Security

What Trinitis can access, what it stores, and how it protects it — stated plainly so your security team can evaluate it.

The SELECT privilege

On Snowflake, Databricks, Redshift and PostgreSQL, column discovery requires the SELECT privilege. These platforms expose no metadata-only option, so the grant that reveals column metadata is the same grant that can read rows.

BigQuery is the exception: roles/bigquery.metadataViewer exposes column metadata with data reads denied.

PlatformNeeded for column discoveryWhat the credential could do
SnowflakeSELECTCan read rows
DatabricksSELECTCan read rows
RedshiftSELECTCan read rows
PostgreSQLSELECTCan read rows
BigQueryroles/bigquery.metadataViewerData reads denied

What this means

Trinitis reads only schema and column metadata and stores no row values. But the credential you grant is capable of reading data, and you should evaluate it on that basis.

What Trinitis stores

  • Schema, table and column names, and tags
  • Existing grants, and the policies you draft and approve
  • Group and role membership
  • Query history for the audit trail, with real data values stripped

Trinitis stores no customer data values and does not sample column contents. Sensitive columns are classified from their names, not their contents.

Architecture

  • No proxy in your query path — Trinitis writes approved policies into each platform's native controls.
  • Platform credentials are stored in AWS Secrets Manager, encrypted with AWS KMS.
  • Hosted in the United States — AWS us-east-1 (N. Virginia).
  • Encrypted at rest with AES-256 via AWS KMS.
  • Encrypted in transit with TLS 1.2+.

More detail

Retention and subprocessors are covered in the Privacy Policy and DPA. Compliance status is on the Trust page.