Alteryx Trust Center

Alteryx Trust Center

Search the Trust Center...
Ctrl +K

Alteryx Trust Center | Security, Privacy, and Compliance

The Alteryx Trust Center gives you one centralized place to complete your security review with confidence. Explore up-to-date security documentation, certifications, compliance details, audit reports, and subprocessor disclosures designed to support a faster, more transparent review process.

🔒 Need access to secure content?

Click Get Access in the top right corner to request access to restricted Trust Center documents.


Security at Alteryx

Trust is at the center of how we design, deliver, and support our products.

At Alteryx, security is more than a requirement. It is a shared responsibility across our people, processes, and technology. Our security program is designed to support transparency, strengthen customer confidence, and help organizations evaluate Alteryx with clarity.

We maintain security practices, governance processes, and compliance resources that reflect our commitment to earning and preserving customer trust.

Bulletin Board

👋 New here? Start with this quick Trust Center guide.


Certifications and Reports

CSA STAR 1
CSA STAR 1

Featured Documents


Quick Summary

One or more annual third-party audit(s)

Has a formal mobile device management (MDM) program

Annual third-party penetration testing

Has a disaster recovery plan

Has cyber insurance

Deletes customer data on request

Has an API available

Uses a centralized IAM solution (SSO) to manage employee access


Documents & Knowledge Base FAQs


More from Alteryx

Gainsight Response

Gainsight / Salesforce Security Incident Update

At Alteryx, we take the security of our customers and their data seriously. Our mission is to deliver trusted analytics solutions, and part of that commitment is keeping customers informed about security incidents that customers may be monitoring for potential impacts to their organization.

What Happened?

Alteryx was notified by Salesforce and Gainsight on November 21, 2025, of a security incident involving the Gainsight connected application. This incident is linked to the same threat actors behind the previously disclosed Drift/Salesloft compromise, in which stolen OAuth credentials were used to access certain Salesforce customer environments.

Upon receiving Gainsight's notice, Alteryx promptly initiated an investigation with our Security Operations Center and Salesforce teams. Our review identified a small volume of unauthorized activity involving the Gainsight integration account on October 23, 2025. Salesforce confirmed that three queries were executed during this event, all of which were limited in scope and returned only minimal, non-sensitive internal information. We found no signs of large-scale queries, data exports, or any follow-up activity beyond the single event on October 23. There was no indication that customer data was accessed.

Next Steps

Alteryx will continue working with Salesforce and Gainsight to ensure the security of our integrations and to strengthen monitoring around third-party applications. Although this incident resulted in minimal impact, as summarized above, we are enhancing our controls to further reduce exposure to similar risks in the future. If any new information were to indicate unauthorized access to customer-related data, we will notify affected customers in accordance with our contractual and regulatory obligations.

What You Can Do

We encourage customers to remain cautious of unusual or unexpected communications that appear to come from Alteryx, especially those requesting payment or changes to payment instructions.

If you have additional questions about this incident, please contact us at security-notifications@alteryx.com or reach out to your Alteryx Account Representative.


New SOC2 Report

🔒 New SOC 2 Type II Report Now Available

We’re pleased to announce that the latest Alteryx SOC 2 Type II Report is now available through the Alteryx Trust Center.

This report demonstrates our ongoing commitment to maintaining robust security controls, operational excellence, and transparency for our customers.

👉 Access the SOC 2 Type II Report

Thank you for your continued trust in Alteryx.


Salesloft Drift Response

Salesforce-Connected Third-Party Drift Application Supply Chain Incident Response

At Alteryx, we take the security of our customers and their data seriously. Our mission is to deliver trusted analytics solutions, and part of that commitment is keeping customers informed about security incidents that could impact their organization.

What Happened?

Alteryx was notified by Salesforce on August 22, 2025, of a security incident involving a third-party application, Drift (A Salesloft Product). The incident involved a threat actor using the Drift application’s integration with Salesforce to attempt to access customer CRM instances. However, the connection between Drift and Salesforce had already been terminated by Salesloft on August 20th as part of its response to the incident. This connection will remain disabled until the completion of our investigation, or until adequate assurances of security and safety have been provided by Salesloft and/or Salesforce.

Upon notice, Alteryx promptly began a detailed investigation with our Security Operations Center and Salesforce teams and confirmed unauthorized access to Alteryx’s Salesforce environment on or about August 13, 2025. A detailed analysis confirmed that Alteryx’s exposure was limited to a small sample of our Salesforce records and did not result in any confirmed loss of customer sensitive or confidential information. While the threat actor’s focus appeared to be on obtaining sensitive information, such as cloud access keys, credentials, and other secrets stored in case data, Alteryx’s sensitive information and that of its customers does not appear to have been accessed.

Findings

Based on our findings, the affected records included only business contact information of companies and individuals, publicly available information, notes on support cases (though not any attachments or files pertaining to such cases), and other non-sensitive business information used by Alteryx. We have confirmed that no Alteryx product environments or core systems were accessed through this incident, and we have not detected any further security irregularities following disabling the Drift connection.

Next steps

Alteryx will continue to work with Salesforce and monitor for indicators of suspect activity. We are also taking additional measures to ensure our Salesforce environment remains secure. If further investigation uncovers evidence of unauthorized access to sensitive information, we will directly notify impacted individuals and organizations commensurate with our contractual commitments and all relevant regulations.

What You Can Do

We recommend being cautious of unusual or unexpected communications that appear to come from Alteryx—for example, messages that request payment or change payment instructions.

If you have concerns about the authenticity of a communication purporting to originate from Alteryx, please contact us directly at security-notifications@alteryx.com or reach out to your Alteryx Account Representative.


Security Bulletins

🔔Find Security Bulletins in MyAlteryx

Security Bulletins keep you informed of potential security issues, offer guidance to help you stay protected, and reflect our ongoing commitment to your safety and trust. Sign in to MyAlteryx to view the latest updates.


ISO 22301

We Are Now ISO 22301 Certified!

Resilience You Can Count On

We’re excited to share that Alteryx is now ISO 22301 certified, the international standard for Business Continuity Management Systems (BCMS). This achievement reflects our commitment to operational resilience, proactive risk management, and continuous support for our customers, even in the face of disruption.

What This Means for You:

  • Reliable Operations: We have tested plans in place to keep critical systems running during unexpected events
  • Proactive Preparedness: We continuously identify, assess, and address potential risks to business continuity
  • Global Standards Alignment: Our program meets internationally recognized requirements for continuity and recovery

You can view our ISO 22301 certificate here in our Trust Center.

We’re proud to add this certification to our growing list of security and compliance milestones. Most of all, we’re proud to provide you with the confidence that comes from proven resilience.


Powered by Conveyor, the first end-to-end customer trust platform.
Learn more