privacy Principles. These are self-attested alignments, not audited frameworks. There is no FedRAMP, IRAP, C5, PCI-DSS or HITRUST, and no LGPD or PIPEDA commitment specific to Kentico. That puts it modestly above the GDPR + CCPA baseline.
Admin SSO works with any OAuth/OIDC provider, with documented setups for Entra ID, Auth0 and Okta, but only one external provider can be active at a time and SAML is not supported natively. Admin MFA and token-bucket rate limiting protect the user-management endpoints, and the headless API uses API keys. Scored down because a second authentication-flow advisory followed the May MFA bypass: an account-recovery flaw (CVSS 8.6, v22.0.0–31.8.4, self-hosted only) that could grant unauthorized admin access.
The official changelog shows a named Refresh every month of 2026 so far (Jan 22, Feb 23, Mar 23, Apr 16, May 14, Jun 29, Jul 28 31.7.0, Aug 20 31.8.0, Sep 24 31.9.0). Weekly hotfixes, SaaS updates and AIRA model updates land in between (31.8.1–31.8.4 in Aug–Sep). Each Refresh ships real features: the Sept one added Management MCP tool groups, free-shipping promotions, CSV export on every listing page and a DB status CLI. Not higher because individual Refreshes are incremental rather than platform-shifting.
The published support policy guarantees at least 12 months of backward compatibility after a feature is deprecated or an API is marked obsolete, with the replacement running alongside it. Each release lists its obsolete APIs. Removals are staged: media library support ended Jul 24, 2026 and the removal was then postponed past the Sept Refresh. Migration tooling covers the KX13 exit (Migration Tool plus the KentiCopilot kx13-migration plugin). Not higher because AI tooling (Management MCP/API) is explicitly exempt and was renamed without notice in 31.9.0, and 31.8.0 shipped a content sync regression that needed a hotfix four days later.
The community portal publishes content on a sustained near-monthly cadence (through the June 29, 2026 Refresh), runs an MVP/Community Leaders recognition program that grew its cohort into 2026, and held Community Program Summits in 2026. Kentico team members actively contribute to the community blog and run UX feedback and early-access sessions with program members. Engagement appears genuine for a mid-market B2B product; forum response times not independently verified.
The .NET CLI project templates were substantially modernized in 2026: the August 20 refresh (31.8.0) rebuilt Dancing Goat with Tailwind CSS, an esbuild pipeline, reworked Page Builder content, better SEO, and pre-configured MCP servers plus AI instruction files, and moved all templates to Central Package Management. The September 24 refresh (31.9.0) updated its visual design again. Alongside xperience-component-starter and the Admin Design Components reference project, this is a real example-content starter. Not higher because there is still no vendor-maintained Next.js/Nuxt/Astro starter for the headless channel.
Setup requires the .NET SDK, .NET CLI template registration, SQL Server provisioning, and admin/presentation wiring, which is moderate for experienced .NET developers. 2026 tooling trims friction: templates use Central Package Management, the KentiCopilot project-lifecycle plugin generates CD repository.config, and 31.9.0 added a --kxp-db-status command so scripts and agents can check database readiness without starting the app. That same release made SystemEmailOptions.ServiceDomain or AllowedHosts mandatory on self-hosted projects for user-invite and password-reset emails, adding one more non-obvious config value, so the score holds.
A Certified Developer exam still exists and is strongly expected for agency partners, covering Page Builder internals, custom modules, content modeling, GDPR, and CI/CD — not just general .NET skills, and the platform remains inaccessible to JS/Python-only developers. Kentico's 2026 AI-dev push (KentiCopilot skills, MCP servers, Claude Code/Cursor/Copilot support) explicitly aims to 'lower the seniority bar,' modestly reducing the platform-specific expertise needed before first delivery. Not higher because the proprietary Page Builder/module model and certification expectation persist.
A dedicated Campaigns feature (March 2026) combines campaign briefs, associated digital assets, and linked customer journeys with AIRA Campaign Insights for AI-driven KPI evaluation. The May 2026 refresh added a guided campaign-brief authoring flow: the Campaign Manager Agent asks marketers a structured series of questions (brand, goals, audiences, KPIs, channels, messaging) and restructures the answers into a formatted brief. The production-ready Campaign Manager Agent (April 2026) evaluates campaign performance against KPIs, audience groups, and journey metrics and generates final reports comparing success across multiple campaigns — a significant step toward portfolio-level campaign orchestration. Email Builder (production March 2025) provides visual drag-and-drop email authoring. Marketing automation with conditional branching is native. Multi-channel coordination and a dedicated content calendar UI are still absent.
