In Neon, point-in-time restores are instant—even for 100 TB databases. See how it compares to AWS RDS

Neon’s Security & Compliance

At Neon, security, compliance, privacy, and transparency are core to our platform. We protect customer data through industry leading security controls, independent audits, and strict adherence to global compliance standards.

Compliance Frameworks

SOC 2 Type II

SOC 2 Type II

ISO/IEC 27001:2022 & ISO/IEC 27701:2019

ISO/IEC 27001:2022 & ISO/IEC 27701:2019

Privacy & Regulations

California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)

California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)

European General Data Protection Regulation (GDPR)

European General Data Protection Regulation (GDPR)

United States Health Insurance Portability and Accountability Act of 1996 (HIPAA)

United States Health Insurance Portability and Accountability Act of 1996 (HIPAA)

Trust Center

Neon PostgreSQL Service

Neon PostgreSQL Service

Secure, scalable, cloud-hosted PostgreSQL database.

Cloud Infrastructure

Cloud Infrastructure

Hosted on AWS and Azure, leveraging built-in security controls.

Data Storage & Processing

Data Storage & Processing

Encryption, access controls, and secure data retention policies.

Access & Security Controls

Access & Security Controls

Identity management, monitoring, and compliance enforcement.

Personnel Security

Personnel Security

Employee background checks, security training, and access management.

Sub-Processors

Features

Cloud Infrastructure

  • Data Hosting

    Data Hosting

    Neon’s infrastructure runs on AWS and Azure, certified for SOC 2, ISO 27001, FedRAMP, PCI-DSS, HIPAA, and other global security standards.

  • Data Segregation

    Data Segregation

    Customer data is isolated with unique IDs to prevent unauthorized access. The API enforces this through authentication in access tokens.

  • Physical & Environmental Security

    Physical & Environmental Security

    Neon personnel have no physical access to AWS or Azure data centers, which have 24/7 surveillance, biometric controls, redundancy, and audits.

  • Access Control

    Access Control

    Production access is restricted by default, granted only when needed with least-privilege, time-limited permissions via Teleport and approval.

  • Monitoring

    Monitoring

    Neon uses Grafana to monitor cloud operations. System failures trigger alerts, notifying key personnel for immediate response and resolution.

  • Vendor Risk Management

    Vendor Risk Management

    All vendors are assessed for security, privacy, and compliance. Those handling sensitive data must meet SOC 2.

Cloud Security

  • Network Vulnerability Scanning

    Network Vulnerability Scanning

    Neon performs continuous vulnerability scans on all infrastructure components. Identified vulnerabilities are triaged and remediated based on severity.

  • Intrusion Detection & Prevention

    Intrusion Detection & Prevention

    Neon monitors for unauthorized access using traffic monitoring, anomaly detection, and threat intelligence.

  • Logical Access Controls

    Logical Access Controls

    Access to production systems is role-based (RBAC), requiring SSO and continuous monitoring. Access modifications require documented approval.

  • Security Incident Response

    Security Incident Response

    Neon has a 24/7 incident response team following well-defined playbooks, including continuous training and annual tabletop exercises.

Encryption

  • Data in Transit

    Data in Transit

    Neon enforces TLS 1.2+ encryption for all data transmitted over public and private networks.

  • Data at Rest

    Data at Rest

    All stored data is encrypted using AES-256 and follows key rotation policies to maintain security.

  • Key Management

    Key Management

    Neon uses AWS KMS and Azure Key Vault for key management, with logging and access controls.

Availability & Continuity

  • Redundancy

    Redundancy

    Neon’s infrastructure is designed for high availability, leveraging multi-region failover and automated scaling.

  • Backup Management

    Backup Management

    Neon performs daily encrypted backups stored across multiple availability zones, with automated integrity validation.

  • Business Continuity and Disaster Recovery

    Business Continuity and Disaster Recovery

    Neon has a BCDR plan with annual disaster recovery tests and predefined restoration protocols to ensure resilience.

Application & Platform Security

  • Secure Development Lifecycle (SDLC)

    Secure Development Lifecycle (SDLC)

    Neon follows a secure development lifecycle with security testing, code reviews, dependency monitoring, and developer security training.

  • Vulnerability Management

    Vulnerability Management

    Neon scans for vulnerabilities with Orca and Oligo, patching per SLA: critical 7 days, high 30, medium 60, low 90.

  • Penetration Testing

    Penetration Testing

    Annual third-party penetration tests are conducted on our infrastructure, applications, and APIs to identify and mitigate risks.

  • CI/CD Security

    CI/CD Security

    Neon uses Step Security’s Harden Runner to secure CI/CD by restricting traffic, monitoring dependencies, and enforcing security policies.

  • Github Secret Scanning Partner Program

    Github Secret Scanning Partner Program

    Neon joined the GitHub Secret Scanning Partnership in to improve secret detection and remediation across repositories.

Human Resources & Endpoint Security

  • Background Checks

    Background Checks

    Neon conducts reference checks for all employees before onboarding.

  • Confidentiality Agreements

    Confidentiality Agreements

    All employees and contractors sign non-disclosure agreements (NDA) upon hire.

  • Policies

    Policies

    Neon maintains a security policy framework, reviewed annually and enforced company-wide. Employees are required to acknowledge and comply with these policies each year.

  • Training and Awareness

    Training and Awareness

    Neon conducts annual security awareness training, covering HIPAA compliance, anti-harassment policies, and phishing simulations to strengthen employee resilience.

  • Endpoints

    Endpoints

    Neon centrally manages employee devices via JumpCloud MDM, enforcing full-disk encryption, automatic OS updates, enforced screen locks, anti-malware protection, and continuous monitoring.

The Postgres of tomorrow, available today

Book a meeting with our team