Trust Center

Start your security review
View & download sensitive information
Ask for information
Search items
ControlK

Overview

Welcome to ClickHouse's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.

Compliance

CCPA Logo
CCPA
GDPR Logo
GDPR
ISO 27001 Logo
ISO 27001
ISO 27001 SoA Logo
ISO 27001 SoA
PCI DSS Logo
PCI DSS
SOC 2 Logo
SOC 2
Start your security review
View & download sensitive information
Ask for information
Pentest Report
Vulnerability Assessment Report
ISO 27001
ISO 27001 SoA
PCI DSS
SOC 2
SBOM
Transfer Impact Assessment
Incident Response
Data Classification Policy
Information Security Policy
Operations Security Policy
Risk Management Policy
Secure Development Policy
Third Party Management Policy
ClickHouse W9
Data Processing Locations
Security Companion Guide

Risk Profile

Data Access LevelRestricted
Impact LevelModerate
Critical DependenceYes
View more

Product Security

Audit Logging
Data Security
Integrations
View more

Reports

Pentest Report
Vulnerability Assessment Report

Data Security

Access Monitoring
Backups Enabled
Data Erasure
View more

App Security

Responsible Disclosure
Bot Detection
SBOM
View more

Data Privacy

Cookies
Transfer Impact Assessment

Access Control

Data Access
Logging
Password Security

Infrastructure

Amazon Web Services
Anti-DDoS
View more

Endpoint Security

Disk Encryption
Endpoint Detection & Response
Mobile Device Management
View more

Network Security

IDS/IPS
Security Information and Event Management
Virtual Private Cloud

Corporate Security

Employee Training
HR Security
Incident Response
View more

Policies

Data Classification Policy
Information Security Policy
Operations Security Policy
View more

Security Grades

SecurityScorecard
ClickHouse Cloud
Security Scorecard A grade
Qualys SSL Labs
clickhouse.cloud
A+
Security Headers
clickhouse.cloud
A

Knowledge Base

  • Federal: Is there a ClickHouse version that is secured for US Federal compliance?
  • PCI: Can I use ClickHouse Cloud to store credit card numbers for analysis?
  • HIPAA: Is ClickHouse Cloud HIPAA compliant?
View more

Trust Center Updates

ClickHouse Response to xz-utils Supply Chain Attack (CVE-2024-3094)

VulnerabilitiesCopy link

On March 29, 2024 a vulnerability was discovered in the xz-utils package that was reported as an SSH backdoor that enables remote code execution (RCE) (CVE-2024-3094). We immediately investigated the issue and determined ClickHouse Open Source and ClickHouse Cloud have no known exposure to this vulnerability.

ClickHouse Open Source

The following notice was posted in the public open source repository on March 30, 2024 (issue #62112).

ClickHouse is not affected. None of our releases are affected by this issue.

We are using the xz library to read and write compressed files for data import/export. The library's source code is pinned to an older version that does not include any offending commits or previous commits from the same people. And, similarly to every other dependency, we don't use the upstream packages or build system, and build every dependency from the source instead. Even if someone poisoned the build system or binaries of a dependent library, this is not going to affect us because we use neither build systems nor binaries.

ClickHouse Cloud

ClickHouse Cloud runs a unified cloud security platform that enables us to find, evaluate and respond to issues quickly. To exploit this vulnerability, systems must be running the vulnerable version of the xz-utils package and have SSH exposed to the internet. Based on these factors, we reviewed our systems and believe we have no known exposure to this vulnerability.

Additionally, we are actively working to evaluate our critical vendors to understand their posture and whether any action is required on our part. So far, both AWS and GCP have issued statements indicating their systems are not affected. For more information, please review their security bulletins:

We are continuing to track progress of this issue and will update this notification if there are any changes.

Published at N/A

If you think you may have discovered a vulnerability, please send us a note.

Powered bySafeBase Logo