Third Party Index

Snapshot 55168

Document
Security page
URL
https://mammoth.io/product/security/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
424070 bytes
SHA-256 (raw)
862f4f6a4d1c31b13db870d4b643c563651ee998b270f8444396946e26ddf244
SHA-256 (normalized text)
8ccd232e5b3efd209d30a5e86d173dd536e7d18003961be078a9251475ff322c

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to content
Security
Built for the review that comes before rollout.
Access control through your identity provider, row-level security enforced at query time, restorable checkpoints, and an audit trail you can retain for years. The controls an enterprise evaluation asks about, on the plans that need them.
Request the security packageEnterprise overview
ControlsEnterprise
SSO via SAML & OIDC
Enforced MFA
IP allowlisting
Encryption in transit & at rest
Private cloud deployment
Activity log, 1–7 years
Certified and compliant, and the reports are available
SOC 2 Type II
Controls audited over a period, not a point in time
ISO/IEC 27001:2022
Certified information security management system
HIPAA
Handling of protected health information, with a BAA available
GDPR
EU data protection, with an appointed EU representative
Questionnaire responses, the SOC 2 report and a deployment architecture diagram are available under NDA, and a data processing agreement (DPA) on request: ask your sales contact, or mention it when you book a demo.
Access control
Who can do what, and who can see which rows.
Two separate questions, and most tools only answer the first. Row-level security means one dashboard can serve an entire organisation correctly.
Single sign-on
SAML and OIDC against your identity provider, so access follows joiners and leavers automatically instead of by hand.
Pro and above
Enforced MFA
Require multi-factor authentication workspace-wide rather than hoping individuals switch it on.
Pro and above
IP allowlisting
Restrict workspace access to your office ranges or corporate VPN egress addresses.
Enterprise
Custom roles
Define exactly what a role can connect, transform, publish and see, beyond the standard admin, builder and viewer split.
Pro and above
Row-Level Security
One dashboard, scoped per viewer. Each region, entity or client sees only its own rows, enforced at query time.
Pro and above
Connector governance
Control which sources a team is allowed to connect, so credentials and data movement stay inside policy.
Pro and above
Scoping
One dashboard, correctly scoped per viewer
Rather than building a copy per region and hoping they stay in sync, publish once and let row-level security decide what each person sees. A regional lead opens the same URL as the CFO and sees only their own rows.
Enforced at query time, not by hiding charts
Scoped by user attribute, group or identity-provider claim
Custom roles define capability separately from data scope
Viewers can filter and export within their scope, still free
AccessRow-Level Security
Role	Sees	People
Admin	All regions	2
Builder	All regions	5
Regional lead	Own region only	14
Viewer	Own store only	179
198 of 200 people here are viewers or leads. None of them cost anything.
Auditability
Show how a figure was produced, and what changed since
Regulated reporting needs to be defensible months later. The pipeline is the record, every step readable in order, nothing compiled away, and it versions itself each time it changes, so you can see what was added, removed or modified and when. The activity log records who connected what, who changed which step, and when it ran.
Automatic pipeline versions, each with a change summary
Draft mode so nothing half-finished is ever published
Activity log retained 1–7 years on Enterprise
Every transform shows the row counts it affected
Version historyAutomatic
v14 · currentMargin calc corrected
v13Added ANZ region
v12Approval gate added
v11Initial build
Data handling
Where your data lives, and what we don't do with it.
Encryption
Encrypted in transit and at rest throughout, including intermediate pipeline state.
Private cloud
Enterprise deployments can run in a dedicated environment rather than shared infrastructure.
Data residency
Choose the region your workspace and its data live in. Mammoth operates from London.
Retention on cancellation
Data is retained for 90 days on paid plans and 30 days on Free after cancellation, then deleted.
No training on your data
Your data answers your questions and runs your pipelines. It is never used as model training data.
Uptime commitment
99.5% on Pro and 99.9% on Enterprise, with a named success manager on Enterprise accounts.
What security review asks
Where does our data physically live?
In the region you choose for your workspace. Enterprise deployments can run in a dedicated private cloud environment rather than shared infrastructure.
Can different teams see the same dashboard with different data?
Yes, and this is usually the right pattern. Row-Level Security scopes rows per viewer, so one published dashboard correctly serves every region, entity or client without building copies.
How long do you keep the audit trail?
Activity log retention runs from 7 days on Free, 90 days on Starter, 1 year on Team and 3 years on Pro, up to 1 to 7 years configurable on Enterprise.
Can we prove what a number was on the date it was reported?
Not the number itself. What is preserved is how it was produced: the pipeline versions itself every time it changes, with a summary of what was added, removed or modified and who did it, and the activity log records every run. So you can show the exact logic behind a reported figure and everything that has changed since. If you need the reported values themselves held, that is what a scheduled export gives you: the output as it stood, kept outside the pipeline.
What happens to our data if we cancel?
It's retained for 90 days on paid plans and 30 days on Free, giving you time to export, then deleted. Downgrading rather than cancelling leaves your work and dashboards intact.
Are you certified, and can we see the reports?
Mammoth holds SOC 2 Type II and ISO/IEC 27001:2022 certification, with HIPAA and GDPR compliance. Questionnaire responses, the SOC 2 report and a deployment architecture diagram are available under NDA: mention it when you book a demo and we'll route you to the team that handles security review.
Do you sign a DPA, and who are your sub-processors?
Yes, a data processing agreement is available on request: ask your sales contact, or mention it when you book a demo. Our sub-processors, including the AI model providers behind the App's AI features, are listed in our privacy policy at mammoth.io/privacy.
Bring your security questionnaire.
Book a demo and we'll route you to the team that handles security review, deployment options and documentation.
Book a demoEnterprise overview
SSO & enforced MFA
Private cloud
99.9% uptime on Enterprise
Keep reading
EnterpriseScale, governance and deployment.Data EnginePipelines, checkpoints and audit trails.Financial ServicesReporting your risk team will sign off on.