tencent cloud

Compliance Center
In alignment with diverse national and industry-specific regulatory requirements, Tencent Cloud remains dedicated to delivering secure, reliable, and trustworthy cloud services to our customers.
Ensure Security and Privacy Compliance
Security Compliance Certifications & Audits
Tencent Cloud has built a compliance framework based on globally recognized standards and obtained multiple international security and privacy certifications, providing solid assurance for the trustworthy operation of cloud services.
Security Responsibility & Controls Framework
Our Security Whitepaper details the Shared Responsibility Model and our multi-layered technical & organizational controls verified by independent third-party audits.
Privacy by Design & Data Protection
The Privacy Whitepaper outlines our data lifecycle governance, privacy impact assessments, and adherence to global data protection regulations like GDPR.
Security Compliance Certifications & Audits
Tencent Cloud has built a compliance framework based on globally recognized standards and obtained multiple international security and privacy certifications, providing solid assurance for the trustworthy operation of cloud services.
Security Responsibility & Controls Framework
Our Security Whitepaper details the Shared Responsibility Model and our multi-layered technical & organizational controls verified by independent third-party audits.
Privacy by Design & Data Protection
The Privacy Whitepaper outlines our data lifecycle governance, privacy impact assessments, and adherence to global data protection regulations like GDPR.
Security Best Practices
Overview of Tencent Cloud Security and Compliance Management System
Tencent Cloud has established a robust security and compliance framework anchored in a shared responsibility model and validated by international certifications such as ISO 27001 and SOC. By integrating systematic risk management, strict technical controls (including identity authentication and full-chain monitoring), and a multi-layered protection system covering physical and network security, the platform continuously enhances its standards through third-party audits to provide customers with reliable and compliant cloud operations.
Meeting Your Compliance Goals
Cloud Audit
A recording and tracking service for operations of Tencent Cloud resources.
Cloud Config
Config assists you in centralized auditing and governance of cloud resources.
Compliance Program
Compliant with various country-specific and industry-specific requirements, Tencent Cloud is committed to creating secure, reliable, and trustworthy cloud services for our customers.
Data Privacy & Security
We take your data privacy and security very seriously. Whether you are an individual user, a small business owner or a large corporation, we take steps to ensure that your content is stored and processed by us in a transparent way and using secure and reliable technology.
Information Request
These guidelines govern requests from law enforcement or government authorities for the disclosure of user data related to Tencent Cloud International Services.
Security Expert Service
Take full advantage of our expert support services to meet your specific business needs in various scenarios and ensure smooth business development in the cloud.
Frequently Asked Questions
Shared security responsibilities
Customers' rights to their content data
Content data access
Data storage and cross-border transfer
Safety and compliance qualifications
What responsibilities does Tencent Cloud bear for cloud environment security?

Tencent Cloud's responsibility for cloud environment security includes ensuring the security of the underlying physical and infrastructure layers of the entire cloud computing environment, and is responsible for the security and compliance of the cloud platform and the cloud products it provides.

Specifically, Tencent Cloud is responsible for the secure operation and management of data center physical facilities, physical servers, and network equipment, as well as the security and compliance of cloud platforms (such as the virtualization layer and management platform) and all cloud products/services at the design, development, and operation levels, and obtains and maintains relevant security certifications.

In the IaaS model, Tencent Cloud is also responsible for the security management of the virtualization control layer; in the PaaS model, Tencent Cloud shares responsibility for virtualization network and host security, cloud application security, and security configuration policies; in the SaaS model, Tencent Cloud is further responsible for the security of cloud application layers.

For more information on Tencent Cloud platform and product security, please refer to Tencent Cloud Security White Paper.

What responsibilities do customers bear for security in the cloud?

The customer's responsibility for cloud security includes ensuring the security of their own data, identity access, and the configuration and management of cloud resources.

Specifically, this includes: bearing ultimate responsibility for the security of all business data uploaded, stored, and processed in the cloud; being responsible for the security of their Tencent Cloud account and the management of account-based access control policies; and correctly configuring and using the cloud products (including security products) they purchase according to their own business security needs.

