Trust

Trust center

Everything a security review needs, in one place. dvt pushes queries down to your warehouse and returns only the rows needed to render a chart, so your data rows and values never have to live in our infrastructure. Here's how we back that up.

Data handling at a glance

dvt never hosts your data rows or values

Queries run in your warehouse, on your compute. Only result rows return, in memory, and they're discarded after rendering: never persisted to our database.

Credentials stay encrypted

Warehouse credentials are envelope-encrypted; our database holds only ciphertext, and the key that unwraps them never leaves the engine tier.

Least-privilege access

Capability-based roles gate every action, every record is scoped to an organization, and sensitive actions land in an append-only audit log.

Retention, stated plainly

When a user's account is deleted or an organization closes, their account details — email, name, avatar — are de-identified after 90 days. Image exports have no deletion schedule — they're retained until you ask us to delete them, and we'd rather say that than imply a timetable we don't run. A couple of records outlive that scrub, such as a scheduled-export recipient address or a note in a change history; the privacy policy has the detail, and we remove them on request.

Catalog structure is opt-in

An org admin can opt a connection into catalog sync, off by default per connection. It stores names/types/comments only, never data rows or values, and turning it back off deletes the synced structure immediately. See the security overview for the full boundary.

Compliance roadmap

We hold continuous, evidence-backed readiness and pursue formal certification when a deal calls for it: readiness now, audit on demand.

  • SOC 2: readiness now, audit on trigger. dvt is not yet SOC 2 audited. Our controls map to the SOC 2 Common Criteria, and our CI produces a continuous, timestamped evidence trail. We'll commission a formal Type II audit when an enterprise engagement calls for it.
  • Continuous security testing. Static analysis, dependency and secret scanning, and a layered dynamic-testing pyramid run on every change; see the security overview for the full program.
  • Penetration testing. We don't have a third-party pentest under contract yet; automated testing doesn't replace one, and we'll commission it when an enterprise engagement calls for it.

Need a DPA, a security questionnaire completed, or a call with our team? Emailsecurity@dvt.dev.