Data Sovereignty

Data ownership used to be a checkbox. Now it's the starting point. Your data, your infrastructure, your models, all under your control.

Sovereignty, ownership, control, self-hosted - whatever you call it, this is how you get there. Run Metabase on your own network, no data leaves, and nothing (person, agent, model, or mineral) touches your data without your say so. Remove third-parties from the conversation, reduce your exposure and your risk.

Metabase logo with a shield to signify maximum security and control over your data

Who data sovereignty is for

Regulated industries

Healthcare, banking, finance, government and defense - or anywhere where compliance is non-negotiable. Whether it's HIPAA, BAA, ISO 27001, SOC2 or another official acronym — anywhere a formal security review gates the deal.

Security conscious

You take privacy seriously, regardless of what's strictly required. Control over your data and AI is simply how you operate.

Metabase is trusted by 100,000+ companies

huggingface logomcdonalds logohuma logocapital-one logoJLL logolinear logoDeutsche Telekom logokong logo

Self-hosted

  • Everything stays on your servers.
  • The default for regulated industries: HIPAA, SOC 2 Type II, GDPR, data residency laws.
  • However it gets phrased internally, "we can't have data leaving our network" is usually the plain-English version of what's actually required.

Air-gapped

  • Full network isolation, zero internet connection.
  • For orgs with the strictest policies and security reviews.
  • Go further with air-gapping Metabase.

Your data never leaves your network

We perform in-database analytics. Metabase queries are sent to your database, results are sent back — nothing is extracted, and nothing is ever stored by Metabase. The query runs where your data already lives.

  • Self-host, region-agnostic, isolated deployments — your data never has to leave servers you control. Air-gap for full network isolation, or stay off the public internet behind your own VPN.'
  • Setup is low-effort — deploying under these constraints is basically the same lift as any other Metabase deployment, not a specialist project.
  • Open source and portable. The codebase is auditable and forkable. You're not locked in any more than you choose to be.
Illustration of the Metabase logo at the centre of a number of compliance badges

AI, without giving up control

AI analytics doesn't require compromising on security, privacy, or control.

  • Bring your own model, including open-weights options. You can host it yourself. No data has to go to a third-party model provider unless you choose to send it there.
  • Isolated workspaces (coming soon) let agents work autonomously against your production warehouse without running amok — sandboxed, with changes reviewed before they touch production.
  • Every prompt is exposure too. When you send a request to a hosted LLM, it's not just your underlying data the model sees — it's the prompt itself, logged and retained on that provider's terms, not yours.
“We operate a number of private data centres for our systems, and an air-gapped version of Metabase allows us to reduce the attack surface for cyber security reasons.
Let alone the potential impact of a cyber attack on system uptime, being a heavily regulated company, being air-gapped further reduces the risk of data breaches and sensitive and private data loss.
It also optimizes and maximizes operational availability as the system is network failure resilient.”
Frédéric Tremblay

Head of Business Intelligence, LMAX Group

A control plane you can audit

The governance and permission model you need for regulated industries and compliance — with or without AI.

  • End-to-end lineage, from transforms all the way through to dashboards, plus audit logs to see who — or what — did what, and when.
  • AI governance — restrict access, set token limits, and control system prompts.
  • SSO and permission grouping, mapped to how your org is actually structured.
  • Row- and column-level security, plus database-level routing and connection impersonation.
Illustration of the Metabase logo at the centre of a number of compliance badges

Frequently asked questions

What does "data sovereignty" actually mean, and how is it different from data residency?
Data residency is about where your data physically sits at rest. Data sovereignty is broader — it's about who controls your data and infrastructure, and under whose legal jurisdiction, including the models that touch it. (A related term, digital sovereignty, goes further still — control over the entire digital stack, not just data.) In practice, most teams mean some combination of all three.
What kind of orgs is data sovereignty most important for?
Healthcare (HIPAA/BAA), banking and fintech, government and defense, and anyone operating under GDPR or a similar regional data law. If your security team runs a formal review before approving new infrastructure, this is probably relevant to you.
Is Metabase HIPAA compliant? What about SOC 2 or GDPR?
Yes — Metabase's SOC 2 Type II report covers the controls behind our security program, we sign BAAs for HIPAA-covered workloads, and self-hosting gives you the infrastructure control most GDPR reviews are actually asking about. See our compliance certifications for the specifics.
How is this different from governance in Databricks or Snowflake?
Databricks and Snowflake are strong on ingestion, modeling, and access control — but analytics and governed BI aren't their core strength, and both come with real lock-in (opaque consumption pricing, a warehouse you're tied to). Metabase runs governance, permissions, and BI on top of whatever you're already using, self-hosted if you choose, open source so you're never locked in.
Can we run Metabase with zero internet connection at all?
Yes — see air-gapping Metabase for a fully isolated deployment.
Can we bring our own AI model instead of using a hosted provider?
Yes, including open-weights models through providers like Bedrock or OpenRouter. Talk to our team about your specific setup.
What happens when a new version ships — are we on our own to keep it updated?
You'll need to backup and upgrade to stay on the most current version. Enterprise self-hosting comes with a named success engineer who can help if you need it.
How long does a security review usually take?
It depends on your organization, but self-hosted deployments make it easier to move fast — you can install Metabase in your own environment and let your security team evaluate it directly, rather than waiting on a vendor's shared infrastructure. Security documentation and compliance certifications are available to speed that up.