Security at entropyDB

Your data security is our top priority. We implement industry-leading practices to protect your information.

🔐

Encryption

Planned

AES-256 encryption at rest, TLS 1.3 in transit. Field-level encryption for sensitive data.

Infrastructure-level encryption (AES-256 at rest via AWS, TLS in transit) is real. Application-level field encryption exists in code but is not yet wired into query paths.

🛡️

Access Control

Beta

Role-based access control (RBAC) with row-level security. Multi-factor authentication required.

RBAC now genuinely governs every data-plane request. Row-level security policies and MFA are not yet implemented.

📋

Compliance

Planned

SOC2 Type II, HIPAA, GDPR, CCPA compliant. Regular third-party audits.

No certification has been completed. This is a business/legal-track initiative planned for after Cloud GA, not an engineering task — see the product roadmap.

🔍

Audit Logging

Beta

Comprehensive, tamper-proof audit trails. Track all data access and modifications.

Real audit events are now recorded for every data-plane operation. Tamper-proofing and long-term retention at scale are not yet independently verified.

🚨

Threat Detection

Planned

Real-time threat monitoring and anomaly detection. 24/7 security operations center.

No automated threat-detection system or security operations center exists yet.

🔧

Vulnerability Management

Planned

Regular penetration testing and security assessments. Rapid patching of vulnerabilities.

Dependency CVEs are patched as found (internal practice, not yet formalized). No third-party penetration test has been commissioned — a business-track item planned before Cloud GA.

Infrastructure Security

BetaVPC isolation, automated encrypted backups, and point-in-time recovery are real and running today. Items below marked with the gray Planned badge (WAF, IDS/IPS, geographic replication, formal disaster-recovery/incident-response procedures) are not yet built — the infrastructure is currently single-region.

Network Security

  • • VPC isolation and private networking
  • • Rate limiting (auth endpoints, real) · DDoS protection (Planned)
  • • Web application firewall (WAF) (Planned)
  • • Intrusion detection/prevention systems (Planned)

Data Protection

  • • Automated encrypted backups
  • • Point-in-time recovery (PITR)
  • • Geographic replication options (Planned — single-region today)
  • • Disaster recovery procedures (Planned formal runbook)

Platform Security

  • • Secure software development lifecycle
  • • Container security scanning (Planned)
  • • Dependency vulnerability monitoring (patched as found)
  • • Regular security training for staff (Planned)

Incident Response

  • • Real Prometheus/Grafana monitoring · 24/7 SOC (Planned)
  • • Documented incident response plan (Planned)
  • • Rapid notification procedures (Planned)
  • • Post-incident analysis and remediation (Planned)

Responsible Disclosure

We value the security community. If you discover a vulnerability, please report it to our security team.

Report a Vulnerability