Security at Spice AI
Built on Principles
Our principles form the solid foundation of Spice AI’s security, guiding every decision and action we make.
Compliance
Certified compliance with industry standards including SOC 2.
Secure-Access-Control
All Spice AI systems are protected by Secure-Access-Controls including Authentication (AuthN), Authorization (AuthZ), and RBAC (Role-Based-Access-Control).
Data Protection
All secret and sensitive information is encrypted in-transit and at-rest.
Multi-Factor-Authentication (MFA)
All authentication systems require and enforce Multi-Factor-Authentication (MFA).
Least Privilege
Least-Privilege-Access is employed so that users, employees, and contractors do not have greater access than necessary.
Defense-in-Depth
Multiple security controls in depth.
Auditable
Access and usage are logged and auditable.
Secure Code
Code is scanned and tested for secrets and vulnerabilities.
Just-In-Time Access
Access is given only when it's required.