Organisation hierarchy
Group workspaces by business unit or region, apply policy at any level, and let a domain owner administer their own branch without seeing the rest.
Northlane for enterprise
Single-tenant deployment, your own KMS keys, SCIM-driven access and an audit stream your risk team can query. Enterprise rollouts land in a scheduled window, not a support ticket.
Running inside regulated estates
Enterprise controls
Everything below runs today on Enterprise workspaces. Each control maps to a SOC 2 criterion and to a clause in the security addendum attached to your order form.
Provisioned per organisation at contract start. The region is fixed for the life of the workspace.
A dedicated VPC, dedicated warehouse credentials and a dedicated metadata store. No customer shares a compute node at query time.
Bring your own KMS key. Revoking it halts processing within 60 seconds and leaves stored metadata unreadable.
Pin the organisation to eu-west-1, eu-central-1, us-east-1 or ap-southeast-2. Neither metadata nor derived lineage crosses that boundary.
Enforced across the whole organisation once your identity provider is connected, not workspace by workspace.
Any SAML 2.0 or OIDC provider with SCIM 2.0 push. A leaver in your directory loses Northlane access inside 60 seconds.
Every read, permission change and export, retained 400 days and streamed to Splunk, Chronicle or an S3 bucket you own.
SOC 2 Type II report, ISO 27001 certificate, penetration test summary and the sub-processor register, released under NDA.
Descriptions summarise the Enterprise production environment as of this quarter. The SOC 2 Type II report and the security addendum on your order form are the governing documents; nothing on this page amends a signed agreement.
Administration and scale
Policy applies at the organisation level, ownership is delegated down, and quotas stop one backfill from starving everybody else.
Group workspaces by business unit or region, apply policy at any level, and let a domain owner administer their own branch without seeing the rest.
Nine built-in roles plus custom roles scoped to a workspace, a project or a single column. Every grant is approved, signed and retained.
Per-team warehouse credit budgets with hard stops. A runaway backfill is queued and flagged to its owner rather than billed.
Policy edits go through review, land in the audit stream, and can be rolled back to any state in the last 400 days.
PrivateLink, VPC peering or an IP-allowlisted egress gateway. Your warehouse never needs a public endpoint.
Import existing dbt projects, Airflow DAGs and third-party monitors, then run both systems side by side until you sign off the cutover.
See the migration guideEvery capability above is included in the Enterprise licence — none of it is a paid add-on.
Deployment
Every deployment model shares the same control plane, the same policy engine and the same audit stream. What changes is where the metadata store sits and who holds the keys — so procurement and platform can pick independently of the feature set.
Enterprise rollouts, last twelve months
Business or Enterprise
Everything in Business carries over. The rows below are the only differences, and most of them are about isolation, identity and the commercial terms rather than features.
| Capability | Business $549 / month, billed annually Compare all plans | 500+ seats Enterprise Annual, volume-tiered Talk to sales |
|---|---|---|
| Isolation and residency | ||
| Deployment model | Multi-tenant cloud | Single-tenant VPC or your own account |
| Data residency | Limited US and EU regions only | Included |
| Customer-managed encryption keys Bring your own KMS key | Not included | Included |
| Private networking PrivateLink, VPC peering or an egress gateway | Limited By request | Included |
| Identity and governance | ||
| SSO (SAML 2.0, OIDC) | Included | Included |
| SCIM provisioning | Not included | Included |
| Custom roles and column-level policy | Limited Workspace scope only | Included |
| Audit log export The 400-day retention window is fixed on both plans and cannot be shortened | In-app export | Streamed to your SIEM Splunk, Chronicle or an S3 bucket you own; archive length negotiable |
| Organisation hierarchy and delegated admin | Not included | Included |
| Support and commercial terms | ||
| First-response SLA | 4 hours | 1 hour, 24/7 |
| Named solutions architect | Not included | Included |
| Uptime commitment | 99.9% | 99.99% With service credits |
| Security review support | Limited Standard questionnaire only | Included Custom questionnaires and review calls |
| Contracting | Standard order form | Negotiated MSA and DPA |
$549 / month, billed annually
Annual, volume-tiered
A half-filled mark means the capability is available with a limit. The note under the mark says what the limit is.
Enterprise proof
Each rollout below crossed at least two regions and a formal security review. The numbers are the customer's own, measured 90 days after cutover.
Halden Bank
Banking 9,400 employees
Eleven regional warehouses moved onto one policy engine in a single-tenant deployment, with the regulator briefed before the first sync ran.
Healthcare 18,000 employees
Residency rules that used to live in a spreadsheet are now enforced by the platform, with an audit stream the compliance office queries directly.
Logistics 6,200 employees
Per-team credit budgets replaced a quarterly cost review, and the finance team stopped chasing owners for unattributed compute.
Contact sales
Enterprise conversations start with an architecture review, not a pitch. Send the warehouses in scope, the regions you need and the date your review board meets. You get back a deployment plan, a written migration estimate and the evidence pack.
First reply in under 4 business hours
Warehouses, regions, headcount and the deadline. That is enough for us to scope it properly.
We use these details to answer your request. No sequences, no resale.
Or reach the team directly