Skip to main content
Cargo is built with security at its core. We understand that you’re trusting us with sensitive business data, and we take that responsibility seriously.

Infrastructure security

FeatureDescription
Cloud hostingCargo runs on enterprise-grade cloud infrastructure with 99.9% uptime SLA, automatic failover, and geo-redundant backups.
Network isolationAll services are designed to run in isolated virtual private clouds, with strict network policies and firewall rules.

Data protection

Encryption

All data is encrypted both in transit and at rest:
LayerProtection
In transitTLS 1.3 encryption for all API and web traffic
At restAES-256 encryption for all stored data
DatabaseEncrypted storage with customer-isolated data partitions
BackupsEncrypted backups with point-in-time recovery

Data handling

1

Minimal data retention

Cargo only stores data necessary to run your workflows. Intermediate processing data is automatically purged after execution.
2

Customer isolation

Each workspace’s data is logically isolated. Strict access controls ensure no cross-tenant data access.
3

Secure deletion

When you delete data or close your account, we permanently remove all associated data from our systems.

Access control

Authentication

  • Single Sign-On (SSO): Connect your identity provider for centralized authentication
  • Multi-factor authentication (MFA): Add an extra layer of security to user accounts
  • API keys: Scoped, rotatable keys for programmatic access with granular permissions

Permissions

Cargo provides role-based access control (RBAC) to manage what users can do within your workspace:
RoleCapabilities
AdminFull access to all settings, integrations, and user management
EditorCreate and modify tools, agents, plays, and data models
ViewerRead-only access to view workflows and results

Compliance

CertificationDescription
SOC 2 Type IICargo maintains SOC 2 Type II certification, demonstrating our commitment to security, availability, and confidentiality.
GDPR-alignedWe align with GDPR requirements and provide Data Processing Agreements (DPA) as well as support data subject access requests. Note: Cargo does not hold formal GDPR certification.

Data residency

Cargo supports data residency requirements for customers with specific regional data storage needs. Contact us to discuss your requirements.

Integration security

Warehouse connections

When connecting to your data warehouse (Snowflake, BigQuery, Redshift), Cargo:
  • Uses read-only credentials where possible
  • Connects via secure, encrypted channels
  • Never stores raw credentials — they’re encrypted and isolated in secure vaults

CRM and third-party integrations

All OAuth connections follow best practices:
  • Minimal permission scopes requested
  • Tokens securely stored and automatically refreshed
  • Connections can be revoked at any time from your workspace

Monitoring and incident response

FeatureDescription
24/7 monitoringAutomated systems continuously monitor for security threats and anomalies.
Incident responseDocumented incident response procedures with defined SLAs for communication and resolution.

Reporting vulnerabilities

If you discover a security vulnerability, please report it responsibly by emailing [email protected]. We appreciate your help in keeping Cargo secure and will acknowledge your report within 24 hours.

Questions?

For security-related inquiries or to request our SOC 2 report, contact us at [email protected].