Page Builder with template-based page creation, version history for pages, content sync from staging to production (May 2025), and shareable preview URLs (December 2025) support a reasonable content velocity workflow. AIRA inline text generation and transformation was expanded to text fields across all content type targets including headless items (May 2026), extending assisted authoring beyond the rich text editor. Content overwrite protection (May 2026) and globally configurable content locking (June 2026) prevent lost edits and rework from concurrent editing, and a content reuse locator surfaces cross-channel usage during editorial decisions. Drag-and-drop asset uploading during content creation (November 2025) reduces friction. 'Save and create another' (August 2026) creates the next page or content item with the previous page's content type, template and tree position already filled in, which speeds up batch authoring. Content locking was extended to emails (July 2026). True bulk editing is still not featured, and new page types still require developer setup of widgets.
Catalog discounts and order discounts are production-ready (December 2025), and generic coupon codes are native (January 2026) — covering core promotional mechanics. The February 2026 refresh added promotion targeting flexibility, letting marketers scope a promotion to all customers or only those authenticated through member accounts — a step toward audience-specific promotional targeting. Free shipping promotions (September 2026) join catalog and order discounts: they remove shipping cost above a cart threshold, can be limited to specific shipping methods, and store managers configure them like any other promotion. Content scheduling via workflow and scheduled publishing allows time-activated promotional banners, and Page Builder widgets can display promotional content. However, dedicated countdown timer widgets, tiered pricing tables with display logic, and channel-specific promotional content targeting are still not documented as native features.
A single XbK instance provides a central admin who can manage users across all brand channels. Workspaces let central teams give brand/project groups autonomous content areas with role permissions scoped per workspace (View/Create/Update/Delete per application), so brand teams operate independently while central admin retains oversight. Per-channel role scoping allows brand teams autonomous editorial permissions within their channel. SSO via OAuth/OIDC (Microsoft Entra ID, Auth0, Okta) works across all channels from a single identity provider, and users can hold roles across multiple channels. Comfortably meets the central-admin-with-autonomous-brand-teams-and-SSO bar.
EU residency is real (West/North Europe, Germany West Central, Switzerland North, UK regions) and Kentico's privacy policy relies on the EU-U.S. Data Privacy Framework and SCCs for transfers. Consent management is built in. However, the Data protection application is only a framework: the docs say that by default Xperience provides no personal data collection or erasure functionality, so developers must implement collectors and erasers. No public DPA or sub-processor list could be fetched; the trust center sits behind a Cloudflare challenge. That keeps the score in the 60–78 band.
Xperience Portal offers self-service manual and automatic exports: the database as a bacpac file plus blob storage, in separate Restore points and Exports apps since 30.1.0. That gives customers complete data portability. However, personal-data erasure is not built in, because developers must write custom erasers. No post-termination retention or deletion period is published.
There is still no WCAG 2.1 AA conformance statement or stated conformance target for the administration UI. The changelog does show ongoing accessibility work. The September 24, 2026 Refresh made AIRA guidance fully keyboard accessible and added focus rings to dashboard tiles and the image focal-point control. An earlier refresh gave date/time inputs keyboard navigation and ARIA. That is concrete progress, but it is incremental and not measured against a standard.
Content delivery for headless channels is a GraphQL API per channel with an auto-generated schema, API-key security and a built-in query browser; .NET consumers get the Content Item Query API and IContentRetriever (which gained IncludeContentTypeFields projection in v31.7.0). The previously credited 'preview Headless REST API' could not be found anywhere in the changelog or docs and has been removed; the only REST surfaces are headless tracking and the OpenAPI-described Management API, which is scoped to local development. Not higher because GraphQL is retrieval-only with no mutations or subscriptions and there is no REST content delivery API.
