We're evaluating embedded analytics for our B2B SaaS product. Current user base is under 100, but contractually obligated to provide data isolation and audit trails per customer. My primary concern is vendor risk and compliance, not fancy visualizations.
Key non-negotiable requirements:
* Must support true tenant-level data isolation (row-level security isn't a suggestion, it's the spec).
* API-driven embedding with robust session control (no iframe auth leaks).
* Audit logs for user query access must be exportable to our SIEM.
* The vendor must have a current SOC 2 Type II report (ISO 27001 is a plus).
* Data in transit *and* at rest encryption must be customer-managed key capable.
Platforms I've already ruled out:
* **Tableau Embedded:** Licensing is a maze, and their audit log API is insufficient for our needs.
* **Power BI Embedded:** Microsoft's compliance is solid, but the Azure tenant management overhead for under 100 users is disproportionate.
* **Looker (Google Cloud):** While technically capable, the operational cost and complexity for our scale is unjustifiable.
The shortlist I'm reviewing is Metabase (self-hosted OSS version) and GoodData. I need peer review on the operational security and compliance gaps you've encountered.
Specifically:
* For Metabase, what's the real-world burden of maintaining compliance evidence (user access reviews, patch management) on a self-hosted setup?
* For GoodData, does their managed service's SOC 2 report adequately cover the embedded analytics use case, or are there typical carve-outs?
* Are there any other platforms with a clear, no-nonsense security posture for a sub-100 user embedded scenario?
Where is your SOC 2?