True cloud-native spatial analytics, built for the Enterprise
Deployment options, connections, and data access policies designed for ultimate security and control.
Trusted by world’s leading brands
Data always remains where it belongs - in your data warehouse
CARTO offers a truly cloud-native solution; you do not need to worry about syncing your data elsewhere. Extend the geospatial capabilities of your data warehouse, without compromising on data security and governance.
Deploy CARTO in your own cloud
With our Self-hosted deployment you can host and operate CARTO your way, with ultimate control
Options for both Single VM and Orchestrated containers.
Streamlined installation, with fully self-service or assisted options.
Support for deploying inside your VPC or behind your VPN, and with proxy configurations.
Standardized releases. Regular updates to ensure stability across all environments.
Frequently asked questions
No, CARTO does not make any copies of the data available through your Connections.
CARTO is cloud-native by design, and we never need to replicate your data. Maps, Workflows, and Applications built with CARTO will launch queries against live data in your own data warehouse (BigQuery, Snowflake, Redshift, Databricks, PostgreSQL, etc) and the result of these queries is not stored for further uses. This applies to all kinds of deployments.
Yes. Because connections in CARTO always send live queries back to your data warehouse, we always respect the permissions and controls in your organization, including advanced scenarios such as row-level security or role-based access control.
Moreover, connections in CARTO can be set up using OAuth-based mechanisms, with additional strict configurations such as viewer credentials, where every user needs to provide their own identity and credentials in order to access the data.
Yes! On top of the OAuth-based mechanisms, CARTO also supports mechanisms such as Service Accounts or Workload Identity where you can granularly generate connections with limited permissions on specific resources in your data warehouse, following least-privilege best practices.
Yes. CARTO can be deployed in your own network with our Self-Hosted deployment. This deployment can be restricted using a proxy or VPC controls. Connections to the data warehouse can be set up using Private Link.
CARTO supports seamless integration with your SSO (using SAML, OIDC or other protocols) including smooth user provisioning, and can also synchronize groups coming from your Identity Provider. Additionally, groups can be mapped to roles in CARTO. Roles in CARTO go from viewer, that can only consume pre-created assets; to admins, who can configure and monitor the CARTO organization.
CARTO’s latest SOC 2 Type II report is available upon request for customers and prospects. Please note that prospects must have signed an NDA (Non-disclosure agreement) with CARTO before receiving the SOC 2 Type II report.
Visit our Trust and Security center to request the latest report as well as other resources. In our Trust and Security you will also find additional information about our infrastructure security, internal procedures, and data privacy management.