BlogsSingleStorePCI DSS Compliance

PCI DSS Compliance

PCI DSS Compliance

7
posts
2026

SingleStore Helios and Helios BYOC have achieved PCI DSS v4.0.1 compliance, demonstrating robust security controls for handling payment card data. This includes identity and access management with MFA and SSO, encryption at rest and in transit (TLS 1.2+, AES-256), continuous monitoring of logs, regular vulnerability management, and secure cloud infrastructure on AWS with network segmentation. The compliance covers the managed platform, with shared responsibility for application-level security. This post further clarifies the scope and implications of PCI DSS compliance, detailing the shared responsibility model between SingleStore and the customer, and emphasizing that compliance is an ongoing process involving regular audits, risk assessments, and vulnerability management.

2026

SingleStore Helios Achieves PCI DSS v4.0.1 Compliance

8/3/2026

This post announces the achievement of PCI DSS v4.0.1 compliance for SingleStore Helios and Helios BYOC. It details the scope of the assessment, the security controls validated (IAM, encryption, monitoring, vulnerability management, secure infrastructure), and clarifies the shared responsibility model. It also positions this compliance alongside existing certifications like SOC 2 Type II and ISO 27001.

Why ad platforms run six databases to answer one question

7/9/2026

This post analyzes the architectural challenges of ad platforms that lead to data sprawl, where multiple databases are used for different functions, resulting in increased operational costs and complexity. It highlights the shift from traditional batch OLAP and individual OLTP systems to the need for real-time HTAP systems. The post details how this data sprawl arises from specialized databases for auction lookups, advertiser dashboards, audience filtering, and caching, leading to redundant data copies and synchronization issues. It argues that the traditional split between batch and real-time processing incurs significant costs due to data migration, latency, and operational overhead. The post introduces Hybrid Transactional/Analytical Processing (HTAP) as a solution, enabling both high-speed writes and analytical reads within a single engine, thus consolidating diverse workloads and providing a unified freshness profile and single point of access.

Cloud Database Security Engineering and SDLC | SingleStore

6/24/2026

This post details the integration of security into the Software Development Lifecycle (SDLC) for SingleStore Helios. It outlines six key practices: security training, threat modeling, security requirements definition, architecture vetting, secure code review, and automated CI/CD testing. The automated testing layer includes SAST, SCA, DAST, container image scanning, secrets scanning, IaC scanning, and CNAPP. It also covers external validation through annual penetration testing, a responsible disclosure program, and incident management aligned with NIST SP 800-61.

Cloud Database Shared Responsibility Explained | SingleStore

6/17/2026

This post elaborates on the shared responsibility model for SingleStore Helios, detailing the security controls provided by default (encryption at rest/in transit, no public access, network boundaries, secure credential store) and those that remain the customer's responsibility (IP allowlisting, identity provider integration, RBAC, customer-managed encryption keys, application-layer security). It frames the vendor's responsibility around providing secure defaults and the customer's around specific organizational requirements and customizations.

Cloud Database Encryption Keys and CMEK | SingleStore

6/11/2026

This post elaborates on the encryption capabilities within SingleStore Helios, specifically detailing the implementation and implications of Customer-Managed Encryption Keys (CMEK). It explains the architecture of CMEK, which involves using a customer-provided Key Encrypting Key (KEK) to encrypt Data Encryption Keys (DEKs) managed by the cloud provider's KMS. The post highlights the technical aspects of how SingleStore interacts with cloud KMS APIs for encryption/decryption operations and emphasizes the critical importance of key management practices for data sovereignty and the risk of data loss if keys are mishandled or deleted. It contrasts CMEK with platform-managed encryption, providing guidance on choosing the appropriate model based on security and regulatory requirements.

Database SSO Integration: SAML, OIDC, SCIM and MFA | SingleStore

5/19/2026

This post details the integration of SingleStore Helios with enterprise identity management systems, focusing on SAML 2.0, OIDC, SCIM, and MFA. It explains how SingleStore leverages existing IdP infrastructure for authentication and authorization, including automated provisioning/deprovisioning via SCIM and machine identity authentication through cloud IAM or JWTs. The post also outlines a maturity model for identity integration.

Cloud Database Compliance Certifications Explained | SingleStore

5/7/2026

This post elaborates on SingleStore's PCI DSS compliance by detailing the shared responsibility model, clarifying customer obligations for application design and data handling, and outlining SingleStore's platform security responsibilities. It also highlights the ongoing nature of compliance through regular audits, penetration tests, risk assessments, and vulnerability management processes, aligning with the NIST Cybersecurity Framework.