Trust center
Security
Your data. Your infrastructure. Your rules. The short version: row data never lands on our disks — only schema metadata does.
Data model
- Row data: queried live from your source, rendered in-session, never stored.
- Schema metadata: table/column names and types only, encrypted at rest, auto-deleted deleted within 30 days of disconnect or account closure.
- Credentials: encrypted with per-workspace keys, used solely to open your connection.
Encryption & residency
TLS 1.2+ in transit, AES-256 at rest. Hosted data lives in ap-south-1 (Mumbai) with encrypted backups in ap-south-2. Backups kept 35 days.
Access control
Analyst (view), Operations (edit + run actions), Admin (full access). SSO on Team and above, SCIM on Business. Every sensitive operation lands in immutable audit logs kept 90 days rolling.
Self-hosted
Run everything inside your VPC: images, migrations, and docs from us; data plane entirely yours. Report vulnerabilities to [email protected] — we acknowledge within 48 hours.
What we don't claim
No SOC 2 / ISO badges yet — ask for our latest pen-test summary at [email protected] instead of assuming certifications we haven’t earned.