Security & Compliance
Compliance Standards
Formal certifications and regulations (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR) that govern how providers handle security and data, and which you may be required to use.
Compliance standards are the certifications and regulations that dictate how data must be secured and handled. SOC 2 and ISO 27001 attest that a provider follows recognized security practices. PCI DSS governs handling card payments. HIPAA covers US health data, and GDPR governs personal data for anyone with EU users. Which ones matter depends entirely on what you build and who you serve.
The reason this belongs in a hosting glossary is that your provider's certifications can decide whether you're allowed to use them. Process health records and you need a host that will sign a HIPAA business associate agreement. Handle EU customer data and GDPR pushes you toward keeping that data in an EU region. This site tracks which compliance standards each provider publishes, because for regulated workloads it's a hard filter, not a nice-to-have.
The nuance is that a provider being certified doesn't make you compliant, it's a prerequisite, not the finish line. You still have to configure and operate your part correctly. But building on infrastructure that lacks the certification you need is a non-starter, so it's often the first thing to check.
Go deeper
- Cloud Hosting Security: What's Your Job vs the Provider'sThe shared responsibility model, and the specific things people forget to configure.
- How to Actually Choose Between Cloud ProvidersA decision process that starts with your constraints, not with a spec comparison table.