New: Supaflow AI Plugin -- build, run, and monitor data pipelines from the ChatGPT app. Install the plugin

Zero Trust Architecture for Data Pipelines

Supaflow separates the control plane from the data plane so teams can run pipelines in customer-controlled environments while Supaflow Cloud stores orchestration metadata and encrypted connection metadata.

In customer-controlled deployments, agents run within your AWS account or Snowflake Snowpark Container Services (SPCS) and communicate with Supaflow exclusively via outbound HTTPS polling. No inbound firewall rules, IP allowlists, or SSH access are required.

With VPC or Snowflake-native agents, pipeline records move between your source and destination through that environment. Connector-generated error files may be retained in Supaflow Cloud for troubleshooting under the MSA and DPA.

Supaflow Security Architecture Diagram

What This Means in Practice

The security model on this page is designed to answer the questions infrastructure and compliance teams usually ask first: network direction, data residency, and key control.

No inbound access required

The Supaflow Agent polls for work over outbound HTTPS only. The security model does not depend on inbound firewall rules, SSH sessions, or IP allowlists.

Processing in your data plane

Customer-controlled agents move records between your source and destination. Supaflow Cloud coordinates execution and may retain connector-generated error files containing Customer Data for troubleshooting.

Customer-managed keys stay with you

Where customer-managed keys are configured, the agent decrypts sensitive connection settings and credentials locally using keys held in your environment. Those keys do not encrypt retained control-plane error files.

How Supaflow Agent Works

For customer-controlled agents, data flows directly from source to destination.

1

Agent Polls for Jobs

The Supaflow Agent runs in your AWS environment or Snowflake SPCS and polls Supaflow for work using outbound HTTPS only. No inbound network access is required.

2

Agent Decrypts Job

Where customer-managed keys are configured, the agent decrypts sensitive connection settings and credentials locally using keys held in your environment.

3

Agent Runs Pipeline

The agent connects to your configured sources and destinations and executes the pipeline. Supaflow Cloud coordinates execution and may retain connector-generated error files for troubleshooting under the MSA and DPA.

Enterprise Security Features

Zero Trust Architecture

No ingress connections required. Agent polls control plane via HTTPS egress only, ensuring your network perimeter remains secure.

Customer-Managed Encryption

Where customer-managed keys are configured for private agents, the agent decrypts sensitive connection settings and credentials using keys held in your environment.

Data Plane Isolation

Customer-controlled agents process pipeline records in your VPC or Snowflake SPCS. Retained error files may contain Customer Data and remain subject to the applicable MSA and DPA protections.

Control-Plane Storage

Supaflow Cloud stores configuration and operational metadata and may retain connector-generated error files for troubleshooting. Customer Data in those files remains Customer Data.

Tenant Credential Encryption

Customer-managed tenant or workspace keys, where configured, protect sensitive connection settings and credentials. Retained error files use separate provider-managed storage encryption.

Audit Logging

Track pipeline configurations, job executions, and user actions for compliance reviews and operational visibility.

Data Residency & Retention

Lives in Supaflow Cloud

  • •Pipeline configurations
  • •Lineage metadata
  • •User and workspace settings
  • •System orchestration data and diagnostic logs
  • •Encrypted connection credentials
  • •Retained connector-generated error files, which may contain Customer Data

In Your Agent Environment

  • Customer-managed keys, where configured
  • Pipeline execution and temporary staging
  • Access to your configured source and destination

Data handling: Metadata and diagnostic logs can contain sensitive information. Customer Data reproduced in an error file or log remains Customer Data. The DPA applies to Personal Data processed on your behalf, including Personal Data in retained error files. See the MSA and DPA for the applicable terms.

Flexible Deployment Options

AWS VPC Deployment

Deploy Supaflow Agent in your AWS account with full control over networking, IAM, and compute resources. No firewall rules or SSH bastions needed—agent uses standard HTTPS egress.

Snowflake SPCS Native

Run the agent natively in Snowflake Snowpark Container Services for ultimate data gravity and security. Zero infrastructure setup required.

Learn how Snowflake native ETL works →

Watch how to deploy the Supaflow Agent in Snowflake SPCS in minutes

Additional Security Controls

Role-Based Access Control (RBAC)

Strict identity and access management boundaries at workspace and project levels.

Audit Trail

Track pipeline configurations, deployments, and user actions for compliance and operational reviews.

Encryption in Transit & At Rest

Industry-standard TLS encryption for all network communication. Metadata encrypted at rest in our database.

Frequently Asked Questions

Common questions from teams evaluating network, key management, and deployment requirements.

Does customer data pass through Supaflow Cloud?
Customer-controlled agents move pipeline records between your source and destination. Supaflow Cloud stores orchestration and connection metadata and may retain connector-generated error files containing Customer Data for troubleshooting. Those files remain subject to the applicable MSA and DPA protections.
Does Supaflow require inbound firewall rules or SSH access?
No. The Supaflow Agent polls for work using outbound HTTPS only. No inbound firewall rules, IP allowlists, or SSH access are required.
Where do encryption keys live?
Where customer-managed keys are configured for private agents, credential-encryption keys are held in the agent keystore or Snowflake secret. These keys protect sensitive connection settings and credentials. Retained control-plane error files use provider-managed encryption at rest and TLS in transit.
How long are troubleshooting error files retained?
Error files are subject to automated deletion once the associated processing has ended and the relevant processing record is more than 14 days old, subject to DPA Section 12. Failed deletions are retried. Files containing Customer Data remain in the customer-selected processing region. Customer Metadata and diagnostic logs follow separate retention schedules.
What is the status of the SOC 2 examination?
Supaflow is undergoing an independent SOC 2 Type 2 examination. The resulting report has not been issued, and its issuance date has not been confirmed. Once available, the report or a summary will be provided on request in accordance with the applicable agreement, including DPA Section 13.
Where can the Supaflow Agent run?
The Supaflow Agent can run in your AWS VPC or in Snowflake Snowpark Container Services.

Ready to secure your data pipelines?

Start building with Supaflow's zero trust architecture today.