Turbopuffer
Security Posture
Compliance-ready
As of September 3, 2026, Turbopuffer's security: Turbopuffer holds SOC 2 and SOC 2 Type II certifications alongside GDPR and CCPA coverage, with audit logs, encryption at rest, and encryption in transit among seven stated controls. Data residency is listed as global, so buyers with strict regional data requirements should confirm specific region availability before committing.
Backed by 12 dated facts
Every value derives from a dated, sourced capture — open any fact for its source.
Every value derives from a dated, sourced capture — open any fact for its source.
Certifications
SOC 2SOC 2 Type II
Privacy
CCPAGDPR
Controls
Audit LogsEncryption At RESTEncryption In TransitIP AllowlistingPrivate LinkPrivate NetworkingSSO
Details
Data residencyGlobal
Security Change Historydated events · values unlock with a key
Security signal removed: Pen Testing · high significance
Security signal removed: VPC Peering · high significance
Security signal removed: HIPAA · high significance
Security signal added: VPC Peering · high significance
Security signal removed: VPC Peering · high significance
Security signal added: Data Residency · high significance
Security signal added: IP Allowlisting · high significance
Security signal added: Pen Testing · high significance
Every security fact on this pagekey · value · provenance · dated · sourced
| Fact | Value | Provenance | As of | Source |
|---|---|---|---|---|
| security.audit-logs | Audit Logs | company stated | 2026-09-03 | turbopuffer.com/docs/security |
| security.cert.soc2 | SOC 2 | company stated | 2026-09-03 | turbopuffer.com/pricing |
| security.cert.soc2-type-ii | SOC 2 Type II | company stated | 2026-09-03 | turbopuffer.com/docs/security |
| security.data_residency | global | company stated | 2026-09-03 | turbopuffer.com/docs/security |
| security.encryption-at-rest | Encryption At REST | company stated | 2026-09-03 | turbopuffer.com/docs/security |
| security.encryption-in-transit | Encryption In Transit | company stated | 2026-09-03 | turbopuffer.com/docs/security |
| security.ip-allowlisting | IP Allowlisting | company stated | 2026-09-03 | turbopuffer.com/docs/security |
| security.privacy.ccpa | CCPA | company stated | 2026-09-03 | turbopuffer.com/docs/security |
| security.privacy.gdpr | GDPR | company stated | 2026-09-03 | turbopuffer.com/docs/security |
| security.private-link | Private Link | company stated | 2026-09-03 | turbopuffer.com/docs/security |
| security.private-networking | Private Networking | company stated | 2026-09-03 | turbopuffer.com/pricing |
| security.sso | SSO | company stated | 2026-09-03 | turbopuffer.com/docs/security |
Security across Vector DatabasesTurbopuffer ranked in place · tap through for each read
| Company | Security read | Facts |
|---|---|---|
| Pinecone | Enterprise-grade | 15 |
| Zilliz | Compliance-ready | 14 |
| Qdrant | Compliance-ready | 13 |
| Turbopuffer this record | Compliance-ready | 12 |
| Weaviate | Compliance-ready | 10 |
| Chroma | Compliance-ready | 8 |
| TopK | Baseline security | 5 |
| Activeloop | Baseline security | 4 |
| Epsilla | Baseline security | 4 |
| Vectara | Compliance-ready | 3 |
No observed security facts yet for KDB.AI, LanceDB, Marqo, Milvus, MyScale and Vespa.
Get security for turbopuffer.com via API / MCPevery field dated and sourced
RESTopen tier
GET https://api.bixel.com/v1/companies/turbopuffer.com/facts?dimension=security
{
"data": {
"facts": [
{
"key": "security.audit-logs",
"value": true,
"provenance": "company_stated",
"as_of": "2026-09-03",
"source_url": "turbopuffer.com/docs/security"
},
{
"key": "security.cert.soc2",
"value": true,
"provenance": "company_stated",
"as_of": "2026-09-03",
"source_url": "turbopuffer.com/pricing"
},
{
"key": "security.cert.soc2-type-ii",
"value": true,
"provenance": "company_stated",
"as_of": "2026-09-03",
"source_url": "turbopuffer.com/docs/security"
},
{
"key": "security.data_residency",
"value": "global",
"provenance": "company_stated",
"as_of": "2026-09-03",
"source_url": "turbopuffer.com/docs/security"
},
"…"
]
}
}MCPfor agents
# any MCP client (Claude, agents)
const record = await bixel.get_company_facts({ domain: "turbopuffer.com", dimension: "security" })
# returns the security record above,
# each value with its source_url + as_of,
# ready to reason overBuild on the company record. One key, REST + MCP, every signal dated and sourced back to the page it came from.
Public record, read from companies' own pages and boards. Every fact dated and sourced; provenance (observed vs company stated) shown inline.