Snapshot 58651
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to main content Winner of the Embedded Analytics Solution of the Year at the Data Breakthrough Awards 2026 Security Embeddable is a modern data platform that uses a secure connection to query your database directly. Embeddable does not store a copy of your database - your data stays safely and securely in your own database. Certifications: Embeddable is SOC 2 Type II certified. Our SOC 2 report and independent penetration-test reports are available via trust.embeddable.com. GDPR Compliance: Embeddable is fully GDPR compliant. Hosting: Embeddable's production infrastructure runs on AWS. You can choose between EU hosting (Frankfurt, with a disaster-recovery site in Ireland) and US hosting (US East, with a disaster-recovery site in US West). Data Storage: Embeddable does not copy your database - it runs live queries, with results caching and fine-grained control. Read-Only Access: You connect Embeddable using a read-only database account, so read-only access is enforced by your own database - Embeddable never writes to or alters your data. Credential Encryption: Database and SSH credentials are encrypted with AES-256-GCM, and connection management is restricted by workspace permissions. Credentials can be replaced and API keys regenerated at any time. In-Transit Security: Both queries and results traverse TLS 1.2+ to guard against eavesdropping and MITM attacks. Tenant Isolation: Workspace access controls keep each customer's data logically separated. Within your application, security contexts and row-level security filters control exactly what each of your users can see. Token Security: Dashboards are embedded using signed tokens. Every request is validated for signature, expiry and permissions, and you control each token's lifetime and the security context it carries. Single Sign-On: Workspace authentication can be delegated to your identity provider (e.g. Okta via SAML), so your own MFA and access policies apply to your Embeddable administrators. Deployment Options: Managed Cube: Cloud-hosted, minimal infra on your end, optional cache (this is used by 90%+ of customers). You can choose between our EU and US hosting options. Self-Hosted Cube: You can run Cube Core in your environment for full control over data and cache, or connect directly to Cube Cloud. Cube Cloud: You can also connect directly to your own Cube Cloud service. Cache Options: Basic cache: In-memory cache speeds up performance and protects your database from too much load. Pre-aggregations: Optional pre-aggregations for enhanced performance and scalability, with granular control. They can remain disabled (the default) while in-memory caching continues to operate. Cache isolation: Cache entries are keyed by workspace and security context, so results generated for one tenant are never served to another. Cached results are streamed straight to the user - they are never written to logs or monitoring systems. Backups: Platform data is backed up daily. Personnel Access: Embeddable personnel access to customer environments follows the principle of least privilege - it is restricted by default, attributable to a named engineer, and reviewed quarterly. Logging: We maintain an extensive, centralised logging environment in our production environment which contains information pertaining to security, monitoring, availability, access, and other metrics about the Embeddable services.