> ## Documentation Index
> Fetch the complete documentation index at: https://private-7c7dfe99-mintlify-3a82795f.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> Learn more about securing ClickHouse Cloud and BYOC

This document details the security options and best practices available for ClickHouse organization and service protection.
ClickHouse is dedicated to providing secure analytical database solutions; therefore, safeguarding data and service integrity is a priority.
The information herein covers various methods designed to assist users in securing their ClickHouse environments.

<h2 id="cloud-console-auth">
  Cloud Console Authentication
</h2>

<h3 id="password-auth">
  Password Authentication
</h3>

ClickHouse Cloud console passwords are configured to NIST 800-63B standards with a minimum of 12 characters and 3 of 4 complexity requirements: upper case characters, lower case characters, numbers and/or special characters.

Learn more about [password authentication](/products/cloud/guides/security/cloud-access-management/manage-my-account#email-and-password).

<h3 id="social-sso">
  Social Single Sign-On (SSO)
</h3>

ClickHouse Cloud supports Google or Microsoft social authentication for single sign-on (SSO).

Learn more about [social SSO](/products/cloud/guides/security/cloud-access-management/manage-my-account#social-sso).

<h3 id="mfa">
  Multi-Factor Authentication
</h3>

Users using email and password or social SSO may also configure multi-factor authentication utilizing an authenticator app such as Authy or Google Authenticator.

Learn more about [multi-factor authentication](/products/cloud/guides/security/cloud-access-management/manage-my-account#mfa).

<h3 id="saml-auth">
  Security Assertion Markup Language (SAML) Authentication
</h3>

Enterprise customers may configure SAML authentication.

Learn more about [SAML authentication](/products/cloud/guides/security/cloud-access-management/saml-sso-setup).

<h3 id="api-auth">
  API Authentication
</h3>

Customers may configure API keys for use with OpenAPI, Terraform and Query API endpoints.

Learn more about [API authentication](/products/cloud/features/admin-features/api/openapi).

<h2 id="database-auth">
  Database Authentication
</h2>

<h3 id="db-password-auth">
  Database Password Authentication
</h3>

ClickHouse database user passwords are configured to NIST 800-63B standards with a minimum of 12 characters and complexity requirements: upper case characters, lower case characters, numbers and/or special characters.

Learn more about [database password authentication](/products/cloud/guides/security/cloud-access-management/manage-database-users#database-user-id--password).

<h3 id="ssh-auth">
  Secure Shell (SSH) Database Authentication
</h3>

ClickHouse database users may be configured to use SSH authentication.

Learn more about [SSH authentication](/products/cloud/guides/security/cloud-access-management/manage-database-users#database-ssh).

<h2 id="access-control">
  Access Control
</h2>

<h3 id="console-rbac">
  Console Role-Based Access Control (RBAC)
</h3>

ClickHouse Cloud supports role assignment for organization, service and database permissions. Database permissions using this method are supported in SQL console only.

Learn more about [console RBAC](/products/cloud/reference/security/console-roles).

<h3 id="database-user-grants">
  Database User Grants
</h3>

ClickHouse databases support granular permission management and role-based access via user grants.

Learn more about [database user grants](/products/cloud/guides/security/cloud-access-management/manage-database-users#database-permissions).

<h2 id="network-security">
  Network Security
</h2>

<h3 id="ip-filters">
  IP Filters
</h3>

Configure IP filters to limit inbound connections to your ClickHouse service.

Learn more about [IP filters](/products/cloud/guides/security/connectivity/setting-ip-filters).

<h3 id="private-connectivity">
  Private Connectivity
</h3>

Connect to your ClickHouse clusters from AWS, GCP or Azure using private connectivity.

Learn more about [private connectivity](/products/cloud/guides/security/connectivity/private-networking).

<h2 id="encryption">
  Encryption
</h2>

<h3 id="storage-encryption">
  Storage Level Encryption
</h3>

ClickHouse Cloud encrypts data at rest by default using cloud provider-managed AES 256 keys.

Learn more about [storage encryption](/products/cloud/guides/security/cmek#storage-encryption).

<h3 id="tde">
  Transparent Data Encryption
</h3>

In addition to storage encryption, ClickHouse Cloud Enterprise customers may enable database level transparent data encryption for additional protection.

Learn more about [transparent data encryption](/products/cloud/guides/security/cmek#transparent-data-encryption-tde).

<h3 id="cmek">
  Customer Managed Encryption Keys
</h3>

ClickHouse Cloud Enterprise customers may use their own key for database level encryption.

Learn more about [customer managed encryption keys](/products/cloud/guides/security/cmek#customer-managed-encryption-keys-cmek).

<h2 id="auditing-logging">
  Auditing and Logging
</h2>

<h3 id="console-audit-log">
  Console Audit Log
</h3>

Activities within the console are logged. Logs are available for review and export.

Learn more about [console audit logs](/products/cloud/guides/security/audit-logging/console-audit-log).

<h3 id="database-audit-logs">
  Database Audit Logs
</h3>

Activities within the database are logged. Logs are available for review and export.

Learn more about [database audit logs](/products/cloud/guides/security/audit-logging/database-audit-log).

<h3 id="byoc-security-playbook">
  BYOC Security Playbook
</h3>

Sample detection queries for security teams managing ClickHouse BYOC instances.

Learn more about the [BYOC security playbook](/products/cloud/guides/security/audit-logging/byoc-security-playbook).

<h2 id="compliance">
  Compliance
</h2>

<h3 id="compliance-reports">
  Security and Compliance Reports
</h3>

ClickHouse maintains a strong security and compliance program. Check back periodically for new third party audit reports.

Learn more about [security and compliance reports](/products/cloud/reference/security/compliance-overview).

<h3 id="hipaa-compliance">
  HIPAA Compliant Services
</h3>

ClickHouse Cloud Enterprise customers may deploy services housing protected health information (PHI) to HIPAA compliant regions after signing a Business Associate Agreement (BAA).

Learn more about [HIPAA compliance](/products/cloud/guides/security/compliance/hipaa-onboarding).

<h3 id="pci-compliance">
  PCI Compliant Services
</h3>

ClickHouse Cloud Enterprise customers may deploy services housing credit card information to PCI compliant regions.

Learn more about [PCI compliance](/products/cloud/guides/security/compliance/pci-onboarding).
