This Security Addendum is incorporated into and made a part of the written agreement between Databricks, Inc. or its Affiliates (“Databricks”) and Customer that references this Security Addendum (“Agreement”).
Databricks maintains a comprehensive documented security program that is based on industry standard security frameworks including NIST 800-53 and ISO 27001 (the “Security Program”). Pursuant to the Security Program, Databricks implements and maintains administrative, physical, and technical security measures to protect the Platform Services, Support Services and the security and confidentiality of Customer Content (including any Personal Data that may be contained therein) (each as defined in the Agreement) under Databricks’ control that is processed by Databricks in its provisioning of the Platform Services or Support Services (the “Security Measures”). Databricks’ compliance with this Addendum shall be deemed to satisfy any more general measures included within any Agreement, including the Service Specific Terms.
Databricks regularly tests and evaluates its Security Program, and may review and update this Security Addendum at any time without notice, provided that such updates either make equivalent or enhance Security Measures and do not materially diminish the level of protection afforded to Customer Content by these Security Measures.
- Deployment Model
- Architecture. Databricks is a platform-as-a-service offering. The components primarily responsible for managing and controlling the Platform Services are referred to as the “Databricks Control Plane”. The compute resources that perform data processing operations are referred to as the “Data Plane”. For certain Platform Services, the Data Plane may either be deployed in Customer’s Cloud Service Provider account (known as the “Customer Data Plane”) or, for Databricks Serverless Compute, in a Databricks-controlled Cloud Service Provider account (known as the “Databricks Data Plane”). Data Plane shall refer to both Customer Data Plane and Databricks Data Plane unless otherwise specified.
- Shared Responsibility. Databricks operates in a shared responsibility model, where both Databricks and Customer maintain security responsibilities. This is covered in more detail in our Documentation.
- Data Storage. Depending on your configuration and which Platform Services features a Customer accesses, Databricks may process Customer Content stored within Customer's own Cloud Service Provider account and/or within Databricks' infrastructure. See the Documentation for details.
- Deployment Region. Customer may choose where their Platform Services Workspaces are deployed from any Databricks-supported region(s), or where applicable, a collection of regions grouped by Databricks (“Geo