---
title: "Control access to your systems and data | Rig"
description: "Role and row-level access, an audit trail and SOC 2 Type 2 cover people, reports and agents. Run Rig on your own warehouse, hosted in the EU or US, in a private cloud or on-premise."
canonical: "https://rig.so/security"
format: markdown
---

Security

# Control access to your systems and data

Role and row-level access, an audit trail and SOC 2 Type 2 cover people, reports and agents. Run Rig on your own warehouse, hosted in the EU or US, in a private cloud or on-premise.

[Talk to an engineer](https://rig.so/book-demo)

Your systems, in viewShared data and definitions

**Salesforce**Customers & revenue

N

**NetSuite**Finance & orders

S

**Shopify**Commerce

❄

**Snowflake**Your warehouse

Systems Map

Context & definitions

ReportsWorkflowsAgents

Dependencies for one field

The reports, flows and teams that use it.

Impact mapped

Illustrative platform viewIngest → Rig Map → Migrate → Run

## Govern who can see what

Role-based and row-level access protect sensitive numbers. Governed definitions and an audit trail make the source and use of your data easier to follow.

## Choose where your data lives

Use your own warehouse or choose EU or US hosting, private cloud or on-premise deployment. Agree residency and deployment requirements with our engineers before connecting systems.

## Review the evidence

Ask our team for the SOC 2 Type 2 report, current security documentation and sub-processor details as part of your systems review.

## Security documentation, in one place

Review our controls and the providers that support the platform.

[Open the trust centre](https://trust.rig.so)

View sub-processors

| Provider | Purpose | Region |
| --- | --- | --- |
| MotherDuck | Isolated per-tenant data warehouses for Rig-hosted customers. Not engaged where you connect your own warehouse | US (default), EU for enterprise or custom deployments |
| Amazon Web Services (AWS) | Application hosting, context cache and secrets management | EU / US |
| Supabase | User accounts and conversation cache | EU |
| Langfuse | LLM traces and reasoning logs | EU |
| Sentry | Error monitoring | EU |
| PostHog | Product analytics (team emails and user IDs) | EU |
| Nango | Authentication and API calls for permitted integrations | US |
| OpenAI, LLC | LLM inference, for Rig-hosted LLM key customers only. Provisioned per tenant with zero data retention enabled | US |

## Common questions

How does data move into Rig?

Rig syncs connected systems on a schedule into one governed space, or works on your existing warehouse. Agree the refresh schedule for your use case with our engineers.

Do we keep our integration tool?

Yes. For a record that must move the moment something happens, keep your integration tool. Rig gives reports and agents access to data from several systems. Rig Map can show those integration flows too.

Can we use our own warehouse?

Yes. Bring Snowflake, BigQuery or Postgres, or use a Rig-hosted warehouse. We agree the hosting and access model with your team.

SOC 2 Type 2EU and US hostingRole-based accessYour warehouse or ours

Talk to Rig

## What work do you want to improve?

Tell us where your team spends time, loses money or needs better information.
In a 30-minute call, we’ll discuss the data and systems work that could help.

[Talk to an engineer](https://rig.so/book-demo)Use the platform with your team, or add our engineers.

---

- [This page as HTML](https://rig.so/security)
- [Site map for language models](https://rig.so/llms.txt)
- [API and agent documentation](https://rig.so/developers)
