Security, Compliance & Privacy

Security, Compliance & Privacy

AutoMQ's product offerings are designed to help enterprise teams protect streaming data, meet compliance requirements, and preserve data privacy across cloud and on-premises environments.

Private by Default

Your environment. Your network. Your data.

AutoMQ commercial editions use a fully private deployment model. The control plane and data plane run inside boundaries you own, helping teams meet strict data privacy and residency requirements without moving Kafka data to a vendor-hosted service.

Explore AutoMQ BYOC
AutoMQ control plane, data plane, and object storage inside a customer-owned private environment

Everything runs in your environment

AutoMQ BYOC runs the control plane and data plane in your cloud account and Virtual Private Cloud (VPC). AutoMQ Software runs them in your private data center.

No standing data access

AutoMQ cannot access your Kafka data or metadata without your authorization. You decide whether support access is enabled and what that access covers.

Customer-controlled boundaries

You control network policies, cloud identities, storage buckets, security settings, and the audit trail within your environment.

Security

Layered safeguards for streaming data

AutoMQ combines customer-controlled infrastructure with data protection, identity controls, and product security practices. Together, these mechanisms can help customers configure their own environments to align with security frameworks, including FedRAMP requirements.

Encryption at Rest

AWS BYOC customers can enable encryption at rest with cloud-provider managed keys when creating the environment and instance.

TLS in Transit

Encrypt Kafka client connections with TLS by using SASL_SSL or mutual TLS (mTLS), based on your authentication model.

RBAC & Kafka Access Control

AutoMQ Cloud provides fine-grained RBAC for member and service accounts performing control-plane operations. Customers can separately enable Kafka ACLs with SASL or mTLS for data-plane access.

Vulnerability Scanning

We scan released AutoMQ artifacts with tools such as Amazon Inspector and use the findings to prioritize remediation of critical and high-severity vulnerabilities.

Compliance

Independently assessed and globally aligned

AutoMQ maintains the following security and privacy compliance programs. Supporting documents are available through our Trust Center and legal resources.

AICPA SOC compliance mark

SOC 2 Type II

A Type II report covering controls relevant to security, availability, and confidentiality over a defined review period.

ISO 27001 Certified badge

ISO 27001

A certified information security management system for protecting the confidentiality, integrity, and availability of information.

GDPR compliance badge

GDPR

Privacy and data processing practices that support customers meeting General Data Protection Regulation requirements.

Support & Community

Guidance when you need it

Find implementation guidance, work directly with AutoMQ, or connect with engineers and streaming practitioners.

Customer Support

Talk with AutoMQ about security reviews, deployment architecture, and product support.

Responsible Disclosure

Found a potential security issue?

Share the details directly with the AutoMQ security team so we can investigate and respond appropriately.