In the IaaS model, the customer is also responsible for the operating system, middleware, and internal network security configuration of the cloud servers they purchase; in the PaaS and IaaS models, the customer is responsible for the security of their self-built applications deployed in the cloud.

What is customer content data?

Customer content data refers to any data submitted, uploaded, transmitted, or displayed by customers using services provided by Tencent Cloud, including but not limited to text, audio, video, or images. Customer content data is entirely under the control of the customer.

Tencent Cloud, as the data processor, processes this data only in accordance with the methods and purposes stipulated in the agreements signed with the customer (such as the Terms of Service, Data Processing, and Security Agreements). You are fully responsible for ensuring that only specific personnel can perform specific operations on specific data.

Tencent Cloud will leverage Tencent's years of compliance management practices to provide you with comprehensive data security and privacy protection tools and technologies to help you better manage your cloud-based customer data.

What rights do customers have over their content data?

Customers are the owners and controllers of the content data they upload to Tencent Cloud (customer cloud business data). They can independently decide the purpose, method, and scope of data processing and lead the entire lifecycle management of their data.

Tencent Cloud, as the data processor, only processes this data according to the methods and purposes agreed upon in the agreements signed with customers (such as service terms, data processing, and security agreements), and will not actively access or use this data for its own purposes.

Customers can choose their own data storage region (availability zone). When purchasing cloud products, customers can select the availability zone for data storage on the purchase page. When customers need to respond to their users' (data subjects') requests regarding their personal data rights (such as access, correction, deletion, restricted processing, and data portability rights), Tencent Cloud is obligated to provide necessary technical support to empower customers to manage the data under their control.

At the same time, Tencent Cloud is committed to maintaining the confidentiality of customer data in accordance with relevant laws and regulations.

Tencent Cloud provides security guarantees for customer data in storage through technical (such as encryption and access control) and management measures to help customers achieve the availability, integrity, and confidentiality of their cloud data.

Does Tencent Cloud access customer content data?

As a cloud service provider, Tencent Cloud promises that, unless otherwise stipulated by laws and regulations or agreed upon by both parties, it will not access or use the content data hosted by customers on Tencent Cloud.

When a customer explicitly requests operational support from Tencent Cloud or when the nature of the services provided by Tencent Cloud necessitates processing the customer's content data, Tencent Cloud will obtain explicit authorization from the customer in advance and will process the data in accordance with the principle of minimum necessity.

Furthermore, Tencent Cloud employs strict operational access control processes and technical measures to prevent Tencent Cloud's backend operations personnel from unauthorized access to or manipulation of the customer's content data stored in the cloud.

How does a multi-tenant cloud prevent unauthorized third parties from accessing customer content data?

Tencent Cloud adheres to the principle of "data privacy" and employs multi-layered technical isolation measures to ensure that customer data within the same resource pool is not visible to each other, technically guaranteeing that tenants cannot access, obtain, or tamper with other tenants' data.

Tencent Cloud safeguards multi-tenant data confidentiality in the following four ways:

  • Virtualization Layer: Tencent Cloud applies mature hardware virtualization technology to provide complete virtual resource isolation capabilities between tenants for cloud servers and other resources in the virtualization layer. The network, memory, disk and other resources of different users are all prevented from communicating and accessing each other through underlying logical access control, ensuring that each customer can only access the cloud computing resources they have purchased, and effectively achieving data isolation between different customers.
  • Network layer: Virtual Private Cloud VPC (Virtual Private Cloud) is a dedicated cloud network space built by Tencent Cloud for its customers. Customers can achieve logical network isolation by configuring a private network. VPCIt allows for custom network segmentation, IP address and routing policies, and filters traffic from the subnet and host dimensions through network ACLs and security groups, ensuring data isolation between different customers through complete network isolation.
  • Cloud Database Layer: When customers use cloud databases, Tencent Cloud isolates the network layer through firewall policies and a whitelist filtering mechanism. Furthermore, Tencent Cloud uses access control mechanisms for database instances to ensure that each customer can only access their corresponding data and cannot access other customers' data. In addition, Tencent Cloud also provides dedicated cluster databases, allowing customers to exclusively use physical cluster resources and flexibly create cloud databases of various custom specifications.
  • Object storage: Verifies the legitimacy of requests through key signing and supports setting public or private read/write permissions for stored objects as needed, ensuring controlled data access.

