Everything runs in your environment
AutoMQ BYOC runs the control plane and data plane in your cloud account and Virtual Private Cloud (VPC). AutoMQ Software runs them in your private data center.
AutoMQ's product offerings are designed to help enterprise teams protect streaming data, meet compliance requirements, and preserve data privacy across cloud and on-premises environments.
Private by Default
AutoMQ commercial editions use a fully private deployment model. The control plane and data plane run inside boundaries you own, helping teams meet strict data privacy and residency requirements without moving Kafka data to a vendor-hosted service.
Explore AutoMQ BYOCAutoMQ BYOC runs the control plane and data plane in your cloud account and Virtual Private Cloud (VPC). AutoMQ Software runs them in your private data center.
AutoMQ cannot access your Kafka data or metadata without your authorization. You decide whether support access is enabled and what that access covers.
You control network policies, cloud identities, storage buckets, security settings, and the audit trail within your environment.
Security
AutoMQ combines customer-controlled infrastructure with data protection, identity controls, and product security practices. Together, these mechanisms can help customers configure their own environments to align with security frameworks, including FedRAMP requirements.
AWS BYOC customers can enable encryption at rest with cloud-provider managed keys when creating the environment and instance.
Encrypt Kafka client connections with TLS by using SASL_SSL or mutual TLS (mTLS), based on your authentication model.
AutoMQ Cloud provides fine-grained RBAC for member and service accounts performing control-plane operations. Customers can separately enable Kafka ACLs with SASL or mTLS for data-plane access.
We scan released AutoMQ artifacts with tools such as Amazon Inspector and use the findings to prioritize remediation of critical and high-severity vulnerabilities.
Compliance
AutoMQ maintains the following security and privacy compliance programs. Supporting documents are available through our Trust Center and legal resources.

A Type II report covering controls relevant to security, availability, and confidentiality over a defined review period.

A certified information security management system for protecting the confidentiality, integrity, and availability of information.

Privacy and data processing practices that support customers meeting General Data Protection Regulation requirements.
Support & Community
Find implementation guidance, work directly with AutoMQ, or connect with engineers and streaming practitioners.
Review deployment, security, identity, and access guidance for AutoMQ commercial editions.
Talk with AutoMQ about security reviews, deployment architecture, and product support.
Connect with AutoMQ engineers and users, share feedback, and follow the open source project.
Responsible Disclosure
Share the details directly with the AutoMQ security team so we can investigate and respond appropriately.