Security

Engineered for your strictest requirements.

DataEmissary was designed around a simple rule: your data never has to leave your control for AI to work on it. Agents run inside your perimeter, under your policies, with proof of everything they do.

Principles

Four rules every agent follows.

Your perimeter, always

Agents execute as workloads inside your own cloud account and warehouse. Queries run where your data lives — there is no pipeline shipping tables out to a third-party AI service.

Least privilege, inherited

Each agent operates under a warehouse role you define — Snowflake roles or BigQuery IAM — scoped to exactly the schemas it needs. An agent can never see data its role can't see.

Complete audit trail

Every query an agent runs, every conclusion it draws, and every action it proposes is logged with full lineage. You can reconstruct exactly what happened, when, and why — down to the SQL.

Never trained on your data

Your warehouse data is used only to answer your questions. It is never used to train shared models, never retained beyond your retention settings, and never visible to other tenants.

Practices

How we build and operate.

DataEmissary is in development, and security is part of the architecture — not a layer added later. These are the practices we're building to:

  • Encryption everywhere. Data encrypted in transit (TLS 1.2+) and at rest (AES-256) across every component we operate.
  • Human approval for writes. Agents read autonomously; anything that modifies data, schedules, or permissions waits for an explicit human approval.
  • Secrets stay yours. Warehouse credentials are stored in your secret manager or ours with hardware-backed encryption — never in code, logs, or chat transcripts.
  • Regional control. Agents run in the cloud region your warehouse lives in. Your data doesn't cross borders you didn't choose.
  • Reviewed releases. Every release goes through security review before it touches a customer warehouse, and changes are versioned and rollback-safe.

Found a vulnerability?

We take reports seriously. Email us with details and we'll acknowledge within two business days.

hello@dataemissary.com →
Early access

DataEmissary is in development.

Bring your security questionnaire to the conversation — we're building to pass it. Request early access and tell us about your stack.

Request early access →