For more information on data security, please see Tencent Cloud Security White Paper.

Where will customer data be stored?

Tencent Cloud's infrastructure covers 26 geographic regions globally.

Tencent Cloud allows customers to choose their preferred region for storing their data within its geographically targeted products. Different Tencent Cloud regions are completely isolated, ensuring maximum stability and fault tolerance.

Customer content data will not be transferred outside the customer's chosen Tencent Cloud region without their consent.

Will Tencent Cloud move (including cross-border transfers) customers' content data without their permission?

As a data processor, Tencent Cloud will not transfer customer business data to regions outside their chosen region. As a data controller, customers should select an appropriate Tencent Cloud region based on their needs.

Before transferring (disclosing/sharing) personal data to other organizations, the purpose of the transfer, the content of the data to be transferred, and the names of other data processing organizations receiving the data should be communicated to the data subject, with corresponding legal grounds.

When personal data is transferred outside the country (region) where the data subject resides, appropriate laws and regulations should be identified to ensure that corresponding control measures are deployed and implemented in accordance with legal requirements.

This includes, for example, signing a data transfer agreement with the receiving party in a third country, clearly defining the control requirements for data processing, jurisdiction, sufficiency assessment, mitigation scenarios, and appropriate safeguards (depending on applicable legal requirements).

What security compliance qualifications has Tencent Cloud obtained?

Compliance is the foundation of Tencent Cloud's development.

Tencent Cloud identifies and adopts advanced international and industry security standards, adheres to the compliance requirements of different countries/regions and industries, continuously improves its internal management system, enhances its security control level, and strives to create cloud services that customers can trust.

At the same time, Tencent Cloud actively participates in the formulation and promotion of industry security standards, adheres to the principle of compliance as a service, and builds and operates a secure and reliable cloud ecosystem.

To date, Tencent Cloud has obtained multiple security and privacy compliance certifications or qualifications through independent third-party audits or assessments, including: ISO 27001 Information security management system certification CSA STAR Cloud security certification SOC 1/SOC 2/SOC 3 Report Other regional and industry safety certifications or audit reports.

For more information on Tencent Cloud security compliance, please see Tencent Cloud Compliance page.

How to obtain Tencent Cloud's security compliance certificate?

Tencent Cloud has obtained multiple security and privacy compliance certifications or qualifications through independent third-party audits or assessments, demonstrating that Tencent Cloud's security management and privacy protection practices meet relevant certification standards or industry best practices.

For more information on Tencent Cloud compliance, please see Tencent Cloud Compliance Page.

If clients require any relevant compliance certificates or reports, please click to download them on the qualifications details page, or through Tencent Cloud Compliance Document Center Apply and download.

Frequently Asked Questions
Shared security responsibilities
Customers' rights to their content data
Content data access
Data storage and cross-border transfer
Safety and compliance qualifications
What responsibilities does Tencent Cloud bear for cloud environment security?

Tencent Cloud's responsibility for cloud environment security includes ensuring the security of the underlying physical and infrastructure layers of the entire cloud computing environment, and is responsible for the security and compliance of the cloud platform and the cloud products it provides.

Specifically, Tencent Cloud is responsible for the secure operation and management of data center physical facilities, physical servers, and network equipment, as well as the security and compliance of cloud platforms (such as the virtualization layer and management platform) and all cloud products/services at the design, development, and operation levels, and obtains and maintains relevant security certifications.

