Encryption
TLS 1.3 for all connections. Optional mTLS for service-to-service authentication. Data encrypted at rest via Parquet + S3 SSE.
Encryption
TLS 1.3 for all connections. Optional mTLS for service-to-service authentication. Data encrypted at rest via Parquet + S3 SSE.
Authentication
JWT/OIDC (Okta, Auth0, Azure AD, Google), API keys with rotation, and mTLS client certificates.
Authorization
RBAC with 5 built-in roles: admin, writer, reader, analyst, monitor. Namespace isolation for multi-tenancy.
Audit
All authentication events, queries, and admin actions logged. Structured JSON format for SIEM integration.
| Standard | Status |
|---|---|
| SOC2 Type II | Ready (audit logging, RBAC, encryption) |
| MiFID II | Ready (trade audit trail, access controls) |
| GDPR | Namespace isolation, data deletion support |
| PCI DSS | TLS 1.3, access controls, audit logging |
Found a security issue? Please report it responsibly:
📧 security@zeptodb.com (placeholder)
We aim to acknowledge reports within 48 hours and provide a fix timeline within 5 business days.
For detailed configuration, see the Security Operations Guide and SSO Integration Guide.