XbyK uses a structured content type system with code-generated C# models, making schema changes type-safe and refactorable, with CI/CD serialization for schema-as-code. The Management MCP server (GA Sept 2026) manages content types, reusable field schemas, and as of 31.9.0 custom module classes and UI forms. 31.8.0 also let custom data types be used in reusable field schemas. There are no documented severe field-count limits, but the reusable-content vs. page vs. headless-item split needs upfront planning, and media library removal forces an asset-model migration on older projects.
Page Builder lets marketers self-serve page layout, widget placement, and content edits post go-live, with read-only inspection reducing editor friction, and AIRA now assists marketers directly: the April 2026 refresh added SEO & GEO Specialist and Campaign Manager agents plus segment-condition building, and the May 14, 2026 refresh (31.5.0) extended AIRA text-field assistance across all content type targets including headless items. Not higher because new widget types, page templates, and new content types still require developers.
Built-in workflows, content locking (June 2026), form usage tracking ('Used in' tab) and the AIRA agents (Content Strategist, SEO & GEO Specialist) reduce day-to-day editorial overhead, and 31.9.0 adds CSV export on listing pages, which helps with manual audits. There is still no native broken-reference detection, orphaned-content alerting, stale-content identification or content health dashboard, so hygiene remains manual or depends on paid third-party tools such as Siteimprove. Not lower because locking and the AIRA agents lighten the load; not higher because content hygiene is not automated.
Xperience by Kentico is essentially stable this cycle with a slight upward tilt, as Capability edged up 0.6 points while Platform Velocity, Cost Efficiency, Build Simplicity, Operational Ease, and Compliance & Trust all held flat. The Capability gain comes from meaningful improvements in native A/B and multivariate testing (now covering both pages and marketing emails) and in product content management, where Content Hub-based modeling allows fully customizable product schemas. Practitioners should weigh those gains against a notable security track record decline tied to a May 2026 critical SQL injection advisory (CVSS 9.4) in the admin interface, along with the impending July 2026 removal of legacy Media libraries as Content Hub becomes the platform's unified DAM.
Score Changes
Xperience by Kentico offers native A/B testing for both pages and marketing emails with variant creation, conversion goal configuration, and built-in analytics for evaluating results. The December 2025 refresh added an official VWO integration as an additional optimization path. Held at 55 because multivariate testing depth and statistical significance reporting are less mature than dedicated experimentation platforms.
Products are modeled as content items in the Content Hub rather than fixed SKU objects, giving fully customizable schema, versioning, localization, and workflow, plus taxonomy-based organization by category/brand/custom attributes and SEO-friendly descriptions reusable across channels. This is a stronger pattern than generic content types repurposed for products. Held at 65 because product-specific UI patterns (variant pickers, attribute matrices) still require developer setup.
May 21, 2026 security advisory disclosed a critical SQL injection vulnerability (CVSS 9.4) in Xperience by Kentico admin UI affecting versions 22.0.0–31.5.0 and an MFA bypass (CVSS 8.6), both directly in the active product line — not just legacy KX13. Older 2025 CVEs continue to appear on CISA KEV (CVE-2025-2746/2747/2749). Vulnerability Disclosure Program exists but is reward-free. The frequency and severity of high-impact CVEs across both Xperience 13 and Xperience by Kentico significantly worsens the track record.
SSO via external authentication providers including OIDC through ASP.NET Core Identity integration; MFA available for admin users; API-key authentication for headless GraphQL/REST endpoints. The May 2026 MFA-bypass advisory (CVSS 8.6, brute-forceable MFA codes without account lockout) has since been patched, partially restoring the prior deduction. Not higher because SAML still requires custom configuration beyond built-in OIDC, and the MFA weakness was recent.
Legacy Media libraries will be removed July 24, 2026, with the Content Hub serving as the unified DAM going forward: metadata schemas via content types, custom tagging/taxonomy, folder structures, asset reuse tracking, smart cropping with focal points, and AIRA-assisted auto-tagging. The Bynder integration extends to full enterprise DAM. Held at 62 because Content Hub assets do not support file versioning (only the latest file is retained) and rights/expiry management of purpose-built DAMs is still missing.
Xperience by Kentico SaaS is publicly documented as designed for 99.9% uptime, with Kentico responsible for SaaS environment, Xperience Portal, and deployment API availability 24/7/365. Public status page at status.xperience-portal.com with uptime history. The April 2026 Refresh added extensible SaaS uptime monitoring supporting up to 6 checker configurations across regions. Not higher because 99.9% is mid-tier vs. 99.95%+ from headless leaders, and historical uptime data not granularly published.
