Security & compliance

The answers, before you have to ask for them.

Most of a vendor security review is the same twenty questions. Here are ours, answered in public, with a questionnaire on request for the rest.

Data residency

Your data stays in Europe.

Clusters run on dedicated hardware in Europe, not public cloud and not shared instances. Data written to a cluster stays in the region it was provisioned in, and we don't replicate it elsewhere for our own convenience.

We are fully GDPR compliant. A data processing agreement is available on request, and our subprocessor list comes with the security questionnaire.

Residency

Europe

GDPR

Compliant

SOC 2

Built to SOC 2 controls · audit in progress

Infrastructure

Dedicated bare metal

Uptime SLA

99.9% monthly, with service credits

Being precise about SOC 2

Controls in place. Report not yet.

We've built to SOC 2 controls and the audit is in progress, but we don't have an attestation report to hand you today. Vendors who say "SOC 2 compliant" without one are describing exactly this position, and you will find out at the point you ask for the report, so we'd rather say it here. When the audit completes, this page changes.

Controls

What you can configure, and what we guarantee.

Tenant isolation

Every cluster is dedicated to one organization. Nodes are not shared between customers and there is no multi-tenant index space to escape from.

Authentication you choose

Delegate cluster access to your identity provider over OIDC or SAML, or use OpenSearch's internal user database. Console access supports Google and GitHub sign-in.

Network restriction

Each endpoint takes its own IP allowlist, the cluster API and Dashboards separately, so exposure can be scoped to the networks that need it.

Credential rotation

Cluster credentials can be rotated at any time from the console, API or Terraform, without downtime and without contacting us.

Backups you hold

Snapshots go to an S3 bucket you own and control, on a schedule you set. Your recovery position doesn't depend on your account with us staying open.

Encryption

Traffic to every endpoint is TLS-terminated with certificates we issue and renew, including for custom hostnames.

Access control

Five roles, each a superset of the last.

Organization roles are cumulative rather than a grid of independent permissions, which is simpler to reason about and easier to audit. Cluster credentials require Write; nobody below it can read them.

Role Can do
Read View the organization, its clusters and its invoices.
Billing Everything above, plus the billing portal and payment details.
Write Everything above, plus create, change and delete clusters, and view or rotate cluster credentials.
Admin Everything above, plus invite and remove members, change roles, and edit organization settings.
Owner Everything above, plus grant ownership and delete the organization.

Availability

99.9%, and a public record of it.

The uptime commitment is a monthly percentage backed by service credits, written into the terms rather than a marketing page. Every incident is published on our status page, including the ones nobody reported.

Maintenance happens inside a weekly window you choose, in UTC. Leave it unset and we work around your traffic instead.

Support response

Availability and support are separate commitments. Support is email on every tier, at [email protected], with these first-response targets.

Severity Response Cover
Production cluster down 1 hour 24×7
Production degraded 4 hours 24×7
Non-production impaired 12 hours Business days
General guidance 24 hours Business days

Need the long form?

We keep a completed security questionnaire, a DPA and a subprocessor list ready to send. Ask and you'll have them the same day.