TiDB clears security review & names CISO Robert Wood
Wed, 2nd Sep 2026 (Today)
TiDB has published the results of an independent source-code security assessment by NCC Group. The review found no critical-, high- or medium-severity vulnerabilities.
It also appointed Robert Wood as Chief Information Security Officer.
NCC Group was given access to TiDB's source code and combined that review with dynamic testing of the running system. The assessment covered the TiDB platform and went beyond a conventional penetration test by examining both the underlying implementation and the system's behaviour in a live environment.
Every issue identified in the review was rated low severity, the lowest level on the scale used in the assessment. TiDB said it would publish the full NCC Group report regardless of the outcome, rather than issue only a summary.
The move comes as database suppliers face closer scrutiny from corporate buyers, particularly when systems underpin AI applications, regulated workloads and other critical operations. Security checks are moving earlier in procurement decisions, and customers are asking for independent validation rather than relying only on certifications and vendor claims.
Broader checks
TiDB framed the source-code review as distinct from controls-based audits such as SOC 2 and ISO-related assessments. Those audits test whether an organisation has established and follows processes and controls, while a code-assisted assessment examines the technology itself and how it performs in operation.
That distinction matters for database software because it sits at a foundational layer of the technology stack. Weaknesses at that level can affect multiple applications and services that depend on the database as a system of record.
The NCC Group assessment forms part of a wider trust and compliance programme. TiDB undergoes independent audits for SOC 2 and PCI DSS compliance and says its data protection practices align with ISO standards, GDPR, the EU-U.S. Data Privacy Framework and HIPAA.
Platform security measures cited by TiDB include end-to-end encryption, multi-factor authentication, granular access controls, data governance tools and continuous threat detection. TiDB Cloud Dedicated carries a monthly uptime commitment of at least 99.99 per cent.
Security leadership
Wood joins to lead product security, cloud infrastructure security, governance, risk management and compliance. TiDB said he previously served as Chief Information Security Officer for technology companies and for a US federal agency whose security programme protected data covering more than 100 million people.
His remit also includes the company's assurance roadmap and the scheduling of future independent assessments. TiDB intends to commission such reviews on a recurring basis because any single assessment reflects a specific software version at a particular point in time.
Publishing a full external report is relatively unusual in enterprise software, where vendors often disclose broad conclusions rather than complete findings and methodology. For buyers, especially in regulated sectors, access to the underlying report gives security teams and auditors more material to review during due diligence.
Databases have taken on a more prominent role in recent years as companies build AI tools, operational systems and analytics platforms on top of them. That has increased pressure on suppliers to show not just that internal controls are in place, but that independent testers have examined the core software.
Max Liu, Co-Founder and Chief Executive Officer of TiDB, said the decision to open the code for review was intended to provide that evidence. "Trust is earned through transparency and independent validation," Liu said. "We handed over our source code and committed to publishing whatever came back before we knew what it would say. Coming through that review with every finding at the lowest severity rating is a result we are proud of, and it is the kind of evidence our customers expect rather than security claims."
Wood described the review as a more exacting test than a standard controls audit. "A source-code assessment is a more demanding form of review than a controls audit, and the teams evaluating a database know the difference," he said. "Clearing one with no critical, high or medium-severity findings says something real about how this platform is built. My goal is to maintain that standard, put independent review on a regular cadence, and make sure customers get clear answers about how TiDB is built, secured and governed."