Configurable multi-stage workflows are supported across all content types with role-based transitions and comment-enabled step notifications. The April 2026 refresh added a Role management app with permission evaluation API for the admin UI. The May 14, 2026 refresh added Workspaces and page permission management for hierarchical access control, a Content reuse locator surfacing cross-channel usage during editorial decisions, granular content synchronization between environments, and content publishing workflows with notifications — together a substantial editorial-governance upgrade.
Native digital commerce became production-ready in July 2025 with product catalog, orders, customers, and granular promotions; 2026 additions include catalog discounts, stock tracking, and a faceted product-listing filter (AND/OR taxonomy logic with URL state). Products are modeled as content items in the Content Hub for full versioning/localization/workflow. Held at 58 because it remains a framework — storefront UI, tax calculation, and payment processing still require custom implementation, unlike turnkey commerce platforms.
SaaS deployment includes built-in CDN delivery for assets with per-field image format conversion and max width/height configuration. The April 2025 refresh added a copy-CDN-URL button, and AIRA delivers 1-click image optimization with smart cropping and focal point preservation. Held at 65 because WebP/AVIF support and responsive image presets are not explicitly documented as first-class delivery features.
Xperience by Kentico supports scheduled publishing, workflow-based publishing states, and (May 2026 refresh) Content Sync Detailed Selection providing granular control over content item promotion across environments with dependency selection. Held at 58 because a calendar-style content calendar UI is not prominently documented as a first-class XbyK feature, and atomic multi-item release bundles remain implicit via Content Sync rather than first-class bundles.
Dedicated STG (Staging) environment for SaaS plans was added May 2025, with Content Sync between environments. The May 2026 refresh added Content Sync Detailed Selection for granular content promotion with dependency selection. Page Builder provides in-context live preview for .NET-rendered sites; branch-based preview environments can be configured via CI/CD. Held at 65 because universal preview for arbitrary headless frontends and shareable external draft preview links are not first-class UI features.
Page Builder widgets support native content personalization rules tied to contact groups with in-editor preview per segment, and the June 2025 refresh added Email Builder widget-level personalization for email campaigns. G2 Winter 2026 reports 90% personalization satisfaction. Held below 75 because variant-level visual preview for arbitrary headless frontends remains less seamless than top-tier DXPs.
Xperience by Kentico supports per-language content variants in the Content Hub with locale fallback chains, field-level locale variants via the content item model, and (April 2026 refresh) basic admin UI localization for date and time formats. Marketers can create language variants of content items and web pages directly in the CMS. Held at 70 because advanced locale-specific publishing rules and locale routing still require developer configuration.
Comprehensive .NET extensibility: custom modules with DI, global event handlers for content lifecycle hooks, custom Page Builder widgets and sections, custom form components, and custom admin UI pages built with React. The June 2026 Refresh released configurable custom Marketing Automation actions (registered actions appear in the marketer's automation step dialog) and the KentiCopilot Management MCP Server with Management API extensions enables agentic content-creation workflows. Limited only by the requirement for .NET/C# skills — no low-code extension approach exists.
Rich text editing is powered by Froala WYSIWYG editor (v5.0.0), with inline rich text editors available within Page Builder widgets. AIRA refinements went GA in April 2026, and the May 14, 2026 refresh expanded AIRA generation/refinement to text fields across pages, emails, headless items, and reusable content items — using linked items and page previews as context. Output remains HTML-based rather than a portable AST, limiting channel portability.
Asset management is consolidating into the Content Hub — legacy Media Libraries and their APIs are scheduled for full removal by July 24, 2026, with non-destructive migration into content item assets (files copied into a dedicated Content Hub workspace; GUIDs, folders, and custom fields preserved). AIRA offers AI-driven focal point suggestion and improved responsive image support, and first-party Bynder DAM integration remains available. Legacy ~/getmedia/ links to migrated assets lose URL-based resizing and no documented on-the-fly transformation pipeline (WebP/AVIF, arbitrary resize) exists — the unified Content Hub with AI focal points modestly improves the native asset story amid short-term migration burden.
