Shared Responsibility
On this page
SingleStore Helios has built in security controls that make it a secure environment to run customer workloads.
Shared Responsibility Model
The following table outlines the responsibilities of the customer and SingleStore for a SingleStore Helios deployment in Managed and BYOC regions:
Cloud Infrastructure Physical Security
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
Customer
|
SingleStore
|
Customer Data, Accounts, and Identities
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
Customer
|
SingleStore
|
Network Isolation and Connectivity
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
Customer
|
SingleStore
|
SingleStore Database Access
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
Customer
|
SingleStore
|
API Controls/Access
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
N/A |
N/A |
Data Encryption (in Transit and at Rest)
Customer-Managed Encryption Keys (CMEK) is only supported on Managed regions.
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
Customer
|
SingleStore
|
Granular Auditing
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
N/A |
N/A |
Performance Monitoring/Alerting
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
Customer
|
SingleStore
|
Security Patches and Maintenance
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
Customer
|
SingleStore
|
High Availability and Disaster Recovery
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
Customer
|
SingleStore
|
Application Security
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
Customer
|
SingleStore
|
Secrets
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
Customer
|
SingleStore
|
Compliance
SingleStore does not provide a BAA for PHI in BYOC regions.
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|
|
Customer
|
SingleStore
|
Customer
|
N/A |
AI Usage
|
Customer
|
SingleStore
|
Responsibility Matrix
The following can be used as a quick reference to the shared responsibilities of the customer and SingleStore.
Cloud Management
|
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|---|
|
Action |
SingleStore |
Customer |
SingleStore |
Customer |
|
VPC |
✔ |
|
|
✔ |
|
EC2 instance management |
✔ |
|
✔ |
|
|
Kubernetes management |
✔ |
|
✔ |
|
|
S3 buckets management |
✔ |
|
✔ |
|
|
SingleStore provisioning |
✔ |
|
✔ |
|
Upgrades and Security
|
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|---|
|
Action |
SingleStore |
Customer |
SingleStore |
Customer |
|
SingleStore upgrades |
✔ |
|
✔ |
|
|
Software vulnerability remediation |
✔ |
|
✔ |
|
|
Infrastructure vulnerability remediation |
✔ |
|
✔ |
✔ |
|
Scaling |
✔ |
|
✔ |
|
Networking
|
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|---|
|
Action |
SingleStore |
Customer |
SingleStore |
Customer |
|
External Routing |
✔ |
|
|
✔ |
|
K8 internal Routing |
✔ |
|
✔ |
|
|
Firewall |
|
✔ |
|
✔ |
|
DNS |
✔ |
|
|
✔ |
|
Load Balancer |
✔ |
|
✔ |
|
Access Control
|
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|---|
|
Action |
SingleStore |
Customer |
SingleStore |
Customer |
|
IAM role, service accounts |
✔ |
|
✔ |
✔ |
|
Access control and auditing |
✔ |
✔ |
✔ |
✔ |
Availability
|
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|---|
|
Action |
SingleStore |
Customer |
SingleStore |
Customer |
|
DR |
✔ |
|
✔ |
✔ |
|
Availability (SLA) |
✔ |
|
✔ |
✔ |
Support
|
|
Managed Regions |
BYOC Regions | ||
|---|---|---|---|---|
|
Action |
SingleStore |
Customer |
SingleStore |
Customer |
|
Logging |
✔ |
|
✔ |
|
|
Audit logging |
✔ |
✔ |
✔ |
✔ |
|
Monitoring |
✔ |
|
✔ |
|
|
Break glass |
✔ |
|
✔ |
✔ |
Last modified: October 17, 2025