Back To Top Arrow
Security, Privacy & Governance

Your data.
Your control.
Our commitment.

Security-first, and flexible by design. Run Connecty in place on your own data warehouse, or let us host your data in our SOC 2 Type II & ISO 27001–certified cloud — whichever fits your team. Encrypted end to end, access-controlled, and fully auditable either way.

Meta Verified Tech Provider Your warehouse or our certified cloud GDPR-aligned
app.connecty.ai

How your data is protected — end to end

Connect your sourceMeta · Snowflake · BigQuery · Databricks OAuth2
Encrypted in transitTLS on every connection TLS
Least-privilege accessValidated & access-controlled per user Verified
Certified environmentWarehouse in-place, or SOC 2 · ISO 27001 cloud AES-256
Encryption
AES-256
Certified cloud
AWS · GCP
AES-256Encryption at rest · TLS in transit · OAuth2
AWS + GCPHosted in SOC 2 Type II & ISO 27001–certified cloud
Meta Verified Tech ProviderVerified Meta Tech Provider
0%Of user actions logged & auditable
Trust Framework

Seven layers between your data and any risk.

Every pillar below is enforced by architecture, not policy — so security holds whether a query comes from an analyst, an agent, or an API call.

Metadata & schemaSent to the modelAllowed
Raw records & PIINever reach the LLMBlocked
Pillar 01

No sensitive data is ever shared with AI.

As GDPR veterans with financial-industry roots, we treat your data like it's our own. Insights are driven by metadata, schema structure, and authorized query patterns — not raw data.

Automatic PII detectionFrom the moment your data connects, we extract PII-related metadata and infer context — and you can override any inference at any time.
Verified before executionEvery interaction with your physical data is validated by Connecty before it runs — parsed and checked outside the LLM.
Strict access enforcementRules are applied deterministically, so no query can reach beyond its permitted scope.
Prompt-injection proof

Because queries are parsed and validated outside the model, no one can manipulate the LLM into performing unauthorized actions beyond their data scope.

Your warehouseEnterprise · in-placeIn-place
Connecty cloudSelf-serve · AWS + GCPCertified
Pillar 02

Where your data lives — your choice.

Flexible by design. Keep everything in your own warehouse, or let Connecty host it in our certified cloud — with the same encryption, access controls, and audit trail either way.

Bring your own warehouse — EnterpriseConnecty runs in place inside your Snowflake, Databricks, or BigQuery via service-account access you control. Your data never leaves your environment.
Connecty secure cloud — Self-serveData is hosted in secure AWS and Google Cloud environments — both SOC 2 Type II and ISO 27001 certified — encrypted at rest and in transit.
Controlled by youEvery interaction can be disabled or set to require explicit confirmation — data never moves unless you allow it.
Encrypted everywhere

AES-256 at rest, TLS in transit — whichever deployment you choose, your data is protected the whole way.

Data EnvironmentsProd · Staging · Business unitPhysical
Data WorkspacesBy team, function, personIntelligence
Pillar 03

Manage access to data and intelligence.

Connecty introduces a multi-level access-management system that separates physical data from the intelligence built on top of it.

Data EnvironmentsSeparate physical data access by context — production, staging, or individual business units.
Data WorkspacesSeparate intelligence by department, function, or individual, and let moderators control the quality of custom metric definitions.
Any level of granularityConfigure access from entire databases down to individual tables.
Impenetrable by design

Administrators can compose an airtight data-governance experience for every user, matched exactly to how your organization is structured.

Sync · Materialize · ExecuteScope defined preciselyControlled
Unlimited workspacesMirror team boundariesFlexible
Pillar 04

Granular governance, built in.

Define precisely what can be synced, materialized, and executed — with complete control over scope and location.

Precise scope controlDecide exactly what Connecty may sync, materialize, and run — and where each operation is allowed to happen.
Strict environment separationEnforce boundaries between production, staging, and beyond to align with your deployment workflows.
Unlimited data workspacesCreate as many as you need to mirror team boundaries and access policies exactly.
Governance as configuration

Policy isn't an afterthought — it's part of how every workspace is provisioned, so the right guardrails exist before anyone runs a query.

AES-256 at restCredentials protectedEncrypted
TLS in transitAll communicationsEncrypted
Pillar 05

Enterprise-grade security.

Encryption and authentication that meet the bar set by the most security-conscious teams — applied everywhere by default.

OAuth2 authenticationSeamless, secure login backed by a modern standard.
AES-256 encryptionCredentials are protected with strong, industry-standard encryption at rest.
TLS everywhereAll communications are encrypted in transit, end to end.
Secure by default

There's nothing to switch on. Encryption and OAuth2 are the baseline for every connection and every session.

SAML SSO (Okta)Central identityFederated
ABAC policiesAdapts as roles changeDynamic
Pillar 06

Role-based control.

Identity and policy enforcement that plugs straight into your existing governance strategy.

SAML SSO with OktaCentralized identity and policy enforcement across the platform.
User, group & role permissionsAligned with your governance strategy at every level.
Attribute-Based Access ControlABAC enables dynamic policy enforcement as users change roles or teams — no manual re-provisioning.
Policy that follows people

When someone moves teams, their access follows automatically — attributes drive permissions, so nothing is left over-granted.

Every query loggedFully traceableImmutable
Audit & compliance readyInternal & regulatoryReady
Pillar 07

Full auditability.

Every user action — including queries and modifications — is logged and fully traceable, so you always have the record you need.

Complete action historyQueries, edits, and access events are captured in a traceable log.
Built for internal auditsGive your security and data teams the visibility they expect.
Regulatory supportTraceability that stands up to compliance requirements.
Nothing goes unrecorded

Because every action is captured, you can always answer "who did what, and when" — for an internal review or an external auditor.

Infrastructure & Compliance

Built on infrastructure that's independently certified.

On the self-serve plan, Connecty hosts your data in secure AWS and Google Cloud environments — both SOC 2 Type II and ISO 27001 certified. On Enterprise, bring your own warehouse and Connecty runs in place, so your data never leaves your environment.

Amazon Web Services

Data is hosted in AWS environments that are independently SOC 2 Type II and ISO 27001 certified.

Certified cloud

Google Cloud

Workloads also run on GCP environments that are independently SOC 2 Type II and ISO 27001 certified.

Certified cloud
Meta Verified Tech Provider

Meta Verified Tech Provider

Connecty is a verified technology provider in the Meta partner ecosystem for ads and creative data.

Verified

GDPR-aligned

Data-handling practices are aligned with EU data-protection and privacy regulations and user rights.

Aligned

Connecty relies on the certifications of its infrastructure vendors (AWS, Google Cloud) rather than holding these certifications directly.

Review our security
for yourself.

Explore live documentation, certifications, and control details in the Connecty Trust Center — or bring your security team to a working session with ours.

Encrypted end to end · SOC 2 Type II & ISO 27001 certified cloud.