The short version: EngineFresh reads your warehouse, it doesn't copy it. Here's the longer version, including what that means for access, storage, and compliance.
EngineFresh never holds a copy of your event data. Every chart, funnel, and alert is a read-only query against your warehouse, run inside your own cloud environment's boundary.
You grant access to specific schemas and tables. EngineFresh can't write, delete, or reach anything outside that scope.
Revoke warehouse access at any time from your provider's console. Access stops immediately, no support ticket required.
You can review exactly what EngineFresh queried and when, both from your own warehouse's query history and from ours.
Connections to your warehouse are encrypted in transit. Any credentials we hold are encrypted at rest and scoped to the minimum required.
Your account and team info, dashboard and metric definitions, alert rules and their history, and metadata about when queries ran.
Your event data, row-level records from your tables, and warehouse credentials, which are encrypted at rest rather than kept in plain text.
Access to customer data is a small-team problem right now, which cuts both ways: fewer people touch it, and there's less process standing between you and an answer if you have a question.
Access to a customer's warehouse connection or dashboard configuration is scoped to the engineers actively working on that account, not open by default across the team.
Warehouse credentials are stored encrypted and used by the system to run scheduled queries. They aren't handed to individual engineers to query manually.
If a security incident could affect your account or warehouse access, we aim to notify affected design partners directly within 72 hours of confirming it, not leave you to find out from a status page.
We're early. Here's an honest picture of where our compliance program actually stands, not where we'd like it to be.
Working closely with our first customers to harden the product before wider release.
Currently underway alongside the design partner program, targeting early 2027.
Under evaluation as a next step once SOC 2 is complete.
Live status and compliance documentation, once we're further along.
We're keeping our infrastructure footprint deliberately small while we're in early access. A full subprocessor list will be published here ahead of general availability. If you need it sooner as part of a security review, mention that in your early access request and we'll share it directly.
If you've found a security issue, let us know through our early access form and mention that it's a security report. We'll prioritize it and follow up directly.
We're happy to walk through any of this in more detail before you send us access.
Request early access