The .NET global event system supports custom code handlers for object create/update/delete and lifecycle events on content items, web pages, and headless items. Zapier integration Phase 2 added inbound actions in 2026, providing webhook-like data exchange with 6,000+ external tools by triggering create/update/delete based on Xperience events. Native webhook documentation still lacks public detail on HMAC signing, filtering, retry logic, and delivery logs — Zapier brokers much of the integration surface rather than the platform exposing a first-class webhook framework.
Xperience by Kentico is a hybrid DXP — Page Builder for traditional website channels plus headless channels with GraphQL and (as of April 2026) a preview Headless REST API for external apps. Primary SDK is .NET/ASP.NET Core with an official Next.js integration. The May 2026 Management API additions for Page Builder components plus granular content synchronization improve programmatic multi-channel publishing flows. Rich text output is HTML (not AST), limiting format-agnostic portability versus purpose-built headless platforms.
Xperience by Kentico ships a native CDP with rule-based Contact Groups, behavioral activity-based conditions, and unified Profiles that merge customers, contacts, and members. The April 16, 2026 refresh added admin-configurable identity resolution with flexible matching on external identifiers or native fields plus new segmentation tools and extensible APIs. Not higher because B2B firmographic enrichment and pre-built Segment/mParticle/Tealium connectors remain absent.
Community Integrations Hub hosts integrations from Kentico, partners, and the community as NuGet packages. Official integrations include Algolia search, Azure AI Search, Zapier, Google Tag Manager, GA4, Application Insights, and Cloudflare CDN. Digital Commerce integrations in preview. The May/June 2026 Refreshes expanded KentiCopilot with a Management MCP Server (content creation via Management API extensions) and Page Builder support. Total catalog remains modest compared to larger platforms, with gaps in DAM, translation, and general AI service connectors.
Xperience by Kentico is on a clear improving trajectory, with gains across nearly every composite dimension and no regressions. The April 2026 AIRA refresh is the dominant driver — the AIRA Usage Overview dashboard doubled AI observability scoring, while the new Segment Condition Builder, Campaign Manager Agent, and SEO & GEO Specialist Agent collectively lifted Capability, Build Simplicity, and Operational Ease. Practitioners should note that the AI tooling story has shifted from aspirational to operationally instrumented, and the auto-generated GraphQL endpoints per headless channel meaningfully strengthen the API delivery posture for composable builds.
Score Changes
The April 16, 2026 refresh introduced the AIRA Usage Overview — a dedicated tracking dashboard that displays credit consumption and request counts by feature over the last 30 days, directly addressing the prior observability gap. This moves Kentico into the 'basic usage tracking and cost visibility' band (45–65). Scores below 65 because per-user metrics, prompt effectiveness analytics, and quality trend monitoring are not yet documented.
The April 16, 2026 refresh introduced the AIRA Segment Condition Builder, which uses AI to translate references to pages and forms into segment condition rules, plus Identity Resolution that unifies customers, contacts, and members into singular profiles using configurable identifiers. These elevate the platform from rule-only to AI-assisted personalization where rules are AI-generated but execution remains traditional (per the 40–60 band). A genuine ML scoring/predictive segment engine comparable to Bloomreach Loomi or Sitecore CDP is still absent.
The SEO & GEO Specialist Agent (April 2026, production-ready) reviews pages for both classic SEO attributes and AI readability/comprehension, provides keyword-based scoring and prioritized recommendations — closing the previously noted gap of no in-box SEO audit/scoring tool. Multiple vanity URLs per page with canonical URL selection (June 2025), URL management application for centralized redirect management (May 2025), and forward-slash support in custom URLs (July 2025) give solid SEO URL hygiene. Standard meta title/description fields are on all content types. The community XperienceCommunity.SEO package adds automatic sitemap generation, dynamic robots.txt, and llms.txt. GEO scoring for AI crawler readability is a forward-looking differentiator.
The April 16, 2026 refresh added the Campaign Manager Agent to the AIRA Agentic Marketing Suite, completing the trio alongside Content Strategist and SEO & GEO Specialist. The Campaign Manager evaluates journey statistics against KPIs, analyzes audience contact group performance, and generates final campaign reports. Agents operate under admin permissions with approval gates. Scores below 75 because the roster is still smaller than Contentstack Agent OS and agent marketplaces are absent.