In the IaaS model, Tencent Cloud is also responsible for the security management of the virtualization control layer; in the PaaS model, Tencent Cloud shares responsibility for virtualization network and host security, cloud application security, and security configuration policies; in the SaaS model, Tencent Cloud is further responsible for the security of cloud application layers.

For more information on Tencent Cloud platform and product security, please refer to Tencent Cloud Security White Paper.

What responsibilities do customers bear for security in the cloud?

The customer's responsibility for cloud security includes ensuring the security of their own data, identity access, and the configuration and management of cloud resources.

Specifically, this includes: bearing ultimate responsibility for the security of all business data uploaded, stored, and processed in the cloud; being responsible for the security of their Tencent Cloud account and the management of account-based access control policies; and correctly configuring and using the cloud products (including security products) they purchase according to their own business security needs.

In the IaaS model, the customer is also responsible for the operating system, middleware, and internal network security configuration of the cloud servers they purchase; in the PaaS and IaaS models, the customer is responsible for the security of their self-built applications deployed in the cloud.

What is customer content data?

Customer content data refers to any data submitted, uploaded, transmitted, or displayed by customers using services provided by Tencent Cloud, including but not limited to text, audio, video, or images. Customer content data is entirely under the control of the customer.

Tencent Cloud, as the data processor, processes this data only in accordance with the methods and purposes stipulated in the agreements signed with the customer (such as the Terms of Service, Data Processing, and Security Agreements). You are fully responsible for ensuring that only specific personnel can perform specific operations on specific data.

Tencent Cloud will leverage Tencent's years of compliance management practices to provide you with comprehensive data security and privacy protection tools and technologies to help you better manage your cloud-based customer data.

What rights do customers have over their content data?

Customers are the owners and controllers of the content data they upload to Tencent Cloud (customer cloud business data). They can independently decide the purpose, method, and scope of data processing and lead the entire lifecycle management of their data.

Tencent Cloud, as the data processor, only processes this data according to the methods and purposes agreed upon in the agreements signed with customers (such as service terms, data processing, and security agreements), and will not actively access or use this data for its own purposes.

Customers can choose their own data storage region (availability zone). When purchasing cloud products, customers can select the availability zone for data storage on the purchase page. When customers need to respond to their users' (data subjects') requests regarding their personal data rights (such as access, correction, deletion, restricted processing, and data portability rights), Tencent Cloud is obligated to provide necessary technical support to empower customers to manage the data under their control.

At the same time, Tencent Cloud is committed to maintaining the confidentiality of customer data in accordance with relevant laws and regulations.

Tencent Cloud provides security guarantees for customer data in storage through technical (such as encryption and access control) and management measures to help customers achieve the availability, integrity, and confidentiality of their cloud data.

Does Tencent Cloud access customer content data?

As a cloud service provider, Tencent Cloud promises that, unless otherwise stipulated by laws and regulations or agreed upon by both parties, it will not access or use the content data hosted by customers on Tencent Cloud.

When a customer explicitly requests operational support from Tencent Cloud or when the nature of the services provided by Tencent Cloud necessitates processing the customer's content data, Tencent Cloud will obtain explicit authorization from the customer in advance and will process the data in accordance with the principle of minimum necessity.

Furthermore, Tencent Cloud employs strict operational access control processes and technical measures to prevent Tencent Cloud's backend operations personnel from unauthorized access to or manipulation of the customer's content data stored in the cloud.

How does a multi-tenant cloud prevent unauthorized third parties from accessing customer content data?

Tencent Cloud adheres to the principle of "data privacy" and employs multi-layered technical isolation measures to ensure that customer data within the same resource pool is not visible to each other, technically guaranteeing that tenants cannot access, obtain, or tamper with other tenants' data.

