Everything your security review will ask for

Access controls, credential handling, encryption, data residency and audit. Certifications and the full control set are published and current at trust.dlthub.com.

Access, credentials and region control

Each team gets its own pipelines, secrets and spend. Credentials are held per environment, configuration is separate from code, and you choose the region the work runs in.

Docs

Workspaces

Each team gets its own pipelines, secrets and spend. Roles are set per organisation and per workspace, so finance and growth never share credentials.

TeamScopeRole
data-platformOrganisationAdmin
finance-analyticsWorkspace · financeEditor
growthWorkspace · growthEditor
risk-reviewWorkspace · financeViewer
A viewer can read every run and open no secret.
Docs

Profiles

Dev, prod and access each hold their own configuration and secrets. The pipeline code is the same in all three.

devprodaccess
dlthub profile list
Docs

Encryption

Encrypted at rest and in transit, with keys held in a managed KMS apart from the data, to NIST SP 800-57.

AWS KMS · GCP Cloud KMS · rotated on a defined schedule

The key is not stored with the data.
Docs

Environment variablesPreview

Non-secret configuration, set once and scoped per profile. Change a value without touching the pipeline code or redeploying it.

VariableValueApplies to
WAREHOUSEsnowflakeAll profiles
BATCH_SIZE50000prod
LOG_LEVELdebugdev
ORACLE_DSNbicc.internal:1521prod
dlthub env set BATCH_SIZE=50000
Docs

Regions

Choose the EU or the US for the data and compute plane, so pipelines execute where your data is allowed to be.

Data and compute plane on GCP and AWS · control plane in North Virginia

Your data stays in the region you pick.

Audit logsEnterprise

Every action across the organisation, with the person, the target and the time, so a review answers itself instead of becoming a support ticket.

WhoDid whatTo whatWhen
r.okaforRotated secretfinance · prod09:14
m.lindqvistAdded membergrowth · Editor09:02
ci-deployDeployed workspacefinance @ 8f21c4e08:47
a.duboisChanged rolerisk-review · Viewer08:31
Who rotated that secret, and when.
Docs

ConsumptionPreview

Credits are consumed when a pipeline runs, transforms or checks data, and the bill breaks down by workspace, so each team carries what it spends.

WorkspaceCredits this monthShare
finance12,40038%
growth8,60026%
product-analytics7,04022%
sandbox4,58014%
Finance pays for the finance workspace.

Built for your security review

Your pipelines run where you say. The data and compute plane sits in the EU or the US, on AWS and GCP, and you choose which when you create a workspace.

Credentials never live in pipeline code. Each environment holds its own secrets, encrypted at rest with keys in a managed KMS to NIST SP 800-57 and rotated on a defined schedule.

Every plane, control, data, storage and application, runs on its own isolated network with its own security boundary, so a problem in one has nowhere to go.

  • SOC 2 Type 1Certified
  • SOC 2 Type 2In progress. Observation period since 1 August 2026
  • ISO 27001In progress
  • HIPAAIn progress
Trust CenterEvery control, the audit reports, our policies and the subprocessor list, kept current.

Deployment

Your databases never leave your network

Where the execution plane sits decides which networks it can reach. That one choice is the difference between these three.

SaaS + private linksAvailable todayBYOC: computeReference architectureBYOC: data + computeReference architecture
Where it runsControl planeNo customer data passes through itdltHubdltHubdltHub
Data planeCode, secrets, logs, configurationdltHubdltHubYour cloud
Execution planeDecides which networks it can reachdltHub VPCYour cloudYour cloud
Where your data staysYour secretsdltHub data planeNever leave your cloudNever leave your cloud
Code, config, telemetry at restdltHubdltHubYour cloud
Sources and destinationsNever leave your networkNever leave your cloudNever leave your cloud
Private link to your sourcesRequiredNot neededNot needed

Private links over AWS PrivateLink, GCP Private Service Connect or Azure Private Link. We provision the endpoint; a dedicated egress proxy where a static IP is preferred.

Discuss enterprise deployment