---
name: netezza-sec_compl_overview
title: Overview
description: ''
last-updated: 2026-07-21
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/netezza?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

{:external: target="_blank" .external}
{:shortdesc: .shortdesc}
{:table: .aria-labeledby="caption"}
{:tip: .tip}
{:important: .important}
{:note: .note}

# Overview
{: #security_compliance_overview}

IBM&reg; Netezza&reg; Performance Server for IBM Cloud Pak&reg; for Data as a Service ensures that your data is secured and protected by adhering to the following security and compliance standards.

## Secure access control
{: #access_control}

### Authentication
{: #auth_sec_compl}

Both [public](https://cloud.ibm.com/docs/netezza?topic=netezza-connecting-overview&format=markdown#public_endpoints) and [private](https://cloud.ibm.com/docs/netezza?topic=netezza-connecting-overview&format=markdown#private_endpoints) NPSaaS endpoints are accessed through an HTTPS API. Where the API endpoint requires it, the user is authenticated for every HTTPS request that NPSaaS receives.

### Encryption
{: #encryptiom_sec_compl}

When transmitted, content is encrypted on any public networks by using TLS 1.2 or later.
For more information, see [Data security and encryption](https://cloud.ibm.com/docs/netezza?topic=netezza-data-encryption&format=markdown).

At rest, content is encrypted within the Cloud Data Center in the following ways:

- On AWS, by using the 256-bit AES data encryption (industry standard).
- On Azure, by using the 256-bit AES data encryption that is compliant with FIPS 140-2.

## Security compliance for Netezza
{: #sec_comp_nps}

Netezza Performance Server as a Service (NPSaaS) follows industry‑recognized security and compliance standards to help protect customer data and support regulatory requirements. The service aligns with multiple frameworks including SOC 2, ISO 27001/27017/27018, and HIPAA—by implementing rigorous operational, administrative, technical, and organizational controls. These certifications and attestations help ensure that NPSaaS maintains a secure, trustworthy, and compliant environment for managing sensitive workloads.

The following table lists the compliance certifications that are supported for NPSaaS by region.

| Compliance | Global | US | Canada | EU & UK | India | Australia | Japan |
|---|---|---|---|---|---|---|---|
| SOC 2 | ![Checkmark icon](../../icons/checkmark-icon.svg) | | | | | | |
| ISO 27K | ![Checkmark icon](../../icons/checkmark-icon.svg) | | | | | | |
| HIPAA | | ![Checkmark icon](../../icons/checkmark-icon.svg) | | | | | |
| GDPR | | | | ![Checkmark icon](../../icons/checkmark-icon.svg) | | | |
| DPDP | | | | | ![Checkmark icon](../../icons/checkmark-icon.svg) | | |
{: caption="Netezza Performance Server compliance availability by region" caption-side="bottom"}

### SOC 2 Type 2
{: #soc2t2}

IBM provides Service Organization Control (SOC) 2 Type 2 reports for its Netezza Performance Server as a Service (NPSaaS) managed services offering on both AWS and Azure platforms.

These reports evaluate IBM's operational controls against the criteria established by the American Institute of Certified Public Accountants (AICPA) Trust Services Principles. These principles define industry‑recognized standards for ensuring systems and controls are designed to protect customer data and maintain service integrity.

SOC 2 Type 2 compliance is available for Netezza Performance Server deployments on both AWS and Azure, demonstrating IBM's commitment to maintaining rigorous security controls across cloud platforms.

## ISO 27017, ISO 27018
{: #iso}

NPSaaS conforms to the security controls and technical and organizational measures (TOMs) that are defined in the following documents:

- [ISO 27001](https://www.iso.org/standard/27001)
- [ISO 27017](https://www.iso.org/standard/43757.html)
- [ISO 27018](https://www.iso.org/standard/76559.html)

For more information, see the [IBM Compliance Support page](https://www.ibm.com/support/pages/compliance-request-tool/search/?q=IBM%20Netezza%20Performance%20Server).

## HIPAA
{: #hipaa}

NPSaaS implemented the necessary controls commensurate with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security and Privacy Rule requirements. The controls include appropriate administrative, physical, and technical safeguards that are required of business associates in 45 CFR Part 160 and Subparts A and C of Part 164.