Security and isolation at every layer
From the source connection to the published dashboard, every access is controlled, scoped and auditable. Data governance isn't a separate project — it's part of the structure.
Security and isolation at every layer
Data in the São Paulo region
Processing and storage in Brazil.
Per-user access control
Each person sees only what they need.
Granular permissions
Control over sources, datasets, dashboards and queries.
Sensitive data governance
Features that support LGPD (Brazil's data protection law) best practices and PII tagging.
Service Accounts
Secure consumption by machines and integrations.
Controlled APIs and webhooks
Read-only, scoped and auditable access.
Per-customer separation
Each company's data is kept isolated, with one dataset and one bucket per tenant.
Your own cloud (BYOC)
On Business and Scale, the datalake can run in your company's cloud.
Architecture implemented and covered by tests; validating isolation in the cloud (real IAM) is a pilot stage. Each company's data is isolated per tenant, with one dataset and one bucket per customer.
Security and isolation at every layer
Sensitive data (PII)
Tagging and protection of sensitive fields, with group-based access control.
Data lineage
Where each number came from: trace the origin column by column.
Auditing
Who accessed, queried and changed what — all logged.
Access control
Permissions by user, team and table; row- and column-level security.
Auditing
Who accessed, queried and changed what — all logged.