Each headless channel auto-generates a strongly-typed GraphQL API endpoint for content delivery, with polymorphic query optimization added in 2025. The April 2026 refresh (31.4.0) introduced a Headless REST API in preview for retrieving content items over HTTP with JSON responses, closing the previous GraphQL-only gap. Both REST and GraphQL are now available for delivery (REST still preview), and the May 2026 Management API additions for Page Builder components further round out the API surface.
Identity Resolution (April 2026, production-ready) unifies customer, contact, and member profiles under single identities and automatically merges profiles when visitors log in with existing accounts — a meaningful upgrade from the earlier preview-only CDP unified profiles. AIRA Segment Condition Builder (April 2026, production-ready) uses AI to assist marketers in defining complex multi-rule segment conditions. Widget-level personalization in Page Builder delivers separate content variants per contact group based on behavioral, demographic, and activity-based segments. Email widget personalization (June 2025) allows per-segment email variants. Membership Roles (March 2026) enable tiered channel-specific content access. No full page-level rules engine or real-time behavioral personalization yet.
The April 16, 2026 refresh added the AIRA Segment Condition Builder, letting marketers construct audience segments through natural language with AI translating references into condition rules. Combined with existing AIRA auto-tagging, campaign management, Customer Journey insights, and Content Strategist rewrite/publish via API, Xperience now has multiple AI workflow assists woven into editorial. Still short of the 70+ tier due to lack of documented bulk enrichment or stale content lifecycle automation.
A dedicated Campaigns feature (March 2026) combines campaign briefs, associated digital assets, and linked customer journeys with AIRA Campaign Insights for AI-driven KPI evaluation. The new production-ready Campaign Manager Agent (April 2026) evaluates campaign performance against KPIs, audience groups, and journey metrics and generates final reports comparing success across multiple campaigns — a significant step toward portfolio-level campaign orchestration. Email Builder (production March 2025) provides visual drag-and-drop email authoring with A/B testing of email subject/content. Marketing automation with conditional branching is native. Multi-channel coordination and a dedicated content calendar UI are still absent.
Built-in CDP unifies customers, contacts, and members into a single profile with admin-configurable identity resolution (April 2026), new segmentation tools, and extensible APIs. Identity resolution matches on external identifiers or native fields (e.g., member email) to merge profiles across touchpoints, enabling unified data for personalization and automation. Held at 71 because external CDP connectors (Segment, mParticle, Tealium) remain absent and B2B firmographic enrichment is limited.
Xperience by Kentico SaaS is publicly documented as designed for 99.9% uptime, with Kentico responsible for SaaS environment, Xperience Portal, and deployment API availability 24/7/365. Public status page at status.xperience-portal.com with uptime history. April 2026 Refresh added extensible SaaS uptime monitoring supporting up to 6 checker configurations across regions. Not higher because 99.9% is mid-tier vs. 99.95%+ from headless leaders, and historical uptime data not granularly published.
SaaS Portal includes extensible uptime monitoring (up to 6 custom checkers per environment with configurable URLs/HTTP methods/response codes, multi-region execution, and historical reporting) added in the April 16, 2026 Refresh — alongside existing dashboards for server errors, response time, CPU/memory, and Cloudflare-integrated security events. An AIRA Usage Overview dashboard tracks AI credit consumption. Microsoft Application Insights is bundled. Not higher because self-hosted deployments have no built-in monitoring and require custom APM, and even SaaS customers must configure alerting thresholds beyond Portal defaults.
Customer journey analytics (March 2025) visualizes contact progression and drop-off through journey stages with date-range filtering. AIRA Campaign Insights evaluates KPI performance across campaigns (March 2026), and the new Campaign Manager Agent (April 2026) generates final reports comparing success across multiple campaigns — extending the in-platform marketing analytics surface beyond single-campaign dashboards. Form submission tracking with channel and language metadata (October 2025) surfaces form performance. No native web analytics module comparable to KX13's visitor tracking — page views, sessions, and source attribution still require external tools (GA4/GTM).
The April 16, 2026 refresh added two KentiCopilot plugins: a Kentico Xperience 13 content auditor CLI tool and an AI-assisted content migration tool. These join the existing KentiCopilot MCP-based content modeling APIs, AIRA SDK for custom content agents, and Azure AI Search RAG-ready indexing. Still short of the 70+ tier because official LangChain/LlamaIndex integration guides and agent-optimized delivery endpoints remain undocumented.
