SingleStore Helios and Helios BYOC have been assessed against PCI DSS v4.0.1, the current version of the payment card security standard, by an independent Qualified Security Assessor.

SingleStore Helios (Enterprise Edition) and SingleStore Helios BYOC have achieved PCI DSS v4.0.1 compliance. The assessment was carried out by ControlCase, an independent Qualified Security Assessor (QSA), and reviewed the security controls in place across the in-scope Helios cloud platform to validate its PCI compliance.
PCI DSS is the security standard for environments that handle payment card data. PCI compliance means an independent assessor has evaluated SingleStore Helios against the standard's requirements. If you run payment or other cardholder data workloads on Helios, the managed platform underneath your application already sits inside a validated control set. It does not make your application compliant on its own, but it takes the platform layer off your list of things to assess and evidence from scratch.
“Security is more than a compliance requirement for us; it is a commitment to our customers. Reaching PCI DSS v4.0.1 reflects the work of our engineering, cloud infrastructure, site reliability, security, and compliance teams. As customers build more of their critical applications on SingleStore Helios, we will keep investing in the controls and processes that let them trust the platform with sensitive workloads.”
Nishanth Singarapu, Associate Director, Governance, Risk & Compliance, SingleStore
Why PCI DSS matters
The Payment Card Industry Data Security Standard is maintained by the PCI Security Standards Council (PCI SSC), the body the major card brands set up to define one common baseline for protecting cardholder data. It sets requirements across twelve areas, including access control, encryption, network security, logging and monitoring, and vulnerability management.
v4.0.1 is the current version of the standard, and since March 2025 its full set of requirements has been mandatory. Reaching compliance now means meeting all of them, not the smaller set that applied while the standard was phasing in.
Scope of the assessment
The assessment covers two products:
SingleStore Helios (Enterprise Edition)
SingleStore Helios BYOC (Bring Your Own Cloud)
As part of the PCI compliance assessment, ControlCase validated the controls across SingleStore's fully managed cloud database platform. That includes the Enterprise Database-as-a-Service (DBaaS) offering, multi-tenant cloud environments, cloud-native infrastructure, and the storage and security services that support them. The BYOC model, where Helios runs inside your own cloud account, falls inside the same assessed control set.
Security controls across the Helios platform
PCI DSS maps onto controls Helios already applies as its default posture. The assessment reviewed those controls across several areas.
Identity and access management
Access to production systems requires Multi-Factor Authentication (MFA) and runs through centralized identity management. Administrative access goes over secure VPN connectivity and through bastion hosts rather than direct connections to production. On the customer side, Helios supports single sign-on (SSO) through SAML and OIDC identity providers and SCIM provisioning, with role-based access control (RBAC) at both the portal and the database level. The identity integration and zero trust posts go into how that access model is built.
Encryption and secure communications
Connections to Helios use encrypted HTTPS/TLS, enforced at TLS 1.2 or above for client connections, internal traffic between nodes, and transfers to and from object storage, so there are no plaintext paths. Data at rest is encrypted with AES-256 using cloud-managed Key Management Service (KMS) keys. Customers with key-sovereignty requirements can supply and control their own keys through Customer-Managed Encryption Keys.
Continuous monitoring
Logs from infrastructure and applications are centralized so the security team can detect, investigate, and respond to suspicious activity. Audit logging covers both control-plane and database-level operations, which is what produces the evidence trail an assessment like this depends on.
Vulnerability management
The platform is scanned for vulnerabilities on a regular schedule, with defined remediation and change-management processes to fix and track what the scans surface.
Secure cloud infrastructure
Helios runs on Amazon Web Services (AWS). Each deployment sits in a discrete AWS account within the cloud region and uses dedicated Virtual Private Clouds (VPCs) and network segmentation to isolate compute, with a dedicated object storage bucket per cluster and cloud-native security controls applied at the infrastructure layer. Cluster endpoints are not exposed to the public internet by default; access requires explicit IP allowlisting. The security documentation sets out the platform's baseline in full.
Where PCI DSS fits with SingleStore's other certifications
PCI DSS is not the first set of security standards against which the platform has been independently assessed. Helios already holds SOC 2 Type II and ISO/IEC 27001, and supports customers with HIPAA, GDPR, and CCPA obligations. PCI DSS v4.0.1 adds payment card data to that set. For teams evaluating the platform, the practical effect is that more of your own compliance scope can inherit from an already-assessed foundation, whichever framework you report against. The compliance certifications post covers how that inheritance works, and the security page lists the current set.
Shared responsibility: what this covers, and what stays with you
SingleStore's compliance covers the managed platform: the infrastructure, operational controls, and security capabilities Helios provides. It does not extend to the applications and data you deploy on top of it.
Under the shared responsibility model, SingleStore secures the platform and you secure how you use it. In concrete terms, SingleStore owns the encryption defaults, network isolation, patching, and the operational controls behind the assessment. You own your IP allowlist, your identity provider integration and group-to-role mappings, your database RBAC design, your own keys if you use CMEK, and how your application handles any cardholder data it touches. The platform gives you a compliant foundation. It does not make your application compliant on its own. The shared responsibility post and the shared responsibility documentation set out exactly where the line sits.
Compliance as an operating commitment
PCI DSS v4.0.1 compliance is not a one-time certification, and v4.0 was written specifically to discourage treating it that way. Maintaining PCI DSS compliance takes ongoing work: regular assessments, vulnerability management, change control, and coordination across the engineering, infrastructure, site reliability, security, compliance, and operations teams that run the platform. For customers, PCI DSS v4.0.1 is one more independently verified control in the platform they build on, and one SingleStore intends to keep.
Further reading
This announcement sits alongside the Enterprise Security with SingleStore Helios series, which covers each layer of the platform's security in more depth:
For the full architecture, see the SingleStore Helios Cloud Security whitepaper.














