Overview of Estuary security and compliance
masterEstuary provides several mechanisms to ensure data security and regulatory compliance. Security is managed through technical features, flexible deployment models, and adherence to industry standards.
Security Features
Estuary implements a defense-in-depth strategy using:
- Data encryption: Protection for data both in motion and at rest.
- Immutable infrastructure: Reducing the attack surface by using non-persistent, reproducible infrastructure.
- Zero-trust network model: Ensuring every request is authenticated and authorized.
- Role-based access control (RBAC): Managing user permissions through granular roles.
Deployment Options
For organizations requiring higher levels of isolation, Estuary supports:
- Private deployments: Dedicated environments.
- Bring Your Own Cloud (BYOC): Deployments where the data plane remains within your own private cloud infrastructure to maintain data sovereignty.
Compliance Standards
Estuary maintains compliance with several major regulatory frameworks:
- Healthcare: HIPAA
- Privacy: GDPR, CCPA, and CPRA
- Security Audits: SOC 2 Type II certified