ScyllaDB Security Policy

Last modified: April 13, 2026

Introduction
ScyllaDB Ltd., together with its affiliated companies (collectively, “ScyllaDB,” “Company,” “we,” “us,” or “our”), is committed to transparency regarding the security measures it implements to protect data processed in connection with the provision of its services. For information about how ScyllaDB collects, uses, and shares Personal Data, including definitions and legal bases, please see our Privacy Policy.

This Security Policy outlines the Company’s technical, physical, and organizational security practices and applies to all systems, personnel, and processes involved in the delivery of ScyllaDB services.

Physical Access Control
The Company implements measures designed to protect the systems and environments used to store data from unauthorized physical access.

Data processed by the Company in its capacity as a controller may be stored in Google Workspace and by third-party service providers. Data processed by the Company as a processor may be stored on cloud infrastructure chosen by its customers, including Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure.

The Company secures physical access to its offices by ensuring that only authorized individuals — such as employees and authorized external parties (for example, maintenance staff and visitors) — can access Company offices through security locks, alarm systems, and other physical security measures.

Physical media containing customer data is securely decommissioned in accordance with industry best practices, including cryptographic erasure or physical destruction, prior to disposal or reuse.

System Control
Access to the Company’s systems and databases is highly restricted, allowing only authorized personnel with approved access to use them. The Company enforces multi-factor authentication (MFA) for access to critical systems and uses single sign-on (SSO) and zero-trust network access controls where applicable. Appropriate safeguards are also implemented for remote access and wireless computing capabilities.

Employees are assigned individual credentials that permit access to data strictly in accordance with their roles and only to the extent required. There is continuous monitoring of access and authentication activity. The Company uses automated tools to identify non-human login attempts and rate-limit them to help reduce the risk of brute-force attacks.

Privileged access to production systems is limited to authorized personnel based on job responsibilities, protected by strong authentication and controlled access mechanisms, and reviewed periodically. Access to customer data is not part of normal operations and is limited to exceptional support or reliability scenarios on a least-privilege basis.

Asset Management
The Company maintains a comprehensive inventory of hardware and software assets used in the delivery of its services. Assets are classified according to their sensitivity and criticality. The inventory is reviewed and updated regularly to ensure accuracy. Upon decommissioning, assets are securely wiped or destroyed in accordance with data classification requirements, and disposal is documented for audit purposes.

Data Access Control
User authentication and authorization measures are designed to ensure that access to data is restricted solely to authorized personnel and that data is not accessed, modified, copied, used, transferred, or deleted without appropriate authorization. Access to data and actions involving data require authenticated credentials, which are managed, periodically reviewed, and revoked when applicable.

Each employee may perform actions only in accordance with the permissions granted to them by the Company. The Company conducts ongoing reviews of access authorizations to assess whether access remains required, and revokes access promptly upon termination of employment or when access is no longer needed. ScyllaDB also implements logical segregation controls designed to help ensure that customers can access only their own environments and data.

A formal employee offboarding process is in place to ensure timely revocation of system credentials, collection of company devices, and audit of access permissions upon termination of employment or change of role.

Organizational and Operational Security
The Company invests significant effort and resources in maintaining compliance with its security policies and practices, including providing employees with regular security awareness training. The Company works to raise awareness of the risks associated with data processing.

The Company has implemented safeguards for its hardware and software environments, including firewalls, endpoint protection, intrusion detection/prevention systems (IDS/IPS), and network segmentation designed to protect against malicious software and unauthorized access. DDoS protection mechanisms are in place to maintain service availability.

Security and privacy considerations are incorporated into ScyllaDB’s software development lifecycle (SDLC) and change management processes, including secure code reviews, static and dynamic analysis (SAST/DAST), and dependency vulnerability scanning prior to production deployment.

Logging and Monitoring
The Company maintains centralized security event logging across its production systems. Logs are collected, retained, and reviewed to detect suspicious activity, unauthorized access attempts, and anomalous behavior. A Security Information and Event Management (SIEM) system is used to aggregate and correlate security events and generate alerts for investigation. Audit logs are protected from unauthorized modification and retained in accordance with applicable compliance requirements.

Encryption
Data transfers are protected through encryption in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256. All encryption data can be found here https://cloud.docs.scylladb.com/stable/security/concepts.html

Transfer Control
Where required, ScyllaDB enters into appropriate data processing agreements with customers and service providers in accordance with applicable law. For additional information, please see the Data Processing Agreement.

Input Control
The Company implements measures designed to provide transparency and traceability for changes to and deletion of data.

