Skip to content

Security

Overview · Updated May 2026

Coming from another cloud?

▸AWS·Security Pillar

This Quake AI feature maps to AWS’s Security Pillar.

▸DigitalOcean·Security

This Quake AI feature maps to DigitalOcean’s Security.

Security

Quake AI follows a shared responsibility model: the platform secures the underlying infrastructure, and you configure and protect your workloads, data, and access within your projects.

Shared responsibility at a glance#

AreaPlatform responsibilityYour responsibility
Physical infrastructureDatacenter security, hardware, power, coolingN/A
Hypervisor and host OSIsolation between tenants, patchingN/A
Network backboneBackbone integrity, DDoS mitigationSecurity groups, firewall rules, and TLS on public endpoints
API authenticationKeystone identity, token issuanceCredential rotation, app credential scope, MFA
Compute instancesVM placement, host securityOS patching, SSH key management, user data scripts
Block storageVolume encryption at rest (infrastructure layer)Access control, snapshot policies, backup strategy
Object storageStorage infrastructure availabilityBucket policies, SSE-C/SSE-OMK encryption, access control
KubernetesControl plane provisioning (via Magnum)RBAC, network policies, image scanning, secrets
Service availabilityAPI uptime, regional redundancyWorkload redundancy, health checks, auto-scaling

For the full breakdown, see Shared responsibility model.

Get started#

Start with the Security hardening checklist for an actionable walkthrough of the most important security configurations for a new project.

Security guides#

Network security#

Object storage security#

Security configurations exist in each service. Compute instances use SSH key pairs and security groups. Network provides firewall rules and public addressing. Application servers, reverse proxies, CDNs, and WAFs terminate TLS. Storage offers encryption at rest and bucket policies. Kubernetes adds RBAC and network policies at the workload level.

Was this page helpful?