6 Platforms Supported

Connect Your
Modern Data Stack

Trinitis connects natively to the platforms you already use and writes approved policies into each one's own access controls. Here is exactly what works on each platform today — and what is still on the roadmap.

Available now Planned

Snowflake

Enterprise data cloud with native role-based access controls

  • Discovery
  • Enforcement
  • Column masking
  • Access intelligence
  • Migration import
  • Grant drift detection

Enforcement method:

Native GRANT/REVOKE plus tag-based Dynamic Data Masking policies

Databricks

Unified analytics platform with Unity Catalog

  • Discovery
  • Enforcement
  • Column masking
  • Access intelligence
  • Migration import
  • Grant drift detection

Enforcement method:

Unity Catalog GRANTs plus column masks

BigQuery

Google Cloud serverless data warehouse

  • Discovery
  • Enforcement
  • Column masking
  • Access intelligence
  • Grant drift detection

Enforcement method:

IAM bindings at the dataset and table level

Redshift

AWS cloud data warehouse

  • Discovery
  • Enforcement
  • Column masking
  • Access intelligence
  • Migration import
  • Grant drift detection
  • SSH tunnel support for VPC access

Enforcement method:

Native GRANT/REVOKE plus dynamic data masking policies

PostgreSQL

Open-source relational database

  • Discovery
  • Enforcement
  • Column maskingAmazon Aurora only
  • Access intelligence
  • Grant drift detection
  • SSH tunnel support for secure access

Enforcement method:

Native GRANT/REVOKE, including column-level SELECT. Native column masking on Amazon Aurora (pg_columnmask); column restriction on community and RDS PostgreSQL.

S3/Iceberg

Object storage with Iceberg tables

  • Discovery
  • Enforcement
  • Access intelligence

Enforcement method:

Discovery and metadata visibility only today

Grant drift detection flags grants that were revoked, masks that were removed, and shadow grants created outside Trinitis. It is enabled per account.

How Platform Integration Works

1. Connect

Add credentials via our self-service UI. No manual ARN creation required. Secrets stored securely in AWS Secrets Manager.

2. Discover

Automatic schema scans discover databases, schemas, tables, and columns. Sensitive columns are tagged automatically from their names.

3. Enforce

Define policies once. Trinitis writes them into each platform's native controls — GRANT/REVOKE, masking policies, IAM bindings.

Compare platforms

Available now Planned— Not applicable

PlatformDiscoveryEnforcementColumn maskingAccess intelligenceMigration importGrant drift detection
Snowflake
Available now
Available now
Available now
Available now
Available now
Available now
Databricks
Available now
Available now
Available now
Available now
Available now
Available now
BigQuery
Available now
Available now
Planned
Available now
—Not applicable
Available now
Redshift
Available now
Available now
Available now
Available now
Available now
Available now
PostgreSQL
Available now
Available now
Available now
Available now
—Not applicable
Available now
S3/Iceberg
Available now
Planned
—Not applicable
Planned
—Not applicable
—Not applicable

Ready to connect your data stack?

Get started in under 10 minutes. No complex setup required.