SOC 2 Type II Certified

Security-First Architecture

Your data security is our top priority. We've built our platform from the ground up with enterprise-grade security controls.

Our Security Principles

Metadata Only

We only access query metadata, resource configurations, and cost data. We never read your actual table data, S3 objects, or query results.

Read-Only Access

Our service accounts use read-only permissions. We cannot modify warehouses, terminate instances, or change any configurations in your environment.

Encrypted Credentials

All connection credentials are encrypted at rest using AES-256 encryption. Keys are managed via AWS KMS with automatic rotation.

SOC 2 Type II

We maintain SOC 2 Type II compliance with annual audits covering security, availability, and confidentiality controls.

Audit Logging

Every access to your data is logged with timestamps, IP addresses, and user context. Logs are retained for 90 days and available on request.

SSO & RBAC

Enterprise plans include SAML SSO integration and role-based access control to manage team permissions granularly.

What We Access (And What We Don't)

Transparency is core to our security model. Here's exactly what data we read from your connected accounts.

Snowflake Data Access

We use a read-only role with access to metadata views only

DataAccessPurpose
ACCOUNT_USAGE viewsReadQuery patterns & warehouse usage
INFORMATION_SCHEMAReadTable metadata & storage
Query historyReadPerformance analysis
Warehouse metricsReadUtilization analysis
Your table dataNever
Query resultsNever

AWS Data Access

We use a cross-account IAM role with read-only permissions

DataAccessPurpose
Cost Explorer APIReadCost breakdown & trends
CloudWatch metricsReadResource utilization
Resource tagging APIReadCost allocation
EC2/RDS describe APIsReadResource inventory
S3 bucket contentsNever
Database contentsNever

Compliance & Certifications

SOC 2 Type II

Annual third-party audits verifying our security, availability, and confidentiality controls.

GDPR Compliant

Full compliance with EU data protection regulations including data residency options.

HIPAA Ready

BAA available for healthcare organizations on Enterprise plans.

Security Questions?

Our security team is happy to answer questions, provide our SOC 2 report, or discuss your specific compliance requirements.