Security Overview
VeloDB Cloud is a managed data warehouse built on Apache Doris. This section presents a single security model spanning two layers: the VeloDB Cloud control plane (organizations, accounts, the Console, and managed infrastructure) and the warehouse engine (warehouse SQL users, roles, encryption, and audit logs). You manage access and security settings through the Console and SQL. VeloDB operates the underlying infrastructure for SaaS deployments. In BYOC, you own the cloud account and customer-controlled resources.
VeloDB Cloud holds a SOC 2 Type II report. For reports and current trust materials, see Compliance & Trust and the VeloDB Trust Center.
Start with your task
| If you need to | Start here |
|---|---|
| Review VeloDB's audit reports, security program, or vendor-assessment materials. | Compliance & Trust |
| Control access to the Console, Management API, or warehouse. | Identity and Access |
| Choose SaaS connectivity or review BYOC network controls. | Network Security |
| Review encryption at rest or the in-transit boundary. | Encryption at Rest and Encryption in Transit |
| Review organization activity, query activity, or infrastructure evidence. | Audit Logging |
| Review the BYOC operating boundary. | BYOC Security |
Shared responsibility
Security is shared across three parties:
- The cloud provider secures the underlying infrastructure in every deployment, including the physical data centers, hardware, and hypervisor.
- VeloDB Cloud secures the warehouse service. In a SaaS deployment, VeloDB Cloud manages the cloud account, the warehouse engine and platform, encryption, and patching. In a BYOC deployment, VeloDB Cloud manages the warehouse software and its operation inside your cloud account.
- You secure your data, identities, roles, permissions, network exposure, and Console access. In a BYOC deployment, you also own the cloud account and customer-controlled resources.
The task links above apply to both SaaS and BYOC. In BYOC, you also own the cloud account and customer-controlled resources. For the detailed BYOC boundary, see BYOC Security.