Security

Security is a top priority at Cube

From flexible deployment options and SSL encryption to annual penetration testing and compliance, you can feel confident in how Cube secures the data you trust us with.

How Cube protects your data. The same controls apply across every deployment — from encryption and authentication to compliance and auditing.

Three clouds side by side, labeled Cloud, VPC, and BYOC

Cloud, VPC, or BYOC: you decide

Run on the fully managed multi-tenant cloud on AWS or GCP, set up Cube Cloud in a Virtual Private Cloud on AWS, GCP, or Azure with VPC peering, or deploy on your own cloud with the BYOC model.

Microsoft Azure, AWS, and Google Cloud logos

Pick your cloud, pick your region

Cube Cloud deploys through AWS, GCP, and Microsoft Azure, and you choose where your deployments physically run. Data is encrypted at rest, filtered at the API level, and every API requires token-based security.

A lock securing the connection between two endpoints

Authentication, SSL, and pen tests

Sign in with SSO through SAML 2.0 and OAuth 2.0. Cube Cloud never stores plain-text passwords, and all application traffic is encrypted over SSL/TLS 1.2. External penetration tests run throughout the year with different vendors.

Database syncing to a backup copy, with a protection check mark

Protection from data loss or corruption

Databases run on the Google Cloud SQL platform, designed for disaster recovery and automatic failover. Account data is backed up at regular intervals throughout the day to multiple off-site locations.

SOC 2, HIPAA, and GDPR compliance seals

Compliance: SOC 2, HIPAA, GDPR

Cube Cloud is SOC 2 Type II, HIPAA, and GDPR compliant — the same standards hold across the entire stack and our internal processes.

Audit log listing timestamped security events

Audit Log across all deployments

Find out who did what and when for every security-related event. Filter by date range, user, event, or deployment, or use full-text search, and keep a historical record for compliance. Learn more in the docs.

Need the paperwork? Pen-test results and SOC 2, HIPAA, and GDPR reports are available in our Trust Center at trust.cube.dev.

Found a vulnerability in a Cube service? Please don’t share it publicly — report it to security@cube.dev.

Ready to upgrade your data stack?