25 Total
8 High severity
13 Medium severity
4 Low severity

Key Facts

What does Databricks require regarding material findings from a penetration test?
Databricks requires that all material findings from a penetration test be addressed before that test can be marked as passed.
What does Databricks provide to all its customers in its Security Addendum?
Databricks provides a contractual commitment to security, written in plain language, to all its customers, captured in the Security Addendum of the customer agreement.
Where is Databricks's contractual commitment to security captured?
Databricks provides a contractual commitment to security, written in plain language, to all its customers, captured in the Security Addendum of the customer agreement.
What does Databricks perform daily?
Databricks performs daily authenticated vulnerability scans of Databricks and third-party/open-source packages used by Databricks, along with static and dynamic code analysis (SAST and DAST).
What does Databricks perform daily authenticated vulnerability scans of?
Databricks performs daily authenticated vulnerability scans of Databricks and third-party/open-source packages used by Databricks, along with static and dynamic code analysis (SAST and DAST).
What does Databricks share in its Security Addendum?
Databricks shares its remediation timeline commitments in its Security Addendum.
What does Databricks's Security Addendum describe?
Databricks's Security Addendum describes the security measures and practices Databricks follows to keep customer data safe.
What security measures and practices does Databricks's Security Addendum describe?
Databricks's Security Addendum describes the security measures and practices Databricks follows to keep customer data safe.
When does Databricks use trusted security scanning tools?
Databricks uses trusted security scanning tools before promoting new code or images to production.
How does Databricks's Vulnerability Management Program treat Severity-0 vulnerabilities?
Databricks's Vulnerability Management Program treats Severity-0 vulnerabilities, such as zero days, with the highest urgency, prioritizing their fix above other rollouts.
Stay ahead of the changes
Track Databricks and get the diff the day its terms change.
Summary

This document explains the security measures Databricks has committed to following to protect customer data, and those commitments are written into the customer contract — not just an informal policy. Databricks runs daily vulnerability scans, requires security checks before new code goes live, and fixes its most critical vulnerabilities before other work. Customers can review an independent third-party penetration test report through Databricks's publicly available due diligence package.

Analysis

This document establishes Databricks's contractual and operational security commitments to customers, formalized through a Security Addendum that is part of the customer agreement. It defines a Vulnerability Management Program with tiered severity handling, including highest-urgency prioritization of Severity-0 vulnerabilities above other rollouts, daily authenticated vulnerability scans of first-party and third-party/open-source packages, SAST and DAST code analysis, and mandatory security scanning before code or images are promoted to production. Penetration tests are scoped to major releases, new services, and security-sensitive features, and no such test may be marked as passed while material findings remain unresolved. Databricks maintains strict access controls on internal employee access to production systems, customer environments, and customer data, and holds ISO 27001, ISO 27017, ISO 27018, and SOC 2 Type II certifications, with compliance offerings for PCI-DSS, HIPAA, and FedRAMP.

What this means for you

As a Databricks customer, your data is covered by enforceable security commitments documented in the Security Addendum of your customer agreement, not merely by internal policy. Databricks applies strict controls limiting which employees can access production systems, customer environments, and customer data, and remediates material vulnerabilities before closing any penetration test as passed. You can access Databricks's platform-wide third-party penetration test report and remediation timeline commitments directly through the publicly available due diligence package, without a separate request.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

1 important change detected

3 versions captured · Last updated: August 2026

What changed Databricks expanded its Databricks Security Practices document in an update detected on August 28, 2026, adding extensive detail about its bug bounty program, customer penetration testing policies, cloud console access controls, production system access procedures, and secure software development lifecycle practices. The prior version contained minimal language about these areas; the updated version now explicitly describes how Databricks operates its HackerOne bug bounty program (over 200 reports from 100+ researchers), defines permissible scope for customer penetration testing, details multifactor authentication and VPN requirements for employee production access, and outlines its SDLC practices including code review, security scanning, and release management procedures. This adds transparency about Databricks' internal security operations and customer testing options but does not materially alter customer obligations or data rights.
Why this matters The updated security practices disclose Databricks' internal security operations, bug bounty program structure, and customer penetration testing policies. These additions establish transparency about how Databricks operates its security infrastructure but do not impose new requirements on customers or change data collection, retention, or use practices. Customers interested in performing authorized security testing against Databricks can now reference explicit guidance: vulnerability scans may be run on data plane systems within customer cloud accounts, penetration tests must be contained within the data plane, or security researchers may join the formal bug bounty program to access a dedicated Databricks deployment.
View full change record →
Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

25 provisions
12 featured
5 clause types
8 high severity
Stay ahead of the changes

Monitoring

Databricks has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle All Material Penetration Test Findings Must Be Addressed and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured September 11, 2026 00:56 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000839
Version ID CA-V-006772
SHA-256 5284a2a97f983c68099c1d5bec49e85fae2b2344e1855b71bfeb9cd717fa345e
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans