# Security

Source: https://docs.quake.ai/docs/security
Markdown: https://docs.quake.ai/docs/security.md
> Understand the Quake AI shared responsibility model: the platform secures the infrastructure while you protect your workloads, data, and access.

---

# Security

Quake AI follows a **shared responsibility** model: the platform secures the underlying infrastructure, and you configure and protect your workloads, data, and access within your projects.

## Shared responsibility at a glance

| Area | Platform responsibility | Your responsibility |
|---|---|---|
| Physical infrastructure | Datacenter security, hardware, power, cooling | N/A |
| Hypervisor and host OS | Isolation between tenants, patching | N/A |
| Network backbone | Backbone integrity, DDoS mitigation | Security groups, firewall rules, and TLS on public endpoints |
| API authentication | Keystone identity, token issuance | Credential rotation, app credential scope, MFA |
| Compute instances | VM placement, host security | OS patching, SSH key management, user data scripts |
| Block storage | Volume encryption at rest (infrastructure layer) | Access control, snapshot policies, backup strategy |
| Object storage | Storage infrastructure availability | Bucket policies, SSE-C/SSE-OMK encryption, access control |
| Kubernetes | Control plane provisioning (via Magnum) | RBAC, network policies, image scanning, secrets |
| Service availability | API uptime, regional redundancy | Workload redundancy, health checks, auto-scaling |

For the full breakdown, see [Shared responsibility model](/docs/security/shared-responsibility).

## Get started

Start with the [Security hardening checklist](/docs/security/hardening-checklist) for an actionable walkthrough of the most important security configurations for a new project.

## Security guides
- [How to store application secrets and inject them at runtime](/docs/security/how-to/inject-app-secrets)

## Network security

- [Security groups](/docs/network/concepts/security-groups): concepts
- [Create a security group](/docs/network/how-to/create-security-group)
- [Create security group rules](/docs/network/how-to/create-security-group-rules)
- [Security groups CLI reference](/reference/network/security-groups-cli)
- [Issue and auto-renew a TLS certificate](/docs/network/how-to/lets-encrypt-certificate)
- [Put a CDN in front of a workload](/docs/network/how-to/front-with-cdn)
- [Put a WAF in front of a workload](/docs/network/how-to/front-with-waf)

## Object storage security

- [Server-side encryption (SSE-C and SSE-OMK)](/docs/object/how-to/configure-server-side-encryption)
- [Grant access control](/docs/object/how-to/grant-access-control)
- [Example IP whitelist policy](/reference/object-storage/bucket-policies#ip-whitelist)
- [Example public read policy](/reference/object-storage/bucket-policies#public-read)
- [Example read-only policy](/reference/object-storage/bucket-policies#read-only-principal)
- [Example restricted public read policy](/reference/object-storage/bucket-policies#restricted-public-read-prefix)
- [Example reversible read-only policy](/reference/object-storage/bucket-policies#user-reversible-read-only-principal)

## Related services

Security configurations exist in each service. [Compute](/docs/compute) instances use SSH key pairs and security groups. [Network](/docs/network) provides firewall rules and public addressing. Application servers, reverse proxies, CDNs, and WAFs terminate TLS. [Storage](/docs/platform#storage) offers encryption at rest and bucket policies. [Kubernetes](/docs/kubernetes) adds RBAC and network policies at the workload level.
