Change record
CA-C-004683
Databricks Security Practices
Entity
Date detected
August 28, 2026
Effective date
August 28, 2026
Severity
Low
Direction
Positive
Taxonomy
Security change
Changes
+49 sentences added · 2 sentences modified

Impact Summary

Low Positive for users
Affected users
All users Security researchers Enterprise customers

Databricks expanded its Databricks Security Practices document in an update detected on August 28, 2026, adding extensive detail about its bug bounty program, customer penetration testing policies, cloud console access controls, production system access procedures, and secure software development lifecycle practices. The prior version contained minimal language about these areas; the updated version now explicitly describes how Databricks operates its HackerOne bug bounty program (over 200 reports from 100+ researchers), defines permissible scope for customer penetration testing, details multifactor authentication and VPN requirements for employee production access, and outlines its SDLC practices including code review, security scanning, and release management procedures. This adds transparency about Databricks' internal security operations and customer testing options but does not materially alter customer obligations or data rights.

Stay ahead of the changes
Track Databricks and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

What this means for you

The updated security practices disclose Databricks' internal security operations, bug bounty program structure, and customer penetration testing policies. These additions establish transparency about how Databricks operates its security infrastructure but do not impose new requirements on customers or change data collection, retention, or use practices. Customers interested in performing authorized security testing against Databricks can now reference explicit guidance: vulnerability scans may be run on data plane systems within customer cloud accounts, penetration tests must be contained within the data plane, or security researchers may join the formal bug bounty program to access a dedicated Databricks deployment.

Key Clauses Affected

Bug Bounty Program Details

Documented HackerOne program structure, response timeframes, and researcher incentive practices; no customer obligations.

Customer Penetration Testing Scope

Clarified that data plane testing is permitted within customer accounts, but control plane testing requires bug bounty program participation.

Employee Production Access Controls

Documented multifactor authentication, VPN requirements, and time-limited access procedures for Databricks staff accessing production systems.

Full clause-by-clause analysis available with Insight.

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
0eb2a219a956e72f7703bf9fca8351c1290d0540d29bbf71e6dae3ff2897a2e6
July 11, 2026 13:45 UTC
✓ Verified
Current Version
80bb086d35becead8fd53050ce37a7d10d7ae0b3a6b56a42b8b92e21f71580c3
August 28, 2026 00:55 UTC
✓ Verified
Change Detected
August 28, 2026 00:55 UTC
Analysis Methodology
✓ Verified
Source Document
https://www.databricks.com/trust/trust
Citation Record
Entity: Databricks
Document: Databricks Security Practices
Record ID: CA-C-004683
Captured: 2026-08-28 00:55:34 UTC
URL: https://conductatlas.com/change/2026-08-28-databricks-databricks-security-practices-4683/
Accessed: Aug. 28, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

Databricks enhanced its security documentation by adding 49 sentences describing its bug bounty program, customer penetration testing framework, employee access controls, and SDLC practices. This is a disclosure enhancement with no new binding obligations on …

🔒 Full institutional analysis

Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.

Unlock the full institutional analysis — Insight

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-004683.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
Databricks Security Practices
Entity
Databricks
Captured
August 28, 2026
Source URL
https://www.databricks.com/trust/trust
More from Databricks
Aug 28, 2026 Low
Databricks Terms of Service

Databricks updated terminology in its Terms of Service to refer to the 'Databricks Data + AI Platform Services' instead of …

Jun 12, 2026 Low
Databricks Terms of Service

Databricks updated three contact email addresses in its Terms of Service on June 12, 2026. Child data inquiries now go …

Jun 10, 2026 Low
Databricks Privacy Notice

Databricks updated the contact email address for privacy inquiries in their Privacy Notice from an unspecified address to privacy@databricks.com. This …

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Stay ahead of the changes

Track Databricks policy changes

Get alerted when this policy changes again, including what changed and why it matters.

All Databricks changes →