Security

Everything runs in your AWS account

Your data and vendor credentials stay there, and the AWS costs go on your bill.

What leaves your AWS account

Metadata about each run, from a fixed list of fields. No data values, and no raw error text, because error messages often quote rows. Your due diligence can check the field list.

Licensed data never passes through our systems. That matters because some vendor licences forbid passing data to third parties, LLM providers included.

Who can access your account

Your Terraform creates three roles for us. None can read your secrets or change your infrastructure. Every use shows in your CloudTrail, and one edit revokes any of them.

Operations

For the people who run the service, each with their own MFA. It can run our tools and read data, for problems that need the actual values.

Automated triage

An LLM process that sees only the run metadata. It can take safe steps, like retrying a run, and nothing else.

Monitoring

Reads the run metadata and nothing else. It's how we notice a hold, or a setup that has gone quiet.

How changes reach your setup

Your setup is configured from a repo in your GitHub. It holds config and SQL, no Python. Infrastructure only changes through that repo's CI.

Every change arrives there as a pull request, tested against your recent data. Only we can merge it, and only after review.

If you stop working with us

Every upgrade copies the release into your account. You keep every release you ran, licensed for internal use. Your setup keeps running, and only upgrades and our operations stop.

The tables are Apache Iceberg on S3 and the feed rules use ODCS, an open standard. You can read both without our code.