Skip to main content
As with any other cloud service, security is a shared concern between Algolia and its subscribers. Algolia takes full responsibility for the security of its infrastructure. You must follow recommended practices to keep your data and account safe.

Algolia’s security responsibilities

Algolia secures its service. This includes securing the physical and virtual infrastructure, and staying compliant with security standards and certifications. It also includes strong security practices, such as API keys with access control lists (ACL) and two-factor authentication. Algolia also provides SAML SSO and AES256 encryption for users with the Enterprise add-on. Algolia also makes sure its providers follow strong security rules. All Algolia employees receive continuous security training. Each new Algolia team member goes through mandatory security training. Algolia secures the service. It’s Algolia’s job to secure everything it gives you, including the Algolia libraries.

Your security responsibilities

Algolia handles defects in the service. Algolia isn’t responsible for the results of behavior or use that goes against recommended practices. Algolia also isn’t responsible when you don’t follow the docs for a given use case. You’re responsible for how you use Algolia, and for the data you send. For example, Algolia provides two-factor authentication. But it’s your responsibility to activate it and make sure that your team members do too. The same goes for your data. Algolia offers features that let you keep sensitive data safe from unauthorized users. You must use these features the right way.

Control levels

For shared responsibility within a cloud service, there are three levels of control: inherited, shared, and user. These help you understand what falls under Algolia’s responsibility, and what’s on you.

Inherited controls

These are what you inherit from Algolia, and can’t change. For example, when you create a new Algolia , Algolia provisions it on the platform. For example, you can’t deploy an Algolia application on-premise. This makes Algolia fully responsible for those controls.

Shared controls

These are what comes from Algolia, but you gain control over. Shared controls have shared responsibility. For example:
  • Algolia provides and stores API keys and lets you generate new ones. Algolia is responsible for storing your keys securely and for properly encrypting the virtual ones. You’re responsible for how you store and use your keys on your end.
  • Algolia offers and maintains open source API clients and UI libraries. Use them to benefit from Algolia’s security fixes and updates about potential risks. You’re responsible for upgrading to the latest versions of clients and libraries. You’re also responsible for securing the environment where you run them. It should support the features Algolia builds in, for example, by using HTTPS.
  • Algolia trains its employees and builds security awareness internally. You’re responsible for training your teams.

User controls

These depend only on your use case and needs. They’re your full responsibility. For example, you’re responsible for how you name your indices. You’re also responsible for what data you send to Algolia and how you control access to it. The same goes for which team members you invite to your app, and what access level you give them.

See also

Last modified on September 16, 2026