Your data lands in your warehouse. Our pipeline is the only thing in our scope. That's not marketing — it's the architecture.
Customer-owned Postgres and S3 are the default. We don't host a copy of your business. If you cancel, our footprint in your environment is "drop one role."
Aligned with Amazon's Data Protection Policy v2 — encryption at rest and in transit, scoped tokens, and audited access patterns.
Every workspace gets its own credentials, its own row-scope, its own audit trail. Multi-tenant agencies can't accidentally cross client boundaries.
Background checks, least-privilege production access, MFA enforced, change review on every infra commit, paged on-call rotation.
In progress. Report available on request once issued.
Standard DPA and sub-processor list available on request.
Annual third-party assessment, evidence pack on request.
TLS 1.2+ in transit. AES-256 at rest.
Found something? Email us. We respond within one business day, acknowledge confirmed vulnerabilities publicly with credit, and don't pursue legal action against good-faith research.
security@databrill.com