Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document explains the security measures Databricks has committed to following to protect customer data, and those commitments are written into the customer contract — not just an informal policy. Databricks runs daily vulnerability scans, requires security checks before new code goes live, and fixes its most critical vulnerabilities before other work. Customers can review an independent third-party penetration test report through Databricks's publicly available due diligence package.
This document establishes Databricks's contractual and operational security commitments to customers, formalized through a Security Addendum that is part of the customer agreement. It defines a Vulnerability Management Program with tiered severity handling, including highest-urgency prioritization of Severity-0 vulnerabilities above other rollouts, daily authenticated vulnerability scans of first-party and third-party/open-source packages, SAST and DAST code analysis, and mandatory security scanning before code or images are promoted to production. Penetration tests are scoped to major releases, new services, and security-sensitive features, and no such test may be marked as passed while material findings remain unresolved. Databricks maintains strict access controls on internal employee access to production systems, customer environments, and customer data, and holds ISO 27001, ISO 27017, ISO 27018, and SOC 2 Type II certifications, with compliance offerings for PCI-DSS, HIPAA, and FedRAMP.
As a Databricks customer, your data is covered by enforceable security commitments documented in the Security Addendum of your customer agreement, not merely by internal policy. Databricks applies strict controls limiting which employees can access production systems, customer environments, and customer data, and remediates material vulnerabilities before closing any penetration test as passed. You can access Databricks's platform-wide third-party penetration test report and remediation timeline commitments directly through the publicly available due diligence package, without a separate request.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Databricks has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle All Material Penetration Test Findings Must Be Addressed and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.