Skip to main content

Enterprise evaluation FAQ

Encryption at rest​

For AWS deployment, we rely on Amazon's built-in encryption for RDS and S3 buckets. Credentials for data connections are additionally encrypted by Datagrok with server keys.

Encryption in transit​

All client-server communications use the HTTPS protocol, which means it is secure and encrypted.

Server API​

The Datagrok client uses an HTTP REST API to interact with the server. You must pass an authentication token to access all features. Proof of concept video

Logging and monitoring​

Datagrok works with the monitoring tools you already use, in any cloud or on-premises:

  • Logs and alerts. Log sync pushes logs, audit events, alerts, and a heartbeat to Amazon CloudWatch, Google Cloud Logging, or any OpenTelemetry (OTLP) collector. See Export logs.
  • Health checks. The /api/admin/health endpoint reports the status of every service and needs no sign-in, so load balancers and uptime monitors can probe it.
  • Usage and performance. Usage Analysis shows user activity, errors, and server and database metrics.

For details, see Monitor the platform.

Backup and restore​

Back up these together so that you can restore them to the same point in time:

  • The Postgres database that holds metadata, audit logs, and encrypted credentials. You can back it up and restore it as a standard Postgres database, for example with scheduled RDS snapshots on AWS.
  • The file storage (S3, Google Cloud Storage, or a local volume). On AWS, see S3 backup.
  • Server key material, if you keep keys in an external backend.

Disaster recovery​

Datagrok supports Docker installation, Amazon cluster will immediately restart failed instance

Infrastructure as a Code​

Datagrok Docker containers are built using Jenkins. All software is upgraded and patched on every build.

You can deploy Datagrok with standard DevOps tools: