Security and Certification
Gain confidence that your data is protected and we follow a rigorous testing and evaluation program.
Security always at the forefront
Security has been baked into Instaclustr’s platform and operations since Day One. We understand that you are trusting us with your valuable data, and we take that responsibility very seriously. As part of our security focus, several of our offerings are PCI-certified, and we have been SOC 2 compliant for several years. Both of these certifications require individual and regular external compliance audits.
Our security program is designed around methodologies that include security considerations built into our platform, as well as continual review, testing, and monitoring of our environment. With Instaclustr managed services, our customers can achieve both SOC 2 certification and HIPAA (Health Insurance Portability and Accountability Act) compliance.
- SOC 2 Certification
The internationally recognized SOC 2 standard is a set of compliance requirements verifying the security practices of service providers and other companies who store sensitive customer data in the cloud. To achieve compliance, Instaclustr underwent an independent technical audit to assess its policies and procedures in accordance with three trusted principles: Security, Availability, and Confidentiality.
While the Security trust principle is a mandatory component of the audit, Instaclustr chose to include the optional Availability and Confidentiality principles to further demonstrate to customers our strong data security capabilities.
With this designation, Instaclustr becomes the first—and currently the only—hosted Cassandra service provider to provide a security environment audited to meet the SOC 2 standards of the American Institute of Certified Public Accountants (AICPA).
Holding SOC 2 compliance is now part of Instaclustr’s formal security program, which includes regular independent penetration testing and participation in a bug-bounty program to encourage third-party reporting of potential security issues.
- PCI Certification
We offer the ability to create clusters that are PCI certified for Cassandra and Kafka on AWS. The PCI-DSS (Payment Card Industry Data Security Standard) is the payment card industry’s mandated information security standard and applies to all organizations that store, process, and/or transmit cardholder data. PCI-DSS certification requirements dictate that all system components either within the cardholder data environment or with access to it must feature specific and strict technical, physical, and operational security controls.
- Instaclustr Certification Framework
- Enterprise-Grade and Production-Ready Certified Apache Cassandra
Our certification framework program continually assesses the health of selected open source projects and tests specific versions of open source software within the project, applying a repeatable and reproducible methodology.
Be assured that specific releases of Apache Cassandra have been tested across a range of functional, performance, and integration properties. This is completed prior to any Cassandra release being added to the Instaclustr Managed Platform for deployment in production environments.