Secure Every Deployment

Security controls are available across all Qdrant Cloud deployment modes. Hybrid Cloud and Private Cloud add full data isolation for stricter residency and compliance requirements.

What Security You Get on Each Deployment Model

Qdrant logo Qdrant Cloud
Hybrid cloud Hybrid / Private Cloud
Server Self-Hosted
Encryption in transit (TLS)
Built-in
Customer configuration
Customer configuration
Encryption at rest
Built-in; Customer-provided keys (Premium)
Customer configuration
Customer configuration
Audit Logging
Available on paid clusters
Available on paid clusters
Customer configuration
Cloud Management Console role-based access control (RBAC)
Built-in
Built-in, Hybrid only
Not applicable
Single sign-on (SSO)
Premium add-on
Premium add-on
(Hybrid only)
Not applicable
VPC PrivateLink
Premium add-on
Not applicable
Not applicable
Compliance documentation (SOC 2 Type 2, HIPAA)
Available via Trust Center
Available via Trust Center
Not applicable

Data Access Isolation and Encryption

For Qdrant Cloud, customers can expect:

Vectors
Cluster Isolation

Hardened, unprivileged containers, isolated from one another.

Explore Cluster Isolation
Lock
Encryption in Transit, at Rest

Data protected in transit with TLS and storage volumes encrypted at rest. Premium customers can encrypt their data at rest using their own keys.

See How Encryption Works
Square activity
Telemetry and Logs

Originate from Qdrant cluster, but then are pushed to Qdrant's US management plane.

Monitor Your Clusters
Globe lock
In-region Data Residency

Data in Qdrant clusters stored only in the cluster's deployment region.

Choose Your Region

Read More About Cloud Security

Across All Deployment Modes, Here Is What Qdrant Can Access

Qdrant logo Qdrant Cloud
Hybrid cloud Hybrid Cloud
Private cloud Private Cloud
Infrastructure metrics
(CPU, memory, disk)
Visible to Qdrant
Visible to Qdrant
Not Visible to Qdrant
Cluster metadata
(names, labels, collections)
Visible to Qdrant
Visible to Qdrant
Not Visible to Qdrant
Vectors, payloads, queries
Stays in your cluster
Stays in your cluster
Stays in your cluster
Database, stored data, API keys, backups, logs
Qdrant Infrastructure
Your infrastructure, no Qdrant access
Your infrastructure, no Qdrant access
Integrated management and observability
Available
Available
Not available (airgapped)

Compare Deployment Modes

FAQs

Does Qdrant access my data on Qdrant Managed Cloud?
On Qdrant Cloud, every storage volume is encrypted at rest. Qdrant does not access any data stored in Qdrant clusters. API keys are stored securely as hashes. The data isolation guarantee covering the database, stored data, API keys, backups, and cluster logs applies to Hybrid Cloud and Private Cloud. Contact Qdrant if your requirements call for that level of isolation.
Which controls does a Premium tier account provide?
PrivateLink (private VPC connectivity), enterprise SSO, and customer-managed encryption keys (BYOK) are all available to Premium tier customers. Contact Qdrant to enable any of these for your account.
Which identity providers does Qdrant Cloud SSO support?
Qdrant Cloud enterprise SSO supports Active Directory/LDAP, ADFS, Azure Active Directory Native, Google Workspace, OpenID Connect, Okta, PingFederate, and SAML. SSO is available as an add-on for Premium tier customers.
How do API keys work and can I scope them to specific collections?
Api keys default to cluster-wide manage/write permissions, with a read-only option also available. To restrict a key to a subset of collections, select the Collections tab and choose the relevant collections. Set an expiration in days (default is 90) and rotate keys regularly.
How does Hybrid Cloud address data residency requirements?
Hybrid Cloud provides a similar developer and ops experience to Qdrant Managed Cloud through the Qdrant Cloud console, while keeping the data plane inside your own infrastructure. Qdrant sees only infrastructure metrics in this mode; the database, stored data, API keys, backups, and cluster logs remain inside your infrastructure.
What certifications does Qdrant hold?
Qdrant holds SOC 2 Type 2 and HIPAA certifications. Pull reports from the Trust Center. For certifications or frameworks not listed there, contact Qdrant directly.
Can Qdrant sign a BAA for PHI workloads?
Qdrant is HIPAA certified and Business Associate Agreement is available for Qdrant Managed Cloud. For specific PHI handling requirements, contact Qdrant to discuss your situation.

Start Building on a
Secure Foundation

Start free and self-serve from the Qdrant Cloud Management Console.

Rocket flying over globe illustration