Infrastructure security
Data protection
Encryption
All data is encrypted both in transit and at rest:Data handling
1
Minimal data retention
Cargo only stores data necessary to run your workflows. Intermediate
processing data is automatically purged after execution.
2
Customer isolation
Each workspace’s data is logically isolated. Strict access controls ensure
no cross-tenant data access.
3
Secure deletion
When you delete data or close your account, we permanently remove all
associated data from our systems.
Access control
Authentication
- Single Sign-On (SSO): Connect your identity provider for centralized authentication
- Multi-factor authentication (MFA): Add an extra layer of security to user accounts
- API keys: Scoped, rotatable keys for programmatic access with granular permissions
Permissions
Cargo provides role-based access control (RBAC) to manage what users can do within your workspace:Compliance
Data residency
Cargo supports data residency requirements for customers with specific regional data storage needs. Contact us to discuss your requirements.Integration security
Warehouse connections
When connecting to your data warehouse (Snowflake, BigQuery), Cargo:- Uses read-only credentials where possible
- Connects via secure, encrypted channels
- Never stores raw credentials — they’re encrypted and isolated in secure vaults
CRM and third-party integrations
All OAuth connections follow best practices:- Minimal permission scopes requested
- Tokens securely stored and automatically refreshed
- Connections can be revoked at any time from your workspace

