Databricks expanded its Databricks Security Practices document in an update detected on August 28, 2026, adding extensive detail about its bug bounty program, customer penetration testing policies, cloud console access controls, production system access procedures, and secure software development lifecycle practices. The prior version contained minimal language about these areas; the updated version now explicitly describes how Databricks operates its HackerOne bug bounty program (over 200 reports from 100+ researchers), defines permissible scope for customer penetration testing, details multifactor authentication and VPN requirements for employee production access, and outlines its SDLC practices including code review, security scanning, and release management procedures. This adds transparency about Databricks' internal security operations and customer testing options but does not materially alter customer obligations or data rights.
The updated security practices disclose Databricks' internal security operations, bug bounty program structure, and customer penetration testing policies. These additions establish transparency about how Databricks operates its security infrastructure but do not impose new requirements on customers or change data collection, retention, or use practices. Customers interested in performing authorized security testing against Databricks can now reference explicit guidance: vulnerability scans may be run on data plane systems within customer cloud accounts, penetration tests must be contained within the data plane, or security researchers may join the formal bug bounty program to access a dedicated Databricks deployment.
Documented HackerOne program structure, response timeframes, and researcher incentive practices; no customer obligations.
Clarified that data plane testing is permitted within customer accounts, but control plane testing requires bug bounty program participation.
Documented multifactor authentication, VPN requirements, and time-limited access procedures for Databricks staff accessing production systems.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Databricks enhanced its security documentation by adding 49 sentences describing its bug bounty program, customer penetration testing framework, employee access controls, and SDLC practices. This is a disclosure enhancement with no new binding obligations on …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-004683.
Databricks updated terminology in its Terms of Service to refer to the 'Databricks Data + AI Platform Services' instead of …
Databricks updated three contact email addresses in its Terms of Service on June 12, 2026. Child data inquiries now go …
Databricks updated the contact email address for privacy inquiries in their Privacy Notice from an unspecified address to privacy@databricks.com. This …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.