# Tinybird is the real-time data platform you can trust.

### GDPR

Tinybird fully complies with GDPR regulations, with all related requests handled via our support.

### SOC 2 Compliance

Tinybird is SOC 2 Type 2 compliant. Our SOC 2 report is available to all customers on our Enterprise plan.

### HIPAA Compliant

Our HIPAA compliance report is available to all customers.

### Backups

All customer databases are backed up daily to highly durable storage and retained for two (2) days. Backups are tested annually. In a recovery scenario, data is restored to the most recent daily backup.

### Data center security

Tinybird runs all services on AWS, Google, and Microsoft data centers, which have some of the highest levels of security and reliability available.

### Security assistance

Engineering review for security best practices, making sure your Tinybird deployment is secure from unauthorized access, data breaches, and other security threats.

### Vulnerabilities

Software developed by Tinybird is constantly analyzed by static analysis security tools. Code is reviewed as changes are proposed and security design reviews take place as needed.

### SSO/SAML

SSO/SAML authentication is available to all Enterprise customers.

### Encryption in transit

Tinybird requires industry-standard Transport Layer Security (versions 1.2+) encryption for all connections. All database services support client certificate verification modes. Critical internal traffic is protected by mutual TLS.

### Subprocessors

Tinybird keeps the list of [data subprocessors](/content/tinybird-subprocessors.pdf) updated in the Terms of Service.

### MFA

Tinybird offers secure Multi-Factor Authentication (or 2FA) for all customers.

### Support and operations

Support is fully staffed 24x7 globally, with SLOs based on issue severity. [Contact us](/content/contact-us/index.html) for any support and operations requests you have.

### Intrusion detection/Pen test

Tinybird regularly collaborates with external security audit firms to assess our security posture and intrusion detection capabilities.

### Encryption at rest

All data volumes, including backups, are encrypted at rest with unique keys specific to each service, and keys are automatically rotated at a regular cadence.

### Monitoring

Tinybird uses 24/7 on-call rotations with internal escalations to monitor all systems. Subscribe to our [status page](https://status.tinybird.co/) for system wide alerts.

### Payments and PCI

Credit card payments are processed through Stripe without storing personal credit card information. Corporate invoicing is also available to Enterprise Tier customers. Stripe is a certified PCI Service Provider Level 1, which is the highest level of certification in the payments industry.

### Resources

[Tinybird system status](https://status.tinybird.co/) / [Tinybird Trust Center](https://trust.tinybird.co/)
