Solutions / Data security

Reference data that meets your governance bar.

Row-level security, granular access, SSO and an audit trail, so only the right people see and change sensitive mappings, and you can show who did what.

Row-level security

Filter rows by who's asking

Derive each user's access from a control registry, by division, location or any other column. One dataset, scoped per person.

Access audit

See every permission at once

One view of who can access which project, gridmap and registry, and whether that access is direct or inherited.

Row-level security

Permissions that manage themselves

Point gridmap at a control registry (a table of users and the values they may see) and each person's row access is derived from it, by division, location or any other column. Sync it from your data warehouse on a schedule and access stays current as your team changes. One dataset, scoped per person, instead of duplicate "filtered" copies.

UserDivisionLocation
finance@acme.co Finance Falun
ops@acme.co All Stockholm
admin@acme.co All All
The hidden risk

Your most sensitive business rules are probably uncontrolled

Access is broad by default

With shared drives and folders, it is hard to limit who sees finance codes, customer segments, and pricing rules.

Change tracking is limited

Knowing who changed reference data, when, and what the previous value was is difficult, especially during an audit.

Permissions are manual to manage

Granting and revoking access through folders is time-consuming and hard to keep consistent as teams change.

Credentials need careful handling

Database connection details are sensitive. A dedicated platform stores them encrypted and manages access centrally.

Built-in security

Security that works automatically

Row-level security

Users see only the rows they are allowed to see. gridmap enforces it on the server, not with spreadsheet tabs.

Automatic permissions from user tables

Sync your access table from Snowflake, SQL Server, Microsoft Fabric or another supported database. Permissions update with every scheduled sync.

User groups & roles

Organize users into groups with defined permissions. Add someone to a group once and they get everything the group can access.

Audit logging

Who opened what, who changed which value, who granted access. Searchable, and exportable to CSV.

Encrypted connections

Credentials are encrypted at rest with Fernet. Connections use TLS by default.

SSO & MFA

Single sign-on with Microsoft Entra ID or Google. MFA is required for admins and available to everyone.

SSOGroupsGranular permissionsAudit trail
Enterprise

Bring your own database

On the Enterprise plan, gridmap stores your data in your own PostgreSQL database: self-hosted PostgreSQL, Azure Database for PostgreSQL, Amazon RDS or Aurora PostgreSQL, or Google Cloud SQL for PostgreSQL.

Stored in your database

gridmap values, registry rows, their change history and audit trail, comments, value lists and uploaded import files.

Kept by gridmap

Configuration only: users, projects, the structure of your gridmaps and registries, access rules, schedules and connection settings.

An admin sets it up under Targets. gridmap needs a database user that can write to one schema, and admins get step-by-step grant scripts. If you use AI mapping, the values being mapped are still sent to the AI provider.

The value

Enterprise security, built in from the start

Per-row
access control, not per file or per folder
Automatic
permissions synced from your data warehouse on a schedule
Always on
audit trail from day one, with no setup
Common questions

Frequently asked questions

What is row-level security and how does it work in gridmap? ⌄

Row-level security means each user sees only the rows in a registry that they are allowed to see, even when several teams share the same registry. For example, the finance team sees cost center codes while operations sees product codes. gridmap applies the filter on the server, so there is no need for separate files or spreadsheet tabs. Once it is set up, it works on its own.

How do we control who can edit our mapping data? ⌄

gridmap uses role-based access control with user groups. You add users to groups (for example "Finance editors" or "Operations viewers") and grant read, write or admin access per project, gridmap or registry, with row-level rules on top. Changes take effect immediately. You can also sync row permissions from a user table in your data warehouse.

What does the audit log capture? ⌄

The activity log records who opened a gridmap or registry, who changed which value, who imported or synced data, who granted or revoked access, and when. Edits keep both the previous value and the new value. You can filter and search the log, and export it to CSV for compliance reviews.

How are database credentials stored? ⌄

Database connection credentials are encrypted with Fernet symmetric encryption before they are stored. Connections to your databases use TLS by default.

Do you support Microsoft Entra ID (Azure AD) SSO? ⌄

Yes. gridmap supports single sign-on with Microsoft Entra ID and Google on the Professional and Enterprise plans. People from your allowed email domains can get an account on their first sign-in, with or without admin approval. Multi-factor authentication (authenticator app or passkey) is required for admins and available to every user.

How does automatic permission management from a user table work? ⌄

You sync a control registry from a table of emails and permission values in any supported database. gridmap uses that registry to decide which rows each person sees, and someone with several rows gets access to all of their values. Sync it on a schedule and access keeps up as your team changes.

Is gridmap GDPR compliant? ⌄

gridmap runs on Microsoft Azure in the Sweden Central region, and data at rest is encrypted. Access is logged, and row-level security limits data to the people allowed to see it. On the Enterprise plan your data can stay in your own PostgreSQL database. If you use AI mapping, the values being mapped are sent to the AI provider. For specific compliance requirements, contact us for details on our data processing agreements.

Can we keep our data in our own database? ⌄

Yes, on the Enterprise plan. gridmap stores your data in your own PostgreSQL database: self-hosted PostgreSQL, Azure Database for PostgreSQL, Amazon RDS or Aurora PostgreSQL, or Google Cloud SQL for PostgreSQL. Your database holds gridmap values, registry rows, their change history and audit trail, comments, value lists and uploaded import files. gridmap keeps only configuration: users, projects, the structure of your gridmaps and registries, access rules, schedules and connection settings. An admin sets it up under Targets. gridmap needs a database user that can write to one schema, and admins get step-by-step grant scripts. If you use AI mapping, the values being mapped are still sent to the AI provider.

Secure your reference data.

gridmap is live. Ask for a free license that never expires, or talk to us about a paid plan.

We set up every account ourselves and reply by email. No newsletters.
See pricing →