Tenant isolation
Every cluster is dedicated to one organization. Nodes are not shared between customers and there is no multi-tenant index space to escape from.
Security & compliance
Most of a vendor security review is the same twenty questions. Here are ours, answered in public, with a questionnaire on request for the rest.
Data residency
Clusters run on dedicated hardware in Europe, not public cloud and not shared instances. Data written to a cluster stays in the region it was provisioned in, and we don't replicate it elsewhere for our own convenience.
We are fully GDPR compliant. A data processing agreement is available on request, and our subprocessor list comes with the security questionnaire.
Residency
Europe
GDPR
Compliant
SOC 2
Built to SOC 2 controls · audit in progress
Infrastructure
Dedicated bare metal
Uptime SLA
99.9% monthly, with service credits
Being precise about SOC 2
We've built to SOC 2 controls and the audit is in progress, but we don't have an attestation report to hand you today. Vendors who say "SOC 2 compliant" without one are describing exactly this position, and you will find out at the point you ask for the report, so we'd rather say it here. When the audit completes, this page changes.
Controls
Every cluster is dedicated to one organization. Nodes are not shared between customers and there is no multi-tenant index space to escape from.
Delegate cluster access to your identity provider over OIDC or SAML, or use OpenSearch's internal user database. Console access supports Google and GitHub sign-in.
Each endpoint takes its own IP allowlist, the cluster API and Dashboards separately, so exposure can be scoped to the networks that need it.
Cluster credentials can be rotated at any time from the console, API or Terraform, without downtime and without contacting us.
Snapshots go to an S3 bucket you own and control, on a schedule you set. Your recovery position doesn't depend on your account with us staying open.
Traffic to every endpoint is TLS-terminated with certificates we issue and renew, including for custom hostnames.
Access control
Organization roles are cumulative rather than a grid of independent permissions, which is simpler to reason about and easier to audit. Cluster credentials require Write; nobody below it can read them.
| Role | Can do |
|---|---|
| Read | View the organization, its clusters and its invoices. |
| Billing | Everything above, plus the billing portal and payment details. |
| Write | Everything above, plus create, change and delete clusters, and view or rotate cluster credentials. |
| Admin | Everything above, plus invite and remove members, change roles, and edit organization settings. |
| Owner | Everything above, plus grant ownership and delete the organization. |
Availability
The uptime commitment is a monthly percentage backed by service credits, written into the terms rather than a marketing page. Every incident is published on our status page, including the ones nobody reported.
Maintenance happens inside a weekly window you choose, in UTC. Leave it unset and we work around your traffic instead.
Support response
Availability and support are separate commitments. Support is email on every tier, at [email protected], with these first-response targets.
| Severity | Response | Cover |
|---|---|---|
| Production cluster down | 1 hour | 24×7 |
| Production degraded | 4 hours | 24×7 |
| Non-production impaired | 12 hours | Business days |
| General guidance | 24 hours | Business days |
We keep a completed security questionnaire, a DPA and a subprocessor list ready to send. Ask and you'll have them the same day.