Rich text editing is powered by Froala WYSIWYG editor (v5.0.0), with inline rich text editors available within Page Builder widgets. AIRA refinements went GA in April 2026, and the May 14, 2026 refresh expanded AIRA generation/refinement to text fields across pages, emails, headless items, and reusable content items — using linked items and page previews as context. Output remains HTML-based rather than a portable AST, limiting channel portability.
Xperience by Kentico ships a native CDP with rule-based Contact Groups, behavioral activity-based conditions, and unified Profiles that merge customers, contacts, and members. The April 16, 2026 refresh added admin-configurable identity resolution with flexible matching on external identifiers or native fields plus new segmentation tools and extensible APIs. Not higher because B2B firmographic enrichment and pre-built Segment/mParticle/Tealium connectors remain absent.
Comprehensive .NET extensibility: custom modules with DI, global event handlers for content lifecycle hooks, custom Page Builder widgets and sections, custom form components, and custom admin UI pages built with React. May 2026 Refresh adds configurable custom Marketing Automation actions and a KentiCopilot Management MCP Server with Management API extensions, enabling agentic content creation workflows via a pluggable architecture. Limited only by the requirement for .NET/C# skills — no low-code extension approach exists.
Kentico has tightened its Refresh cadence from ~6–8 weeks toward near-monthly: documented Refreshes include March, May, July, October, December 2025 and January, February, March 2026, with an April 16, 2026 Refresh landing back-to-back with March. Each Refresh bundles meaningful features (digital commerce GA, AIRA agents, form field conditions). Not higher because patch-level cadence between named Refreshes is still not independently visible.
SaaS cloud infrastructure is described as ready in 30 minutes, and the Kickstart .NET CLI workflow gives developers a running local instance quickly. However, content type modeling, channel setup, and Kentico-specific conventions add a half-day to full day before a working site is live for an experienced .NET developer. Monthly refresh cadence (Apr 16, 2026 release) continues to ship DX improvements but doesn't fundamentally accelerate first-value.
Kentico maintains a structured Developer Learning Map, Developer Kickstart guide, community quickstarts, a training-guides GitHub repo (v31+), and a Certified Developer path. The April 16, 2026 refresh added KentiCopilot Migration Tools (Content Auditor CLI + Content Migration Claude Code skill) that meaningfully improve the onboarding story for KX13 teams upgrading to XbyK — a major onboarding pathway. Still no in-app tour or first-class framework-specific (Next.js) guided path, so not higher.
Page Builder already lets marketers self-serve page layout, widget placement, and content edits post go-live, and the read-only inspection mode reduces friction for editors. The April 16, 2026 refresh further reduces developer dependency: AIRA now assists with segment condition building, a Campaign Manager agent provides cross-campaign lifecycle insights, and an SEO & GEO Specialist agent runs keyword-based page scoring — tasks that previously required dev or specialist involvement. Not higher because new widget types, page templates, and new content types still require developers.
The April 16, 2026 refresh expanded the AIRA SEO & GEO Specialist agent to analyze both 'human and AI readability and comprehension' and provide optimization recommendations for traditional search and AI-powered discovery experiences. Combined with one-click fixes for SEO titles, meta descriptions, schema markup, and auto alt-text on mass image upload, this is now a robust GA offering. Scores below 70 because on-page scoring dashboards and bulk metadata generation at scale are still not fully confirmed.
Xperience by Kentico holds entirely stable this review period, with no movement across any composite dimension — Capability remains at 62.3, Platform Velocity at 69.6, Cost Efficiency at 53.1, Build Simplicity at 56.5, Operational Ease at 59.8, and Compliance & Trust at 55.9. The platform continues to show its strongest positioning in Platform Velocity while Cost Efficiency and Compliance & Trust remain its relative weak points, suggesting Kentico's investment in product iteration has not yet translated into gains on the cost or governance fronts. All scores remain unchanged since the last review, reflecting a period of consolidation rather than active momentum in either direction.
Reach out to these highly trusted implementation partners, agencies and specialists.
Agencies, dev shops, and systems integrators vary wildly in how well they deliver on Xperience by Kentico. We don't take on implementation work ourselves.
Tell us what you're building and we'll come back with a shortlist of firms with a genuine track record on this platform.