Availability Control
The Company maintains backup policies and associated measures, including monitoring of operational parameters relevant to backup operations. The Company’s systems include automated backup procedures, and regular checks are performed to help confirm that backups can be successfully restored, as required and applicable.

The Company also maintains disaster recovery and business continuity processes, including periodic restore testing to validate recoverability.

Incident Response
The Company maintains incident response procedures designed to detect, respond to, and recover from security incidents in a timely manner. In the event of a security incident affecting customer data, the Company will notify affected parties without undue delay, as required by applicable data protection laws and the terms of its Data Processing Agreement.

Incident response procedures are reviewed and tested periodically to ensure their effectiveness.

International Data Transfer
ScyllaDB operates globally and may transfer data across international borders. The Company seeks to ensure that such transfers are conducted securely and in compliance with applicable data protection laws.

The Company implements technical and organizational measures, including encryption in transit and at rest and strict access controls, to protect data integrity and confidentiality regardless of the geographic location of processing. For information about the legal mechanisms governing international data transfers, including Standard Contractual Clauses, adequacy decisions, and applicable data privacy frameworks, please see our Privacy Policy, Data Processing Agreement, and Data Privacy Framework Statement.

Data Retention
For information about how ScyllaDB retains data, including applicable retention periods, please see the Data Retention section of our Privacy Policy.

Job Control and Third-Party Contractors and Service Providers
All employees are required to execute employment agreements that include confidentiality obligations and provisions requiring compliance with applicable data security practices. As permitted by applicable law, the Company conducts background checks for new employees and contractors as part of its pre-employment screening process. In the event of non-compliance with Company policies, ScyllaDB implements appropriate measures to promote ongoing compliance.

Before engaging third-party contractors and service providers, the Company undertakes due diligence reviews appropriate to the nature of the services provided. Where applicable, the Company enters into agreements that include appropriate data protection and security obligations.

For information about sub-processors and third-party recipients, please see the Data Processing Agreement and the Privacy Policy.

Supply Chain and Third-Party Security
ScyllaDB actively manages supply chain security risks associated with third-party software components and service providers. Open-source and third-party dependencies are monitored for known vulnerabilities on an ongoing basis. A current list of sub-processors is maintained and published in the ScyllaDB Trust Center. Significant changes to the sub-processor list are communicated to customers in accordance with applicable data processing agreements.

Artificial Intelligence Security
Where AI or machine learning tools are used internally in connection with the delivery of ScyllaDB services, the Company applies appropriate governance controls, including vendor security assessments, data access restrictions, and usage policies. ScyllaDB does not use customer data to train external AI models without explicit authorization.

Penetration Testing
External penetration tests are performed annually by reputable third-party vendors. Penetration tests and security scans are designed to identify vulnerabilities across ScyllaDB’s production systems and customer-facing services.

In addition, ScyllaDB conducts vulnerability scans on a periodic basis and after significant changes in the environment. Identified deficiencies are remediated in a timely manner. Encryption standards, network configurations, and access controls are validated as part of the testing scope.

Compliance Programs
ScyllaDB operations, policies, and procedures are reviewed and audited regularly to help ensure alignment with applicable standards for a cloud service provider. Compliance certifications and attestations are assessed by independent third-party auditors. Current certifications, attestations, and scope information are available in ScyllaDB’s Trust Center.

ScyllaDB customers remain responsible for complying with applicable laws, regulations, and privacy requirements relevant to their own use of ScyllaDB services.

Reporting a Security Issue
ScyllaDB dedicates considerable resources to helping ensure secure code and infrastructure for its products and services. If you believe you have found a security vulnerability in any of our products, please report it via our vulnerability reporting form. Please include a brief description, detailed steps to reproduce, and the potential impact. Vulnerabilities are classified using the Common Vulnerability Scoring System (CVSS) to prioritize remediation.

For additional information about ScyllaDB’s Bug Bounty Program, including scope and eligibility, please visit the Trust Center and Bug Bounty Program pages.

Responsible Disclosure Policy
We encourage responsible disclosure and will investigate legitimate reports and work to remediate issues as appropriate. During your research, please make every effort to maintain the integrity of any data you encounter, avoid violating any person’s privacy, and avoid degrading our offerings. Please give ScyllaDB a reasonable opportunity to investigate and address any vulnerabilities before making them public. In return, we will investigate reports promptly and will not take legal action against you for good-faith security research conducted in accordance with this policy.

ScyllaDB Ltd. | security@scylladb.com | www.scylladb.com/trust-center