/
New feature GA

Compliance security profile

Compliance security profile is a Databricks data governance capability, introduced June 2022.

A workspace-level hardening profile that turns on extra monitoring, a hardened compute image, enforced encryption-capable instance types, automatic cluster updates, and TLS 1.2+ egress - and is the mandatory baseline for processing data under HIPAA, PCI-DSS, FedRAMP, and a dozen other regimes.

  • It is a one-way door: once a workspace has processed regulated data the profile cannot be disabled at all, and the documented way to stop using it is to delete the workspace and create a new one.
  • Workspaces running it get a shield logo next to the workspace name in the top-right of the UI, and if the shield is missing the docs tell you to contact your account team.
  • Turning it on is also a way of turning most previews off - only the Public Preview, Private Preview, and Beta features on an explicit allow-list work in a profile-enabled workspace, and nothing else pre-GA does.

Limitations: Requires the Enterprise pricing tier and the Enhanced Security and Compliance add-on, SSO on the workspace, a workspace storage bucket with no period in its name, outbound port 2443 for FIPS endpoints, and only approved AWS Nitro instance types (Graviton fleet types excluded); enabling it is intended to be permanent, partner-powered AI features are off by default, and only allow-listed preview features are supported.

Open in REbricked →
Category
Data governance
Introduced
June 2022
Also known as
CSP, security profile, compliance profile
Verified
2026-09-11

Sources

Related in Data governance