TiDB said on July 28, 2026, in Singapore that it had unveiled a new whitepaper titled 'Secure by Design: TiDB Cloud on Alibaba Cloud'. The company said the paper provides an overview of the security architecture, data protection mechanisms, compliance frameworks, and operational controls governing TiDB Cloud when deployed on Alibaba Cloud.

According to TiDB, the whitepaper covers infrastructure and control plane topics including secure provisioning and automated deployment of the Regional Control Plane on Alibaba Cloud Container Service for Kubernetes, along with continuous integration workflows, RAM role assignments, and API gateway security. It also covers the data plane and core services, including core TiDB cluster components, Backup & Restore, Change Data Capture, and the use of Alibaba Cloud PrivateLink for isolated private network transit.

TiDB said the paper also addresses security and observability operations, including regional observability and metering systems, component image synchronization via Alibaba Cloud Container Registry, high-risk privilege management, and continuous vulnerability and compliance monitoring. The company said the whitepaper is designed for CISOs, security architects, infrastructure leaders, and cloud platform teams.

The release said TiDB Cloud on Alibaba Cloud is delivered as a fully managed Database-as-a-Service, enabling customers to provision, manage, and scale databases through the TiDB Cloud Console, APIs, and SQL endpoints without managing the underlying infrastructure. It added that Alibaba Cloud provides the underlying compute, storage, networking, and physical infrastructure to TiDB, while customers are responsible for securing their applications, managing database users and access policies, configuring network connectivity, and administering customer-managed encryption keys where applicable.

Source note

Read the official announcement for the underlying details.