Palantir Foundry is designed to provide secure collaboration in almost any environment, from the cloud to the edge. If you are running Foundry outside of Palantir’s managed SaaS platform, such as in your own datacenter or on your own cloud, observe the following guidance for protecting your installation.
If your Foundry installation is deployed on bare-metal hardware, such as in a datacenter, it is crucial you implement strong physical security controls. Access to servers running Foundry should be restricted to authorized personnel, have time-bound and documented access, and follow industry best practices.
As physical security is foundational to information security, unauthorized access to the hardware running Foundry could allow an adversary the opportunity to perform various attacks and subvert security controls.
To maintain information security, your data must be encrypted both at rest and in transit.
While all data in Foundry is encrypted at-rest using application-level encryption, you should encrypt all underlying servers and storage devices used in your Foundry installation.
All data transmitted between your clients and Foundry should be protected using strong encryption protocols and ciphers.
You should centrally manage identities in your single sign-on provider.
You should require your users to have strong credential hygiene. Passwordless authentication is strongly recommended.
You should use modern zero trust technologies to protect your Foundry installation.
Your Foundry installation should be highly segmented from the rest of your environment.
Network traffic originating from your Foundry installation should be strictly controlled.
You should use network security controls to protect your Palantir Foundry installation.
The servers used for your Foundry installation should be hardened using industry-standard configuration guidance such as CIS or NIST controls.
You should use host security controls to protect your Foundry installation.
You should strictly control privileged access to your Foundry installation.
You should take periodic full-disk backups of your Foundry installation for organizational continuity purposes.
You should apply security patches to your Foundry installation as soon as possible.