Security

Built so finance and security teams say yes

Your data lands in your warehouse. Our pipeline is the only thing in our scope. That's not marketing — it's the architecture.

Four things we got right

Sovereignty

Customer-owned Postgres and S3 are the default. We don't host a copy of your business. If you cancel, our footprint in your environment is "drop one role."

SP-API DPP-2 alignment

Aligned with Amazon's Data Protection Policy v2 — encryption at rest and in transit, scoped tokens, and audited access patterns.

Per-workspace isolation

Every workspace gets its own credentials, its own row-scope, its own audit trail. Multi-tenant agencies can't accidentally cross client boundaries.

Audited operational practices

Background checks, least-privilege production access, MFA enforced, change review on every infra commit, paged on-call rotation.

Compliance & review packs

SOC 2 Type II

In progress. Report available on request once issued.

GDPR & UK GDPR

Standard DPA and sub-processor list available on request.

Amazon SP-API DPP-2

Annual third-party assessment, evidence pack on request.

Encryption

TLS 1.2+ in transit. AES-256 at rest.

Responsible disclosure

Found something? Email us. We respond within one business day, acknowledge confirmed vulnerabilities publicly with credit, and don't pursue legal action against good-faith research.

security@databrill.com