Source
Security / trust page — GrowthBook
Checked for GrowthBook on 30 Sep 2026
- Page
- https://www.growthbook.io/platform/security
- Checked
- 30 Sep 2026, 13:11 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:bf97d6f0bde52923b41f05f0607b41344bae5cf7250da58040b1007d1b95bb0f
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
SOC 2 Report an error
“GrowthBook is SOC 2 Type II certified and compliant with GDPR, COPPA, and CCPA.”
-
Encryption Report an error
“Data is encrypted at rest and in transit.”
-
Warehouse native privacy Report an error
“Total data privacy: no PII ever leaves your data warehouse; only aggregate data is accessed.”
-
Governance Report an error
“Enterprise governance features: SSO/SAML, fine-grained permissions, role-based access, and audit trails.”
-
Self hosted air gapped Report an error
“Self-hosted and air-gapped: deployment options available for complete control of your infrastructure.”
-
Cloud updates Report an error
“Automatic updates and security patches”
-
Cloud provider Report an error
“Hosted by GrowthBook on AWS”
-
Uptime SLA Report an error
“99.99% uptime SLA (Enterprise)”
-
Self hosted HIPAA Report an error
“Full control of updates, scaling, and infrastructure No data or PII leaves your system, HIPAA compliant”
-
Self hosted deployment Report an error
“Deploy air-gapped on all major clouds or on-prem Single service deployed with Kubernetes or any container platform”
-
Managed warehouse Report an error
“Event data is securely stored on ClickHouse infrastructure, SOC 2 Type II certified, and data encrypted at rest and in transit.”
-
Open source Report an error
“Our code is open and regularly reviewed for security vulnerabilities. We use both static analysis and regular security reviews and testing.”
-
Appsec practices Report an error
“GrowthBook does mandatory code reviews for every PR, security reviews, and routine penetration testing.”
-
Vulnerability disclosure Report an error
“If you discover a security vulnerability, please disclose it to us responsibly.”
Scores citing this record
- The CRO Consultant Statistical method & guardrails
- The CRO Consultant Analytics, data export & integrations
- The CRO Consultant European sovereignty
- The Data Protection Officer Analytics, data export & integrations
- The Data Protection Officer European sovereignty
- The E-Commerce Manager Analytics, data export & integrations
- The E-Commerce Manager European sovereignty
- The Growth Lead Snippet performance & flicker
- The Growth Lead Analytics, data export & integrations
- The Growth Lead European sovereignty
- The Product Engineer Snippet performance & flicker
- The Product Engineer Analytics, data export & integrations
- The Product Engineer European sovereignty
- The Skeptic Analytics, data export & integrations
- The Skeptic European sovereignty