
Initial Setup: This includes installing the software and configuring it to align with the organization's IT infrastructure.
Data Integration: Connecting Alteryx to various data sources within the organization to ensure seamless data flow.
Workflow Creation: Developing and customizing workflows to meet specific business requirements.
Data Protection Compliance: Alteryx meets or exceeds data protection requirements for personal data as outlined by GDPR and CCPA. They have measures in place to notify impacted individuals in case of a confirmed data breach.
Technical and Organizational Measures: Alteryx has implemented organizational, physical, technical, and operational security measures aligned with standards such as ISO 27001. These measures are designed to protect the confidentiality, integrity, and availability of systems and data.
Encryption: Customer Content is encrypted both in transit and at rest. Data in transit is protected using TLS 1.3 encryption, and data at rest is encrypted with 256-bit AES block ciphers.
Access Control: Alteryx employees and contractors do not access or use Customer Content in their ordinary job duties. Limited, monitored access is granted only when customers request support, and only with the customer's approval.
Incident Response: Alteryx has a dedicated incident response team that manages the identification and detection of security incidents, provides timely responses, and takes necessary steps for prompt recovery of systems and data. Their incident response practices align with ISO 27035 and NIST 800-61.
Compliance and Certification: Alteryx holds certifications like ISO 27001 and SOC2 Type II, and aligns with frameworks such as the NIST Cybersecurity Framework and CIS Controls. Their solutions also meet Federal Information Processing Standards (FIPS) compatibility.
Private Data Handling: Alteryx offers private data handling capabilities, including private data storage and processing within a customer's VPC. This includes the use of mTLS encryption for intra-cluster communications and envelope encryption for credentials.
Auto Check for Updates: If connected to the internet, Alteryx automatically checks for updates each time the software is launched. Users are notified if a newer version is available, and they can choose to download the update immediately or defer it for a specified period.
Manual Check for Updates: Users can manually check for updates at any time by navigating to the "Help" menu and selecting "Check for Updates." This requires an internet connection and will inform the user if a new version is available or if their current version is up to date.
Patch Updates: Alteryx provides patch updates that include fixes to defects between regular releases. These patches can be installed without the need for a full uninstall and reinstall, making the process faster and easier.
Major Releases: Major releases, which include new features and significant changes, are supported for 24 months. Organizations can choose to upgrade to the latest version or follow a "current-release-minus-1" strategy to ensure stability.
Data Ownership and Portability:
Contract Renewal:
2. Contract Cancellation:
ISO 27001: Alteryx is certified under ISO 27001, which is an international standard for information security management systems (ISMS). This certification demonstrates Alteryx's commitment to managing and protecting sensitive company and customer information.
SOC 2 Type II: Alteryx holds SOC 2 Type II certification, which ensures that the company meets stringent criteria for managing customer data based on five "trust service principles"—security, availability, processing integrity, confidentiality, and privacy.
GDPR and CCPA Compliance: Alteryx complies with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), ensuring that personal data is handled in accordance with these regulations. This includes responding to data subject requests and providing options for data privacy and protection.
Federal Information Processing Standards (FIPS): Alteryx's solutions meet the thresholds for FIPS compatibility as established by the National Institute of Standards and Technology (NIST) and in accordance with the Federal Information Security Management Act (FISMA).
NIST Cybersecurity Framework and CIS Controls: Alteryx aligns with the NIST Cybersecurity Framework and CIS Controls, which provide guidelines and best practices for improving the security and resilience of information systems.

Alteryx Designer
By Alteryx