Executive Summary
AI-generated analysis for Tableau
Tableau (tableau.com) is a well-established data visualization and analytics platform that presents a moderate overall risk posture, reflected in a Tier 3 rating from ThirdProof's rule engine. Several positive signals support Tableau's credibility as a vendor. The domain has been registered since 1996 — nearly 30 years — managed through enterprise registrar MarkMonitor with protections against unauthorized transfer or deletion. The SSL/TLS configuration is strong, using TLS 1.3 with AES-256-GCM encryption via a DigiCert-issued certificate valid through October 2026. No open ports or exposed services were detected on the primary IP, representing a minimal infrastructure footprint consistent with a mature SaaS platform. Malware detection service returns a clean result with no malware or phishing detections. Sanctions screening returned no confirmed matches — all results were assessed as likely false positives with zero confidence scores. Tableau has claimed SOC 2 compliance on a publicly accessible trust page (https://trust.tableau.com), which is a positive compliance signal, though the full Type II report should be requested directly. Three areas require attention before or shortly after onboarding:
Key Findings
- The public-facing website (tableau.com) received an F grade from Mozilla HTTP Observatory (20/100), with five failed security header tests including missing Strict-Transport-Security, Content-Security-Policy, and X-Frame-Options. While this scan targets the marketing site rather than the product application layer, it is a visible indicator of security hygiene practices.
- A subprocessor page exists at https://trust.tableau.com/subprocessors, but no structured entries could be automatically extracted. Given Tableau's position as a Salesforce subsidiary with likely extensive infrastructure dependencies, manual review of this page is warranted for data privacy due diligence.
- No public AI data usage policy was discovered, which is a meaningful gap for a platform that has introduced AI-assisted analytics features. Customers handling sensitive data should confirm Tableau's position on AI model training, third-party provider involvement, and data retention for AI processing. Overall, Tableau is a commercially mature, widely deployed analytics platform with no sanctions exposure or adverse media findings. The identified gaps are addressable through targeted documentation requests, and the platform is appropriate for medium data access use cases under conditional engagement terms.
Independence Statement
All evidence in this report was independently sourced from external data registries, public threat intelligence feeds, DNS infrastructure analysis, and open web sources without participation or input from the vendor.