Documentation Index
Fetch the complete documentation index at: https://docs.brightdata.com/llms.txt
Use this file to discover all available pages before exploring further.
Certifications at a Glance
ISO/IEC 27001:2022
ISO/IEC 27017:2015
ISO/IEC 27018:2019
SOC 2 Type II
SOC 3
CSA STAR
How independent audits work
SOC 3 Report - Deloitte
Conducted by Brightman Almagor Zohar & Co., a firm in the Deloitte Global Network, covering June 1, 2024 – May 31, 2025. The audit examined controls across four trust service criteria:Security
Availability
Confidentiality
Privacy
“In our opinion, management’s assertion that the controls within the Service Organization’s system were effective… to provide reasonable assurance that Bright Data’s service commitments and system requirements were achieved based on the applicable trust services criteria is fairly stated, in all material respects.”
- Brightman Almagor Zohar & Co. (Deloitte Global Network)
Download SOC 3 Report (PDF)
Penetration Test - Skylight Cyber Security
An independent penetration test and source code review was conducted by Skylight Cyber Security Pty Ltd (May–June 2025), covering the full Bright Data product surface. Products tested:| Product | Coverage |
|---|---|
| Control Panel & Public APIs | Full |
| Datacenter, Residential, Mobile, and ISP Proxies | Full |
| SERP API and Web Unlocker API | Full |
| Web Scraper IDE, Marketplace, and API | Full |
| Web Archive API | Full |
| Dataset Marketplace and Custom Dataset API | Full |
- Unauthenticated attacker attempting to compromise the entire platform
- Malicious administrator attempting internal compromise
- Unauthorized account access or proxy misuse
Download Penetration Test Attestation
How data encryption works
| Layer | Standard |
|---|---|
| Data in transit | TLS 1.3 (minimum TLS 1.2) with modern cipher suite |
| Data at rest | AES-256 or better across all infrastructure |
| Credentials | Hashed and salted using a modern hash function |
| Database backups | Encrypted; daily full backups, monthly snapshots |
| Backup storage | AWS Backup; snapshots distributed across locations |
Infrastructure & Availability
Cloud Provider
Disaster Recovery
Backup Frequency
DDoS & Monitoring
Access Control & Identity
| Control | Implementation |
|---|---|
| Least privilege | All IAM roles scoped to minimum required permissions |
| MFA | Required for all AWS platform access by employees |
| Customer authentication | Strong password (min. 8 chars) + email verification |
| RBAC | Role-Based Access Control with regular user access reviews |
| Third-party access | Re-authorized annually; requires signed NDA and InfoSec approval |
| Remote access | VPN with encryption required; host-check enforced |
Application & Development Security
- CI/CD pipeline - Controlled pipeline with end-to-end and unit testing, including authorization testing
- Secure SDLC - Based on the OWASP Top 10 framework; security requirements defined before development begins; annual developer security training
- Change management - Formal review and approval process for all infrastructure and application changes, including security risk evaluation at R&D review stage
- Third-party risk (TPRM) - All vendors mapped and classified by risk tier; high-risk suppliers require security questionnaire and InfoSec sign-off before contract
- Bug bounty - Managed private program for responsible disclosure by independent security researchers
Privacy & Regulatory Compliance
| Regulation / Standard | Status |
|---|---|
| GDPR (EU) | ✅ Compliant - DPIAs conducted as part of product flows |
| CCPA (California) | ✅ Compliant |
| UK Data Protection Act | ✅ Compliant |
| Virginia Privacy Law | ✅ Compliant |
| Israeli Privacy Protection Law (1981) | ✅ Compliant |
| ISO 27001:2022 | ✅ Certified |
| CSA STAR | ✅ Listed |
| PCI DSS | ✅ Working compliance |
- Privacy policy reviewed and updated annually - brightdata.com/privacy
- Customer data deletion available at any time upon request
- Data selling - Bright Data does not sell or license customer data to any third party
Information Security Policy
Bright Data maintains a formal, board-approved Information Security Policy aligned with NIST, ISO 27001:2022, ISO 27017, and ISO 27018.Identity & Access Management
Identity & Access Management
Network & Encryption
Network & Encryption
Endpoint & Server Hardening
Endpoint & Server Hardening
Secure SDLC
Secure SDLC
Third-Party & Vendor Security
Third-Party & Vendor Security
Data Classification
Data Classification
Incident Response & Business Continuity
Incident Response & Business Continuity
Security for AI Agents & MCP Users
Bright Data’s MCP Server and Browser API operate under the same certified security infrastructure described on this page. Recommended practices when using Bright Data in agentic workflows:Treat web content as untrusted
Use structured extraction tools
web_data_* tools where available - they return pre-validated, schema-consistent data.Store credentials securely
Certifications & Reports
ISO 27001 + 27017 + 27018 Certificates
SOC 3 Report
SOC 2 Type II Report
Trust Center
Privacy Policy
Security Vulnerability Reward Program
Frequently Asked Questions
Is Bright Data ISO 27001 certified?
Is Bright Data ISO 27001 certified?
Does Bright Data have a SOC 2 report?
Does Bright Data have a SOC 2 report?
Is Bright Data GDPR compliant?
Is Bright Data GDPR compliant?
Does Bright Data do penetration testing?
Does Bright Data do penetration testing?
Is Bright Data's infrastructure encrypted?
Is Bright Data's infrastructure encrypted?
Is Bright Data safe for enterprise deployments?
Is Bright Data safe for enterprise deployments?
Is Bright Data's MCP Server covered by these certifications?
Is Bright Data's MCP Server covered by these certifications?
For security inquiries: security@brightdata.com For enterprise compliance reviews: Contact sales