ChaptersEventsBlog

STAR Registry Listing for

Confluent Cloud

Confluent Cloud

Confluent delivers a complete distribution of Apache Kafka with its Confluent Cloud system. Confluent Cloud improves Kafka with additional community and commercial features designed to enhance the streaming experience of both operators and developers in production, at massive scale, enabling companies to access data as real-time streams. Confluent Cloud provides customers with the distribution of the Confluent technology, inclusive of Apache Kafka, as a service in the public cloud, simplifying engineering operations and administration of Kafka clusters and related services such as KSQL, Connect, and Schema Registry. Deployed in minutes, it is a streaming data service for the cloud-first developer on a mission or the operations-starved organization. It complements Apache Kafka with administration, monitoring, and management tools. Confluent Cloud is comprised of the following components:

• Kafka – Confluent Cloud provides an application programming interface (API) based service for the latest, stable Apache Kafka version. Confluent handles the upgrades on behalf of its customers and provides it in a seamless fashion.
• Customer Support (optional) – Full support for the range of products offered by Confluent, including Java, Python, C / C++, Go, .NET, as well as the Kafka Streams API.
• Managed Service – Removes the operations burden with Confluent’s fully-managed cloud service:
• Clusters can be created and destroyed on-demand, in any cloud region the service is offered, with any configuration of throughput available.
• Credentials for access to each cluster are self-managed and completely under customers’ control.
• Role-based access control (RBAC) and access control lists (ACLs) protect Confluent Cloud resources and data by authorizing and restricting access of user and service accounts and by delegating access authorization to the appropriate business units and teams in an organization.
• Audit Events capture event records from auditable event methods for Kafka cluster event categories and organization event categories.
• Metrics API supports a diverse set of querying patterns to support usage and performance analysis over time.
• Public and Private Networking allows access to clusters through secure Internet endpoints, PrivateLink connections, Virtual Private Cloud (VPC) / Virtual Network (VNet) peering, or Amazon Web Services (AWS) Transit Gateway, according to cluster type. Connections to Confluent Cloud are encrypted with transport layer security (TLS) and require authentication using API keys or access tokens.

• Confluent Cloud for Apache Flink – provides a cloud-native, serverless service for Flink that enables simple, scalable, and secure stream processing that integrates seamlessly with Apache Kafka.

Confluent Cloud offers the following features:

• Performance – Supports a higher data processing rate than other streaming services. Standard plans and custom plans are available for scales up to 5GBs ingest and 15GBs egress.
• Reliability – Optional support for high availability across multiple Availability Zones (AZs) is available.
• Flexibility – Configurable retention period, storage (infinite storage available), and throughput rate to suit customer workloads.
• Kafka Expertise – Support provided by the team that created Kafka, with the most extensive experience operating it at scale.

A technology-neutral certification leveraging the requirements of the ISO/IEC 27001 management system standard together with the CSA Cloud Controls Matrix (CCM).
Provides guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Service Principles, AT 101) and the CSA Cloud Controls Matrix.
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Information about Confluent Cloud
Listed Since: 08/13/2020
Last Updated: 11/11/2025

STAR Level 1

Self-Assessment & Partner-Provided

Cloud Controls Matrix

CAIQ Self-assessment v4.0.3

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

STAR Level 2

Third-Party Audit

Organizations looking for a third-party audit can choose from one or more of the security and privacy audits and certifications.

Cloud Controls Matrix

STAR Attestation (CCM v3)

Provides guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Service Principles, AT 101) and the CSA Cloud Controls Matrix.

(Deprecated)
Deprecated assessments do not necessarily indicate non-compliance. In this case, the self-assessment has not been updated in more than one year. We suggest contacting this organization directly to request that they submit an updated self-assessment.
Cloud Controls Matrix

STAR Certification (CCMv4)

A technology-neutral certification leveraging the requirements of the ISO/IEC 27001 management system standard together with the CSA Cloud Controls Matrix (CCM).