Distributed SQL database with strong consistency, horizontal scale, and PostgreSQL wire protocol compatibility. License: BSL-1.1 since June 2019 (Cockroach Community License); converts to Apache-2.0 after 3 years per BSL clock. Cockroach Cloud is the managed offering with HIPAA BAA, SOC 2.
CockroachDB is a distributed SQL database with strong consistency, horizontal scale, and PostgreSQL wire protocol compatibility — BSL-1.1 license (Cockroach Community License), 3-year Apache-2.0 conversion clock per BSL. Cockroach Cloud (managed) HIPAA BAA + SOC 2. Pick CockroachDB for true multi-region distributed SQL where Aurora's single-region scale isn't enough.
CockroachDB's distributed-SQL positioning creates a specific trust posture: serializable isolation across regions, automatic data distribution, survive-region-failure semantics. Trade-off: BSL-1.1 license requires procurement review for SaaS deployments. Cockroach Cloud's compliance covers managed; OSS self-host inherits substrate compliance.
Network round-trips for consensus. Sub-100ms typical.
PG wire protocol.
RBAC + row-level. Cap rule N/A.
Multi-region distributed SQL. Strongest A among RDBMS.
Schema metadata.
Per-query stats + cluster metrics.
RBAC + audit. 3/6 -> 4.
Cluster metrics + Prometheus. 3/6 -> 4.
Survive-region-failure semantics. 6/6 -> 5.
PG metadata.
Strict serializable. 6/6 -> 5.
Best suited for
Compliance certifications
OSS BSL holds no certs. Cockroach Cloud HIPAA BAA + SOC 2.
Use with caution for
Aurora for AWS single-region scale. Cockroach for multi-region distributed.
View analysis →Yugabyte for Apache-2.0 alternative + same distributed-SQL model.
View analysis →Role: L1 distributed SQL.
Upstream: PG protocol queries.
Downstream: SQL results + monitoring.
Mitigation: Procurement review.
Mitigation: Benchmark multi-region. Latency adds via consensus.
Mitigation: Test workload's actual SQL.
CockroachDB's specialty.
Postgres or Aurora simpler.
This analysis is AI-generated using the INPACT and GOALS frameworks from "Trust Before Intelligence." Scores and assessments are algorithmic and may not reflect the vendor's complete capabilities. Always validate with your own evaluation.