We Value Your Trust

At PingCAP, we value security and trust more than anything because we know our customers entrust us with their most important asset – the data itself. We take this responsibility seriously and are always dedicated to protecting the security, availability, and confidentiality of our customers’ data. We have incorporated security into all aspects of our offering and operations.

We are committed to providing enterprise-grade security and privacy. This is not simply demonstrated in technology. We undergo third-party auditing to ensure our services and operations adhere to the compliance requirements of your organization. TiDB Cloud operates in accordance with the following compliance requirements:


SOC 2 Type II

The SOC 2 Type II audit is performed by Schellman & Company, LLC, based on relevant guidelines developed by the American Institute of Certified Public Accountants (AICPA) for the appropriateness of controls related to the security, availability, and confidentiality of the TiDB Cloud service offering. PingCAP completed the SOC 2 Type I examination in July, 2020.

iso 27001

ISO/IEC 27001:2013

ISO/IEC 27001:2013 is a globally recognized standard that sets out the policies and requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). PingCAP has achieved ISO/IEC 27001:2013 for TiDB Cloud, certified by British Standards Institution (BSI), an ANAB-accredited certification body.

iso 27701

ISO/IEC 27701

ISO/IEC 27701 is a privacy extension to ISO/IEC 27001 Information Security Management and ISO/IEC 27002 Security Controls. As an international management system standard, it provides guidance on the protection of privacy, including how organizations should manage personal information, and assists in demonstrating compliance with privacy regulations around the world.


General Data Protection Regulation

The General Data Protection Regulation (GDPR) is a regulation that requires businesses to protect the personal data and privacy of EU citizens for transactions that occur within EU member states. GDPR applies to all companies processing and holding the personal data of data subjects located in the European Union, regardless of the company’s location. PingCAP has achieved the GDPR compliance for TiDB Cloud, certified by ePrivacy GmbH.