25 Total
8 High severity
13 Medium severity
4 Low severity

Key Facts

What does Databricks require regarding material findings from a penetration test?
Databricks requires that all material findings from a penetration test be addressed before that test can be marked as passed.
What does Databricks provide to all its customers in its Security Addendum?
Databricks provides a contractual commitment to security, written in plain language, to all its customers, captured in the Security Addendum of the customer agreement.
Where is Databricks's contractual commitment to security captured?
Databricks provides a contractual commitment to security, written in plain language, to all its customers, captured in the Security Addendum of the customer agreement.
What does Databricks perform daily?
Databricks performs daily authenticated vulnerability scans of Databricks and third-party/open-source packages used by Databricks, along with static and dynamic code analysis (SAST and DAST).
What does Databricks perform daily authenticated vulnerability scans of?
Databricks performs daily authenticated vulnerability scans of Databricks and third-party/open-source packages used by Databricks, along with static and dynamic code analysis (SAST and DAST).
What does Databricks share in its Security Addendum?
Databricks shares its remediation timeline commitments in its Security Addendum.
What does Databricks's Security Addendum describe?
Databricks's Security Addendum describes the security measures and practices Databricks follows to keep customer data safe.
What security measures and practices does Databricks's Security Addendum describe?
Databricks's Security Addendum describes the security measures and practices Databricks follows to keep customer data safe.
When does Databricks use trusted security scanning tools?
Databricks uses trusted security scanning tools before promoting new code or images to production.
How does Databricks's Vulnerability Management Program treat Severity-0 vulnerabilities?
Databricks's Vulnerability Management Program treats Severity-0 vulnerabilities, such as zero days, with the highest urgency, prioritizing their fix above other rollouts.
Stay ahead of the changes
Track Databricks and get the diff the day its terms change.
Summary

This document explains the security measures Databricks has committed to following to protect customer data, and those commitments are written into the customer contract — not just an informal policy. Databricks runs daily vulnerability scans, requires security checks before new code goes live, and fixes its most critical vulnerabilities before other work. Customers can review an independent third-party penetration test report through Databricks's publicly available due diligence package.

Analysis

This document establishes Databricks's contractual and operational security commitments to customers, formalized through a Security Addendum that is part of the customer agreement. It defines a Vulnerability Management Program with tiered severity handling, including highest-urgency prioritization of Severity-0 vulnerabilities above other rollouts, daily authenticated vulnerability scans of first-party and third-party/open-source packages, SAST and DAST code analysis, and mandatory security scanning before code or images are promoted to production. Penetration tests are scoped to major releases, new services, and security-sensitive features, and no such test may be marked as passed while material findings remain unresolved. Databricks maintains strict access controls on internal employee access to production systems, customer environments, and customer data, and holds ISO 27001, ISO 27017, ISO 27018, and SOC 2 Type II certifications, with compliance offerings for PCI-DSS, HIPAA, and FedRAMP.

What this means for you

As a Databricks customer, your data is covered by enforceable security commitments documented in the Security Addendum of your customer agreement, not merely by internal policy. Databricks applies strict controls limiting which employees can access production systems, customer environments, and customer data, and remediates material vulnerabilities before closing any penetration test as passed. You can access Databricks's platform-wide third-party penetration test report and remediation timeline commitments directly through the publicly available due diligence package, without a separate request.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

25 provisions
12 featured
5 clause types
8 high severity
Stay ahead of the changes

Monitoring

Databricks has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle All Material Penetration Test Findings Must Be Addressed and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured July 11, 2026 13:45 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000839
Version ID CA-V-004753
SHA-256 0eb2a219a956e72f7703bf9fca8351c1290d0540d29bbf71e6dae3ff2897a2e6
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans