From flexible deployment options and SSL encryption to annual penetration testing and compliance, you can feel confident in how Cube secures the data you trust us with.
Run on the fully managed multi-tenant cloud on AWS or GCP, set up Cube Cloud in a Virtual Private Cloud on AWS, GCP, or Azure with VPC peering, or deploy on your own cloud with the BYOC model.
Cube Cloud deploys through AWS, GCP, and Microsoft Azure, and you choose where your deployments physically run. Data is encrypted at rest, filtered at the API level, and every API requires token-based security.
Sign in with SSO through SAML 2.0 and OAuth 2.0. Cube Cloud never stores plain-text passwords, and all application traffic is encrypted over SSL/TLS 1.2. External penetration tests run throughout the year with different vendors.
Databases run on the Google Cloud SQL platform, designed for disaster recovery and automatic failover. Account data is backed up at regular intervals throughout the day to multiple off-site locations.
Cube Cloud is SOC 2 Type II, HIPAA, and GDPR compliant — the same standards hold across the entire stack and our internal processes.
Find out who did what and when for every security-related event. Filter by date range, user, event, or deployment, or use full-text search, and keep a historical record for compliance. Learn more in the docs.
Need the paperwork? Pen-test results and SOC 2, HIPAA, and GDPR reports are available in our Trust Center at trust.cube.dev.
Found a vulnerability in a Cube service? Please don’t share it publicly — report it to security@cube.dev.