Secure data infrastructure and guardrails for agents
dltHub ensures data residency, provides fine-grained access controls, secure environment variables management. Visit our trust center at trust.dlthub.com
Certifications and attestations
SOC 2 Type 1Certified
SOC 2 Type 2In progress. Observation period since 1 August 2026
ISO 27001In progress
HIPAAIn progress
Regions and data residency
Your data is processed and stored in the EU or the US, chosen per organization, so pipelines run where your data is allowed to be.
Credentials and secrets
Bring your own vault and dltHub holds only a link to it. Each profile keeps its own secrets, encrypted at rest with keys in a managed KMS.
Access, credentials and region control
Credentials are held per profile, roles are set per organisation and per workspace, and you choose the region your data is processed in.
Workspaces
DocsEach team gets its own pipelines, its own secrets and its own line on the bill. Roles are set per organisation and per workspace, so finance and growth never share credentials.
| Team | Scope | Role |
|---|---|---|
| data-platform | Organisation | Admin |
| finance-analytics | Workspace · finance | Editor |
| growth | Workspace · growth | Editor |
| risk-review | Workspace · finance | Viewer |
Profiles
DocsDev, prod and access each hold their own configuration and secrets.
Encryption
DocsEncrypted at rest and in transit, with keys held in a managed KMS apart from the data, to NIST SP 800-57.
Environment variables
DocsConfiguration and secrets, set once and scoped per profile, resolved when the pipeline runs. Change a value without redeploying.
| Variable | Value | Applies to |
|---|---|---|
| WAREHOUSE | snowflake | All profiles |
| BATCH_SIZE | 50000 | prod |
| LOG_LEVEL | debug | dev |
| ORACLE_DSN | bicc.internal:1521 | prod |
Regions
DocsChoose the EU or the US for where your data is processed and stored, so pipelines run where your data is allowed to be.
Control plane in North Virginia
ConsumptionPreview
DocsCredits are consumed when a pipeline runs, transforms or checks data, and the bill breaks down by workspace, so each team carries what it spends.
| Workspace | Credits this month | Share |
|---|---|---|
| finance | 12,400 | 38% |
| growth | 8,600 | 26% |
| product-analytics | 7,040 | 22% |
| sandbox | 4,580 | 14% |
What a deployed workspace isolates
A deployed workspace provides the isolation of code, execution and data a multi-tenant architecture needs, across six dimensions. Each tenant is assigned one or more workspaces.
- 1
Dev env and CI
Workspaces link to your code repositories. One repository can define several workspaces that deploy independently.
- 2
Deployment, storage
Each workspace deploys to one data plane, EU or US, with isolated storage. Workspaces cannot see each other’s metadata.
- 3
Secrets
Bring your own vault and keep only a link to it on dltHub. Separate secrets, separate vaults, or prefix permissions.
- 4
Operational
Jobs are defined per workspace and scheduled independently. User, agent and service-account access is set at workspace level.
- 5
Execution
Code runs in isolated sandboxes: the only place where code, configuration and secrets meet, and the only place tenant data is processed.
- 6
Tenant data
Separate databases or warehouse accounts for full isolation, or a shared one where a tenant id separates the data.
Private connectivity
Sandboxes reach a production database over a private link, so the database never needs a public IP. A private endpoint in dltHub’s VPC connects to a service you publish from your own.
AWSPrivateLink
Google CloudPrivate Service Connect
AzurePrivate Link
Alternative. dltHub provides compute with static IPs, so inbound access to your resources can be allowed on the firewall instead of over a private link.
Where your data runs, and who can reach it
You choose where your data is processed. Pick the EU or the US when you create a workspace, and every pipeline in it runs there.
Each profile holds its own secrets, encrypted at rest with keys held in a managed KMS, separate from the data, to NIST SP 800-57.
Our control, data, storage and application systems each run on their own isolated network with its own security boundary, so a problem in one has nowhere to go.
SOC 2 Type 1Certified
SOC 2 Type 2In progress. Observation period since 1 August 2026
ISO 27001In progress
HIPAAIn progress
Deployment
Three ways to deploy, and where your data sits in each
Where your pipelines execute decides which of your networks they can reach. That one choice is the difference between these three.
| SaaS + private linksAvailable today | BYOC: computeReference design, built with you | BYOC: data + computeReference design, built with you | |
|---|---|---|---|
| Where it runsControl planeNo customer data passes through it | dltHub | dltHub | dltHub |
| Data planeCode, secrets, logs, configuration | dltHub | dltHub | Your cloud |
| Execution planeDecides which networks it can reach | dltHub VPC | Your cloud | Your cloud |
| Where your data staysYour secrets | dltHub data plane | Never leave your cloud | Never leave your cloud |
| Code, config, telemetry at rest | dltHub | dltHub | Your cloud |
| Sources and destinations | Reached over a private link only | Never leave your cloud | Never leave your cloud |
| Private link to your sources | Required | Not needed | Not needed |
Private links over AWS PrivateLink, GCP Private Service Connect or Azure Private Link. We provision the endpoint; a dedicated egress proxy where a static IP is preferred.