PlanetScale offers the world’s fastest and most scalable cloud hosting for Vitess and Postgres.
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 1
Publicly advertised on the organization’s trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
PCI DSS
Payment card industry standard for handling cardholder data securely.
-
HIPAA
Public claim of compliance with US health-data privacy and security rules. HIPAA has no certification; compliance is self-attested.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
-
CCPA
Publicly advertised on the organization’s trust center.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Planetscale discloses on its trust center. Linked entries have their own profile in the Trust Index.
60% chain trust: 12 of 20 disclosed subprocessors are themselves in the Trust Index.
- Amazon Web Services Data Hosting
- ClearFeed Chat-based Customer Support
- ClickHouse Data hosting and analytics
- Datadog Application monitoring
- Fivetran Data synchronization
- GitHub Code hosting
- Google Cloud Data Hosting, and Internal Infrastructure
- Koala Sales Pipeline Generation
- Okta Centralized identity provider
- Panther Security Information & Events Management
- Pusher Ltd. Real-time Notification Service
- Slack Internal communications
- Stripe Payment processing
- Salesforce Customer Relationship Management
- Sendgrid Transactional Mail Service
- Sentry Application monitoring
- Segment Customer Analytics
- Vercel Web hosting
- WorkOS Single sign-on and directory sync
- Zendesk Cloud-based Customer Support
Named as a subprocessor by
Organizations in the Trust Index that disclose Planetscale as a subprocessor.
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.