Security
Is it safe to connect your warehouse? Here is our posture
Datatrail is built to be the lowest-risk tool a data team can plug in. We connect with least-privilege, read-only access to your query history and metadata only, we encrypt your data in transit and at rest, and we never move, copy, or mutate anything in your warehouse.
In short
Yes. Datatrail requests the minimum read-only scopes to see your query history and metadata, such as a read-only role on Snowflake ACCOUNT_USAGE or a read-only BigQuery viewer role. It reads only metadata and query logs to build lineage. It never ingests row-level data, cannot change anything in your warehouse, and cannot move, copy, or mutate your data. Data is encrypted in transit and at rest, credentials are least-privilege and scoped, and you can revoke access at any time.
Security posture
Read-only by design, metadata-only on purpose
Every choice below is made so a data team can connect Datatrail without expanding their attack surface or handing anyone the ability to change a table.
Read-only access
We request the minimum read scopes only: a read-only role on Snowflake ACCOUNT_USAGE, a read-only BigQuery viewer role, or the equivalent on Redshift, Postgres, or dbt. Datatrail cannot write a table, alter a schema, or run a destructive query. It reads, it maps, your team acts.
We never move your data
Datatrail never ingests row-level data, copies your tables, or mutates anything. It reads metadata and query history to build lineage. There is no write path, so even a worst-case compromise cannot change a row of yours.
Encryption in transit and at rest
All data is encrypted in transit with TLS and encrypted at rest. Credentials and tokens are stored encrypted and are never exposed in logs or to other tenants.
Least-privilege, scoped credentials
Connections use scoped, least-privilege credentials with the narrowest permissions that still let us read your query history and metadata. We do not ask for write or admin scopes we do not need.
Revoke access anytime
You can disconnect any source and revoke our access at any moment from your own warehouse console. Access is yours to grant and yours to remove.
Metadata-only lineage
Lineage is built from metadata and query logs, not from your row-level data. We are deliberate about where this metadata is processed and stored, and enterprise customers can scope data residency and request a security review and custom terms.
Scope
What we read, and what we never do
What we read
- Query history and access history (Snowflake QUERY_HISTORY, BigQuery, Redshift, Postgres)
- Table, column, and schema metadata, so we can map lineage
- dbt models and run results, so lineage reaches past the dbt boundary
- Freshness timestamps and schema versions, to flag stale tables and drift
What we never do
- Ingest, copy, or store your row-level data
- Write, alter, or drop a table or run a destructive query
- Mutate anything in your warehouse
- Request write or admin scopes we do not need
Datatrail is read-only decision support. Every finding is for a human on your team to review and act on in your own warehouse.
Security questions
The questions data teams ask first
Yes. Datatrail connects read-only. It reads your query history and metadata to build lineage, and it never moves, copies, or mutates your data. It does not need write access and it does not ingest row-level data to map how tables and columns flow. You can revoke access at any time. Read-only by design is the whole point.
Lineage maps automatically in minutes from your query history. There is no manual diagramming, no months-long rollout, and no need to annotate every model by hand. The first pass surfaces your table and column flow, freshness state, and recent schema changes right away.
Yes. Datatrail traces a single column through every transformation, from its source table to the dashboards that use it. You can answer exactly what feeds a number and what would break if that column changed, not just which tables touch which tables.
Snowflake, BigQuery, Redshift, Postgres, and dbt, with read-only connections to query history and metadata. Datatrail parses real query logs, so it maps lineage past the dbt boundary and stays current even when someone writes ad-hoc SQL.
More on accuracy, privacy, and what we connect on the full FAQ.
The lowest-risk tool to plug in
Connect your warehouse read-only and see your lineage map itself. We never move or mutate your data, and you can revoke access anytime.