Compliance frameworks, security audits, and quality certifications this company maintains.
dbt Labs maintains SOC 2 Type II certification for dbt Cloud, demonstrating that its managed analytics engineering platform meets rigorous security, availability, and confidentiality controls required by the enterprises and financial services firms that run production data pipelines through the platform.
dbt Labs holds ISO 27001 certification, providing enterprise customers with internationally recognized assurance that the information security management system protecting dbt Cloud production environments and customer data pipeline credentials meets global standards.
dbt Labs is GDPR compliant, offering data processing agreements and EU data residency options for dbt Cloud enterprise customers whose analytics pipelines process personal data of EU residents stored in connected cloud data warehouses.
dbt Labs complies with the California Consumer Privacy Act, providing enterprise customers with the contractual and technical controls needed to operate dbt Cloud in environments where analytics pipelines process data about California residents.
dbt Labs supports HIPAA-compliant dbt Cloud deployments through Business Associate Agreements, enabling healthcare analytics teams to build data transformation pipelines that process protected health information from clinical and claims data sources.
Security
Penetration Testing
Compliantdbt Labs undergoes annual third-party penetration testing of the dbt Cloud platform, IDE, and API surfaces, with findings reviewed and remediated before reports are made available to enterprise customers under NDA during security due diligence.
dbt Cloud supports SAML 2.0 single sign-on with Okta, Azure Active Directory, and Google Workspace, enabling enterprise customers to enforce centralized authentication and user provisioning policies across all dbt Cloud developer accounts.
Security
Role-Based Access Control
Compliantdbt Cloud implements role-based access control at the project, environment, and job level, allowing enterprise customers to restrict which analytics engineers can develop, deploy, and monitor production dbt pipelines and warehouse credentials.
dbt Labs participates in the Cloud Security Alliance STAR Level 1 program, publishing its security self-assessment for dbt Cloud so enterprise IT and procurement teams can review cloud security controls during vendor evaluation.
dbt Labs is pursuing FedRAMP Moderate authorization for dbt Cloud to enable US federal government agencies and regulated public sector organizations to run analytics engineering pipelines in a FedRAMP-compliant cloud environment.