# Security

ScyllaDB Cloud is secure by default. All data is encrypted at rest and in
transit, database-level encryption is enabled automatically for new clusters,
and internal service accounts follow the principle of least privilege — all
managed by ScyllaDB with no configuration required.

This section documents those built-in protections as well as the controls
available to you: managing users and roles, configuring customer-managed
encryption keys, enabling SSO, and requesting immutable backups.


            <div class="cell my-panel">
                <div class="panel">
                    <h5 class="panel_\_title">Overview</h5>
            * [Security Best Practices](https://cloud.docs.scylladb.com/stable/security/best-practices.md) — Recommended configuration for Cloud and database users.
* [Security Concepts](https://cloud.docs.scylladb.com/stable/security/concepts.md) — How ScyllaDB Cloud security is architected: isolation, encryption, and access control.

</div></div>
            <div class="cell my-panel">
                <div class="panel">
                    <h5 class="panel_\_title">Encryption</h5>
            * [Database-level Encryption](https://cloud.docs.scylladb.com/stable/security/database-level-encryption.md) — Configure customer-managed encryption keys (CMK) for your data.
* [Storage-level Encryption](https://cloud.docs.scylladb.com/stable/security/storage-level-encryption.md) — Always-on encryption at rest, managed by ScyllaDB.
* [Client-to-node Encryption](https://cloud.docs.scylladb.com/stable/security/client-to-node-encryption.md) — TLS encryption for traffic between your application and the cluster, managed by ScyllaDB.

</div></div>
            <div class="cell my-panel">
                <div class="panel">
                    <h5 class="panel_\_title">Users and Access Control</h5>
            * [Service Users](https://cloud.docs.scylladb.com/stable/security/service-users.md) — Internal accounts used by ScyllaDB for operations and automation.
* [User Management](https://cloud.docs.scylladb.com/stable/access-management/user-management.md) — Invite users and assign roles for your ScyllaDB Cloud organization.
* [SAML Single Sign-On (SSO)](https://cloud.docs.scylladb.com/stable/access-management/sso.md) — Configure SSO with your identity provider.

</div></div>
            <div class="cell my-panel">
                <div class="panel">
                    <h5 class="panel_\_title">Compliance</h5>
            * [Immutable (WORM) Backups](https://cloud.docs.scylladb.com/stable/security/immutable-backups.md) — Request write-protected backups for regulatory compliance.
* [Data Privacy and Compliance](https://www.scylladb.com/trust-center/) — ScyllaDB’s trust center, certifications, and data privacy policies.

</div></div>
