You can find more information on that topic here.
"With Databricks, your serverless workloads are protected by multiple layers of security. These security layers form the foundation of Databricksโ commitment to providing a secure and reliable environment for even the most sensitive workloads.
They include but are not limited to:
- Dedicated compute resources
- Each workload runs on compute and encrypted storage that is dedicated to that workload
- Storage cannot be reallocated or reassigned after use
- Both the compute and the storage are securely wiped as soon as the workload completes
- Network segmentation
- Each workload operates within a private network with no public IP addresses assigned
- That network is isolated logically from other workloads
- Lateral movement or communication between workloads is blocked
- All traffic between the user, the control plane, the compute plane and cloud services is routed over the cloud providerโs global network, not the public internet
- Encryption at rest and in transit
- All attached storage is protected by industry-standard AES-256 encryption
- All traffic between the user, the control plane, the compute plane and cloud services is encrypted with at least TLS 1.2
- Principle of least privilege
- Workloads have no privileges or credentials for systems outside the scope of that workload
- Access to the data is via short-lived (1-hour) tokens
- These tokens are passed securely to each specific workload"