Secure data infrastructure and guardrails for agents

dltHub ensures data residency, provides fine-grained access controls, secure environment variables management. Visit our trust center at trust.dlthub.com

  • Certifications and attestations

    • SOC 2 Type 1Certified
    • SOC 2 Type 2In progress. Observation period since 1 August 2026
    • ISO 27001In progress
    • HIPAAIn progress
  • Regions and data residency

    Your data is processed and stored in the EU or the US, chosen per organization, so pipelines run where your data is allowed to be.

  • Credentials and secrets

    Bring your own vault and dltHub holds only a link to it. Each profile keeps its own secrets, encrypted at rest with keys in a managed KMS.

Access, credentials and region control

Credentials are held per profile, roles are set per organisation and per workspace, and you choose the region your data is processed in.

Workspaces

Docs

Each team gets its own pipelines, its own secrets and its own line on the bill. Roles are set per organisation and per workspace, so finance and growth never share credentials.

TeamScopeRole
data-platformOrganisationAdmin
finance-analyticsWorkspace · financeEditor
growthWorkspace · growthEditor
risk-reviewWorkspace · financeViewer
Secrets are redacted after setup. Nobody reads them back.

Profiles

Docs

Dev, prod and access each hold their own configuration and secrets.

devprodaccess
dlthub profile list

Encryption

Docs

Encrypted at rest and in transit, with keys held in a managed KMS apart from the data, to NIST SP 800-57.

The key is not stored with the data.

Environment variables

Docs

Configuration and secrets, set once and scoped per profile, resolved when the pipeline runs. Change a value without redeploying.

VariableValueApplies to
WAREHOUSEsnowflakeAll profiles
BATCH_SIZE50000prod
LOG_LEVELdebugdev
ORACLE_DSNbicc.internal:1521prod
dlthub env set BATCH_SIZE=50000

Regions

Docs

Choose the EU or the US for where your data is processed and stored, so pipelines run where your data is allowed to be.

Control plane in North Virginia

Your data stays in the region you pick.

ConsumptionPreview

Docs

Credits are consumed when a pipeline runs, transforms or checks data, and the bill breaks down by workspace, so each team carries what it spends.

WorkspaceCredits this monthShare
finance12,40038%
growth8,60026%
product-analytics7,04022%
sandbox4,58014%
Every credit traces to the workspace that spent it.

What a deployed workspace isolates

A deployed workspace provides the isolation of code, execution and data a multi-tenant architecture needs, across six dimensions. Each tenant is assigned one or more workspaces.

  1. 1

    Dev env and CI

    Workspaces link to your code repositories. One repository can define several workspaces that deploy independently.

  2. 2

    Deployment, storage

    Each workspace deploys to one data plane, EU or US, with isolated storage. Workspaces cannot see each other’s metadata.

  3. 3

    Secrets

    Bring your own vault and keep only a link to it on dltHub. Separate secrets, separate vaults, or prefix permissions.

  4. 4

    Operational

    Jobs are defined per workspace and scheduled independently. User, agent and service-account access is set at workspace level.

  5. 5

    Execution

    Code runs in isolated sandboxes: the only place where code, configuration and secrets meet, and the only place tenant data is processed.

  6. 6

    Tenant data

    Separate databases or warehouse accounts for full isolation, or a shared one where a tenant id separates the data.

Private connectivity

Sandboxes reach a production database over a private link, so the database never needs a public IP. A private endpoint in dltHub’s VPC connects to a service you publish from your own.

  • AWSPrivateLink
  • Google CloudPrivate Service Connect
  • AzurePrivate Link

Alternative. dltHub provides compute with static IPs, so inbound access to your resources can be allowed on the firewall instead of over a private link.

Where your data runs, and who can reach it

You choose where your data is processed. Pick the EU or the US when you create a workspace, and every pipeline in it runs there.

Each profile holds its own secrets, encrypted at rest with keys held in a managed KMS, separate from the data, to NIST SP 800-57.

Our control, data, storage and application systems each run on their own isolated network with its own security boundary, so a problem in one has nowhere to go.

  • SOC 2 Type 1Certified
  • SOC 2 Type 2In progress. Observation period since 1 August 2026
  • ISO 27001In progress
  • HIPAAIn progress
Trust CenterEvery control, the audit reports, our policies and the subprocessor list, kept current.

Deployment

Three ways to deploy, and where your data sits in each

Where your pipelines execute decides which of your networks they can reach. That one choice is the difference between these three.

SaaS + private linksAvailable todayBYOC: computeReference design, built with youBYOC: data + computeReference design, built with you
Where it runsControl planeNo customer data passes through itdltHubdltHubdltHub
Data planeCode, secrets, logs, configurationdltHubdltHubYour cloud
Execution planeDecides which networks it can reachdltHub VPCYour cloudYour cloud
Where your data staysYour secretsdltHub data planeNever leave your cloudNever leave your cloud
Code, config, telemetry at restdltHubdltHubYour cloud
Sources and destinationsReached over a private link onlyNever leave your cloudNever leave your cloud
Private link to your sourcesRequiredNot neededNot needed

Private links over AWS PrivateLink, GCP Private Service Connect or Azure Private Link. We provision the endpoint; a dedicated egress proxy where a static IP is preferred.