1 min read
‧ 1 min read
Update: Metabase is now SOC Type 2 compliant!
Metabase has always cared about data privacy.
When we originally designed Metabase, we took great care to never see anyone’s data. We took the same privacy-first approach when developing Metabase Cloud, and we’re now proud to say our efforts have been validated by third-party auditors.
Today we’re announcing that Metabase is now SOC 2 Type 1 compliant.
SOC 2 (System and Organization Controls) compliance is an industry-standard way for companies to show that their controls and processes around access to systems and data follow a high standard. SOC 2 compliance requires independent verification by a Certified Public Accounting (CPA) firm. You can learn more about the standard in this comprehensive article.
Update: Metabase is now SOC Type 2 compliant!
The next step is to secure our SOC 2 Type 2 compliance. Type 1 is the first step: verifying that the controls are in place. Type 2 is to verify (again, by an independent audit) that we’re maintaining these controls over time.
Meanwhile, we’ll continue to improve the security of both our application, Metabase, and our hosting services, Metabase Cloud.