Compliance frameworks, security audits, and quality certifications this company maintains.
Retool maintains SOC 2 Type II certification, demonstrating that its internal tooling platform meets rigorous security, availability, and confidentiality controls required by enterprise customers connecting sensitive production databases and APIs.
Retool is GDPR compliant, providing data processing agreements and controls that allow European enterprise customers to build internal tools handling personal data of EU residents without violating data protection regulations.
Retool complies with the California Consumer Privacy Act, giving California-based enterprise customers the contractual and technical controls needed to manage personal data within internal tools built on the platform.
Retool supports HIPAA-compliant deployments through Business Associate Agreements, enabling healthcare customers to build internal tools that access and display protected health information without violating federal patient data regulations.
Retool holds ISO 27001 certification, validating its information security management system and providing enterprise customers with an internationally recognized assurance that their data and credentials stored in the platform are protected.
Security
Penetration Testing
CompliantRetool undergoes annual third-party penetration testing of its platform infrastructure and application layer, with findings reviewed and remediated before reports are made available to enterprise customers under NDA.
Retool's app builder interface and generated internal applications conform to WCAG 2.1 AA accessibility standards, ensuring that enterprise customers can build tools accessible to employees with disabilities.
Retool participates in the Cloud Security Alliance STAR program, publishing its security controls self-assessment to give enterprise customers transparency into how their data and database credentials are protected in a cloud-hosted environment.
Retool supports SAML 2.0 single sign-on with identity providers including Okta, Azure AD, and Google Workspace, enabling enterprise customers to enforce centralized authentication policies across all internal tools built on the platform.
Security
Role-Based Access Control
CompliantRetool implements granular role-based access control at the app, query, and resource level, allowing enterprise customers to restrict which teams and users can view, edit, or execute sensitive internal tools and database queries.