Bemærk
Adgang til denne side kræver godkendelse. Du kan prøve at logge på eller ændre mapper.
Adgang til denne side kræver godkendelse. Du kan prøve at ændre mapper.
This article describes the compliance standards and security profile support for Databricks Foundation Model APIs.
Databricks Foundation Model APIs support various compliance standards to meet enterprise security and regulatory requirements. The availability of these standards can vary by region and deployment mode: pay-per-token or provisioned throughput.
Compliance standards support: Pay-per-token
Pay-per-token workloads support the full range of compliance standards available for Model Serving:
- HIPAA compliance across all regions.
- Additional compliance standards (PCI-DSS, FedRAMP, IRAP, CCCS, UK Cyber Essentials Plus) in supported regions.
- See Compliance security profile for the available compliance standards. Each standard has its own page that lists the regions and features it supports.
- Available for customers with the Compliance Security Profile enabled, including when a compliance standard is selected.
Compliance standards support: Provisioned throughput
Provisioned throughput workloads support the full range of compliance standards available for Model Serving:
- HIPAA compliance across all regions.
- Additional compliance standards (PCI-DSS, FedRAMP, IRAP, CCCS, UK Cyber Essentials Plus) in supported regions.
- Recommended for all workloads that require compliance certifications beyond HIPAA.
Note
These compliance standards require served containers to be built in the most recent 30 days. Databricks automatically rebuilds outdated containers on your behalf. However, if this automated job fails, an event log message like the following appears:
"Databricks couldn't complete a scheduled compliance check for model $servedModelName. This can happen if the system can't apply a required update. To resolve, try relogging your model. If the issue persists, contact support@databricks.com."
Data processing and residency
The region and corresponding geography where your Foundation Model API requests are processed depends on your workspace region and the specific model being used:
- As part of providing the Foundation Model APIs, Databricks might process your data outside of the region where your data originated, but not outside of the relevant geographical location.
- If your workspace is in a Model Serving region but not a US or EU region, your workspace must be enabled for cross-Geo data processing.
- See Designated Services for geographic areas that process pay-per-token and provisioned throughput workloads.
Regional model availability
Certain models have regional restrictions based on compliance and infrastructure requirements.
The following table summarizes region availability limitations for pay-per-token endpoints:
| Region | Models | Details |
|---|---|---|
| US-only models | The following models are supported only in Foundation Model APIs pay-per-token supported US regions:
|
Anthropic Claude Sonnet 5 is available in other supported Model Serving regions, including EU regions and japaneast, when you enable cross-Geo data processing. |
| EU and US models | The following models are available in pay-per-token EU and US supported regions.
|
If your workspace is not in an EU or US region but is in a supported Model Serving region, you can enable cross-Geo data processing to access these models. Workspaces in japaneast must enable cross-Geo data processing to access these models. |
| EU, US, and Japan models | The following models are available in pay-per-token EU and US supported regions and in japaneast:
|
If your workspace is not in an EU, US, or Japan region but is in a supported Model Serving region, you can enable cross-Geo data processing to access these models. |
Security best practices
To restrict which Databricks-hosted foundation models your organization can invoke, see foundation model Unity Catalog permissions.
| Topic | Details |
|---|---|
| Access control |
|
| Network security |
|
| Container security |
|