Security
Compliance & Certifications
Meeting the highest international standards for data protection and operational security.
CrateDB is trusted by organizations that operate in highly regulated environments — from manufacturing and energy to finance and SaaS.
Security and compliance are built into our DNA.
Through rigorous certification programs, auditing, and security governance, CrateDB ensures that your data platform aligns with global standards for confidentiality, integrity, and availability. Whether running CrateDB Cloud or self-managed deployments, you benefit from practices that meet enterprise-grade compliance requirements.
ISO 27001: Information Security Management
CrateDB Cloud is certified under ISO 27001, the internationally recognized standard for information security management systems (ISMS).
This certification confirms that CrateDB maintains formalized processes for:
- Risk management and mitigation
- Data confidentiality, integrity, and availability
- Continuous monitoring and improvement of information security controls
SOC 2 Type 2: Trust and Accountability
CrateDB Cloud is SOC 2 Type 2 compliant on AWS and Azure, validating the security, availability, and confidentiality of the service.
This independent audit, conducted annually, assesses CrateDB’s controls across:
This independent audit, conducted annually, assesses CrateDB’s controls across:
- System security and data access
- Availability and uptime
- Confidentiality and data privacy practices
Secure by design
Beyond certifications, CrateDB’s architecture and operational practices align with industry security frameworks and best practices:
- Encryption at rest and in transit protects data across all layers.
- Role-Based Access Control (RBAC) ensures principle-of-least-privilege enforcement.
- Audit logging provides full traceability for compliance audits.
- Vulnerability management and regular patching protect the system against emerging threats.
- Cloud infrastructure hardening follows CIS and NIST best practices.
Why it matters
- Regulatory readiness: Meet compliance requirements for GDPR, ISO, SOC 2, and other regional mandates.
- Enterprise trust: Demonstrate data protection to partners, auditors, and customers.
- Operational assurance: Proven controls for data security, incident management, and disaster recovery.
- Peace of mind: A security program continuously monitored, audited, and improved by dedicated professionals.