Security
In our highly interconnected world, to care for IT security, safety, and data privacy is more important than ever. Everything we do at CrateDB has a special focus on security—including our core database product, CrateDB, our cloud offering CrateDB Cloud, our integrations, and our customer and partner support.
Reporting security issues
If you have any security concerns related to the CrateDB product, services or online properties, reach out to our security team at security@crate.io.
Please, do not publish or disclose any of your concerns or findings publicly, and do not use our public issue trackers for these reports due to their sensitive nature. Thank you so much for your understanding.
You will hear back from us within one business day, and we'll keep you in the loop while investigating the reported issue.
Security in CrateDB Cloud
Every service offered by CrateDB Cloud operates exclusively through HTTPS or other encrypted protocols, adhering strictly to contemporary security best-practices. For utmost protection, customer clusters are accessible solely via HTTPS and PostgreSQL's wire protocol, which includes TLS encryption.
ISO 27001 Certification
CrateDB Cloud is ISO 27001 certified. Read the announcement >
ISO/IEC 27001 is the international standard for information security management systems (ISMS) established by the International Organization for Standardization. The ISO/IEC 27001 standard "provides companies of any size and from all sectors of activity with guidance for establishing, implementing, maintaining and continually improving an information security management system".
See the official CrateDB ISO 27001 certificate >
SOC 2 Type 2 Certification
CrateDB Cloud is SOC 2 Type 2 certified. Read the announcement >
SOC 2 (Service Organization Controls 2) is a rigorous auditing standard developed by the American Institute of Certified Public Accountants (AICPA). It ensures that service providers effectively protect customer data based on five key principles: security, privacy, availability, processing integrity, and confidentiality. By achieving SOC 2 Type 2 compliance, we have demonstrated to our customers and partners that we have established and maintained effective controls over our systems and data throughout the entire year.
HIPAA Compliance
The Health Insurance Portability and Accountability Act (HIPAA) was created in 1996 to govern the flow and sharing of personal health information (ePHI). CrateDB is HIPAA ready and enables covered entities and their business associates to leverage CrateDB to store, process, and analyze ePHI.
GDPR Compliance
The General Data Protection Regulation (GDPR) regulates the use and protection of personal data originating from the European Economic Area (EEA) and provides individuals rights with regard to their data. CrateDB provides our customers the necessary capabilities for building GDPR compliance.
CCPA Compliance
The California Consumer Privacy Act (CCPA) creates consumer rights relating to the access to, deletion of, and sharing of personal information that is collected by businesses. CrateDB is committed to supporting its customers in their CCPA compliance efforts.
Open Source Distribution
If you are using the open source distribution available for download, follow the recommendation mentioned in the CrateDB Documentation in order to keep the system as secure as possible.
SSL/TLS encryption is available and is recommendable to be used, and the same can be enabled as documented. Initially the connections to CrateDB are not encrypted by default, since it requires valid x509 certificates.