Tencent Cloud safeguards multi-tenant data confidentiality in the following four ways:

  • Virtualization Layer: Tencent Cloud applies mature hardware virtualization technology to provide complete virtual resource isolation capabilities between tenants for cloud servers and other resources in the virtualization layer. The network, memory, disk and other resources of different users are all prevented from communicating and accessing each other through underlying logical access control, ensuring that each customer can only access the cloud computing resources they have purchased, and effectively achieving data isolation between different customers.
  • Network layer: Virtual Private Cloud VPC (Virtual Private Cloud) is a dedicated cloud network space built by Tencent Cloud for its customers. Customers can achieve logical network isolation by configuring a private network. VPCIt allows for custom network segmentation, IP address and routing policies, and filters traffic from the subnet and host dimensions through network ACLs and security groups, ensuring data isolation between different customers through complete network isolation.
  • Cloud Database Layer: When customers use cloud databases, Tencent Cloud isolates the network layer through firewall policies and a whitelist filtering mechanism. Furthermore, Tencent Cloud uses access control mechanisms for database instances to ensure that each customer can only access their corresponding data and cannot access other customers' data. In addition, Tencent Cloud also provides dedicated cluster databases, allowing customers to exclusively use physical cluster resources and flexibly create cloud databases of various custom specifications.
  • Object storage: Verifies the legitimacy of requests through key signing and supports setting public or private read/write permissions for stored objects as needed, ensuring controlled data access.

For more information on data security, please see Tencent Cloud Security White Paper.

Where will customer data be stored?

Tencent Cloud's infrastructure covers 26 geographic regions globally.

Tencent Cloud allows customers to choose their preferred region for storing their data within its geographically targeted products. Different Tencent Cloud regions are completely isolated, ensuring maximum stability and fault tolerance.

Customer content data will not be transferred outside the customer's chosen Tencent Cloud region without their consent.

Will Tencent Cloud move (including cross-border transfers) customers' content data without their permission?

As a data processor, Tencent Cloud will not transfer customer business data to regions outside their chosen region. As a data controller, customers should select an appropriate Tencent Cloud region based on their needs.

Before transferring (disclosing/sharing) personal data to other organizations, the purpose of the transfer, the content of the data to be transferred, and the names of other data processing organizations receiving the data should be communicated to the data subject, with corresponding legal grounds.

When personal data is transferred outside the country (region) where the data subject resides, appropriate laws and regulations should be identified to ensure that corresponding control measures are deployed and implemented in accordance with legal requirements.

This includes, for example, signing a data transfer agreement with the receiving party in a third country, clearly defining the control requirements for data processing, jurisdiction, sufficiency assessment, mitigation scenarios, and appropriate safeguards (depending on applicable legal requirements).

What security compliance qualifications has Tencent Cloud obtained?

Compliance is the foundation of Tencent Cloud's development.

Tencent Cloud identifies and adopts advanced international and industry security standards, adheres to the compliance requirements of different countries/regions and industries, continuously improves its internal management system, enhances its security control level, and strives to create cloud services that customers can trust.

At the same time, Tencent Cloud actively participates in the formulation and promotion of industry security standards, adheres to the principle of compliance as a service, and builds and operates a secure and reliable cloud ecosystem.

To date, Tencent Cloud has obtained multiple security and privacy compliance certifications or qualifications through independent third-party audits or assessments, including: ISO 27001 Information security management system certification CSA STAR Cloud security certification SOC 1/SOC 2/SOC 3 Report Other regional and industry safety certifications or audit reports.

For more information on Tencent Cloud security compliance, please see Tencent Cloud Compliance page.

How to obtain Tencent Cloud's security compliance certificate?

Tencent Cloud has obtained multiple security and privacy compliance certifications or qualifications through independent third-party audits or assessments, demonstrating that Tencent Cloud's security management and privacy protection practices meet relevant certification standards or industry best practices.

For more information on Tencent Cloud compliance, please see Tencent Cloud Compliance Page.

If clients require any relevant compliance certificates or reports, please click to download them on the qualifications details page, or through Tencent Cloud Compliance Document Center Apply and download.

More Compliance Resources
Learn More About Tencent Cloud Compliance
Access and download the latest compliance certificates, audit reports, and security whitepapers anytime.
Visit Compliance Documents