Third Party Index

Snapshot 58651

Document
Security page
URL
https://embeddable.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
63384 bytes
SHA-256 (raw)
28758674c8e18939f3f91cfb2c70d65ef8f0c134987e8e933e2bdb0f080a067c
SHA-256 (normalized text)
15631153aa0c7c76301f78254e2dd121ca8d7f04b307c451f39ad15dfd964da6

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to main content
Winner of the Embedded Analytics Solution of the Year at the Data Breakthrough Awards 2026
Security
Embeddable is a modern data platform that uses a secure connection to query your database directly. Embeddable does not store a copy of your database - your data stays safely and securely in your own database.
Certifications: Embeddable is SOC 2 Type II certified. Our SOC 2 report and independent penetration-test reports are available via trust.embeddable.com.
GDPR Compliance: Embeddable is fully GDPR compliant.
Hosting: Embeddable's production infrastructure runs on AWS. You can choose between EU hosting (Frankfurt, with a disaster-recovery site in Ireland) and US hosting (US East, with a disaster-recovery site in US West).
Data Storage: Embeddable does not copy your database - it runs live queries, with results caching and fine-grained control.
Read-Only Access: You connect Embeddable using a read-only database account, so read-only access is enforced by your own database - Embeddable never writes to or alters your data.
Credential Encryption: Database and SSH credentials are encrypted with AES-256-GCM, and connection management is restricted by workspace permissions. Credentials can be replaced and API keys regenerated at any time.
In-Transit Security: Both queries and results traverse TLS 1.2+ to guard against eavesdropping and MITM attacks.
Tenant Isolation: Workspace access controls keep each customer's data logically separated. Within your application, security contexts and row-level security filters control exactly what each of your users can see.
Token Security: Dashboards are embedded using signed tokens. Every request is validated for signature, expiry and permissions, and you control each token's lifetime and the security context it carries.
Single Sign-On: Workspace authentication can be delegated to your identity provider (e.g. Okta via SAML), so your own MFA and access policies apply to your Embeddable administrators.
Deployment Options:
Managed Cube: Cloud-hosted, minimal infra on your end, optional cache (this is used by 90%+ of customers). You can choose between our EU and US hosting options.
Self-Hosted Cube: You can run Cube Core in your environment for full control over data and cache, or connect directly to Cube Cloud.
Cube Cloud: You can also connect directly to your own Cube Cloud service.
Cache Options:
Basic cache: In-memory cache speeds up performance and protects your database from too much load.
Pre-aggregations: Optional pre-aggregations for enhanced performance and scalability, with granular control. They can remain disabled (the default) while in-memory caching continues to operate.
Cache isolation: Cache entries are keyed by workspace and security context, so results generated for one tenant are never served to another. Cached results are streamed straight to the user - they are never written to logs or monitoring systems.
Backups: Platform data is backed up daily.
Personnel Access: Embeddable personnel access to customer environments follows the principle of least privilege - it is restricted by default, attributable to a named engineer, and reviewed quarterly.
Logging: We maintain an extensive, centralised logging environment in our production environment which contains information pertaining to security, monitoring, availability, access, and other metrics about the Embeddable services.