Compliance security profile
Compliance security profile is a Databricks data governance capability, introduced June 2022.
A workspace-level hardening profile that turns on extra monitoring, a hardened compute image, enforced encryption-capable instance types, automatic cluster updates, and TLS 1.2+ egress - and is the mandatory baseline for processing data under HIPAA, PCI-DSS, FedRAMP, and a dozen other regimes.
- It is a one-way door: once a workspace has processed regulated data the profile cannot be disabled at all, and the documented way to stop using it is to delete the workspace and create a new one.
- Workspaces running it get a shield logo next to the workspace name in the top-right of the UI, and if the shield is missing the docs tell you to contact your account team.
- Turning it on is also a way of turning most previews off - only the Public Preview, Private Preview, and Beta features on an explicit allow-list work in a profile-enabled workspace, and nothing else pre-GA does.
Limitations: Requires the Enterprise pricing tier and the Enhanced Security and Compliance add-on, SSO on the workspace, a workspace storage bucket with no period in its name, outbound port 2443 for FIPS endpoints, and only approved AWS Nitro instance types (Graviton fleet types excluded); enabling it is intended to be permanent, partner-powered AI features are off by default, and only allow-listed preview features are supported.
Open in REbricked →- Category
- Data governance
- Also known as
- CSP, security profile, compliance profile
- Verified
- 2026-09-11