Security and data sovereignty
Open source core with full source availability.
Granular role-based access rules enforced server-side.
Government-audited and auditable.
Fully self-hostable for on-prem deployment.
How does Grist handle my data?

Grist is built for sensitive data. Your data is deployable on-premise while remaining collaborative. Your data is portable but follows strict role-based access rules when exporting to lower exfiltration risk. This technical architecture flows directly from our long-standing software principles.
Why do organizations with strict data security requirements choose Grist?
Grist is 100% self-hostable for on-premises deployment, or available with managed hosting around the world.
Grist presents a lowered risk profile thanks to comprehensive and highly-customizable role-based access rules, letting you limit access and exporting down to the row. You can also test these roles interactively to make sure access is properly limited.
Grist is built around fully portable data with no lock-in mechanisms. A Grist file is an SQLite database, and always able to be exported elsewhere – subject to access rules, of course.
How can Grist be deployed?
Managed server
Grist Labs deploys and manages Grist on a dedicated server in a region of your choice. Gives you the customization of self-hosting, but leaves the devops and maintenance to us.
Self-hosted
Serve containerized via Docker or compile directly from source. Configure everything to fit your requirements: SSO, storage, sandboxing, snapshots, styling, and much more.
Build secure business apps with AI
Grist’s unique structure and considered MCP implementation encourages coherent and effective vibe-coding. Building, managing, maintaining, deploying and redeploying can be effective and secure. Start building out of the box, or bring your own model and leverage agents and MCP tool calling.
The architectural advantage

A .grist file holds an app’s data, its views, its business logic (as formulas), and its user permissions — both role-based access control (RBAC) and row-level security (RLS) — in a single portable, editable, self-contained artifact. Most vibe-coding stacks spread those same pieces across a separate frontend, database, auth layer, and storage.
Secure collaboration without compromise

Grist’s unique access rules that are enforced server-side. Unlike spreadsheet security theater like hidden cells and locked documents, Grist prevents data leakage with explicitly defined and owner-customizable user roles.
Grist’s access rules are granular enough to enable permission gating down to the cell, all without duplicating data for different audiences. These rules also apply to AI agents, preventing automated circumvention.
Why enterprises self-host Grist
Address governance, compliance or data residency requirements.
Integrate into your organization’s SSO.
Run with extra CPU and memory.
Create advanced integrations.
Grist for Enterprise
24-hour patch notice
Installation and admin controls
Audit logging
Technical & end-user support
Frequently asked questions
Yes. Grist being fully self-hostable means you can deploy it on servers you own and administer. Grist Labs can also deploy and manage a Grist server for you in the region of your choice.
Learn more about self-hosting Grist in our Help Center, and visit grist-core repo on GitHub to view the source.
Grist supports a variety of authentication options for self-hosters, including OIDC, SAML and forwarded headers. If you don’t have a system already in place, we also provide an authentication method that lets users sign in via getgrist.com, built on the industry-standard OAuth 2.0 and OpenID Connect (OIDC) protocols. Learn more about self-hosted authentication in our Help Center.
Self-hosted Grist also supports the System for Cross-domain Identity Management (SCIM) for managing large organizations with dynamic user bases. Learn more.
Grist data is always portable and exportable, subject to access rules that you define. You can export tables as CSV, TSV and XLSX files, as well an entire Grist documents with or without change history.
Grist documents can be downloaded in their entirety as an SQLite database file with a .grist extension. The downloaded file will contain all your tabular data, any attached files within those tables, metadata about your tables, pages, and widgets, and a history of recent modifications of the document.
The French government deploys Grist as part of its digital suite for thousands of public sector workers.
Grist is a general tool and is used in many different capacities. Aside from the French public service, some of the largest Grist deployments are in manufacturing (Maddox), aerospace (NP Aerospace) and utilities (AEP). All of these industries have strict security needs, including on-premises hosting as an absolute requirement.
Enforcing security in a Microsoft stack with Purview labels, SharePoint permissions and DLP help at the edges, but aren’t a complete solution. They don’t address the core problem, which is at the file-level.
If users can open the file, it’s safe to assume they can see everything in it. There’s no row-level security, no role-based access to a single column or tab, enforced live inside the workbook. Purview’s protections are real but conditional: automatic labeling is an E5-only feature; users can decline labels; and it skips legacy formats like .xls. Also, once data is exported to CSV, every label and every trace of metadata is stripped clean.
DLP has a similar problem, being weak on data at rest and prone enough to false alarms that teams loosen the rules until the gaps become dangerous. Read more about how Grist’s file format helps its security story.
Who uses Grist?

LaSuite
Grist is one of the open source foundations of LaSuite, France’s sovereign digital workspace. There are over 20,000 Grist users in multiple agencies and regions across the country.

Maddox
Maddox builds industrial transformers and runs Grist on-prem to augment and replace their spreadsheets, specifically KPI tracking and consolidation for production, manufacturing, and sales delivery.

E-J Electric
E-J Electric is a large electrical contractor with a dedicated instance of Grist that helps their many distributed worksites collaborate on relational data.
Take control of your data
Unlock your data’s true potential with the better spreadsheet



