Security and Certification

Gain confidence that your data is protected and we follow a rigorous testing and evaluation program.

    Security always at the forefront

    Security has been baked into Instaclustr’s platform and operations since Day One. We understand that you are trusting us with your valuable data, and we take that responsibility very seriously. As part of our security focus, several of our offerings are PCI-certified, and we have been SOC 2 compliant for several years. Both of these certifications require individual and regular external compliance audits.

    Our security program is designed around methodologies that include security considerations built into our platform, as well as continual review, testing, and monitoring of our environment. With Instaclustr managed services, our customers can achieve both SOC 2 certification and HIPAA (Health Insurance Portability and Accountability Act) compliance.

    Learn more about the security process we follow in our operations environment

    Gain access to Instaclustr certification documentation
    • SOC 2 Certification

      The internationally recognized SOC 2 standard is a set of compliance requirements verifying the security practices of service providers and other companies who store sensitive customer data in the cloud. To achieve compliance, Instaclustr underwent an independent technical audit to assess its policies and procedures in accordance with three trusted principles: Security, Availability, and Confidentiality.

      While the Security trust principle is a mandatory component of the audit, Instaclustr chose to include the optional Availability and Confidentiality principles to further demonstrate to customers our strong data security capabilities.

      With this designation, Instaclustr becomes the first—and currently the only—hosted Cassandra service provider to provide a security environment audited to meet the SOC 2 standards of the American Institute of Certified Public Accountants (AICPA).
      Holding SOC 2 compliance is now part of Instaclustr’s formal security program, which includes regular independent penetration testing and participation in a bug-bounty program to encourage third-party reporting of potential security issues.

    • PCI Certification

      We offer the ability to create clusters that are PCI certified for Cassandra and Kafka on AWS. The PCI-DSS (Payment Card Industry Data Security Standard) is the payment card industry’s mandated information security standard and applies to all organizations that store, process, and/or transmit cardholder data. PCI-DSS certification requirements dictate that all system components either within the cardholder data environment or with access to it must feature specific and strict technical, physical, and operational security controls.

    Certification Framework

    We follow a rigorous testing and evaluation program for selected open source technologies.
    Instaclustr Certification Framework

    Our certification framework program continually assesses the health of selected open source projects and tests specific versions of open source software within the project, applying a repeatable and reproducible methodology.

    Learn more about the program.

    Enterprise-Grade and Production-Ready Certified Apache Cassandra

    Be assured that specific releases of Apache Cassandra have been tested across a range of functional, performance, and integration properties. This is completed prior to any Cassandra release being added to the Instaclustr Managed Platform for deployment in production environments.

    Learn more about Certified Cassandra.

    Spin up a cluster in minutes