Security

Enterprise analytics without giving up data control.

Dataforge emphasizes controlled deployment, role-aware answers, read-only query safety, and evidence users can inspect.

SELECT allowed
UPDATE blocked
DELETE blocked
RBACRead replicaSource tracking

Controls

Security capabilities are framed without unverified certifications.

Data sovereignty by deployment model

Final wording should match the implemented production system.

SELECT-only / read-only query safety as intended behavior

Final wording should match the implemented production system.

Read-replica isolation where configured

Final wording should match the implemented production system.

Role-based access to authorized answers

Final wording should match the implemented production system.

Question, query, source, and access logs where supported

Final wording should match the implemented production system.

Private deployment for controlled environments

Final wording should match the implemented production system.

Query Safety

Read-only analytics with visible gates.

The blocked path shows what Dataforge should not execute.

FAQ

Questions security teams naturally ask.

Does Dataforge modify production data?

Dataforge is positioned for read-only analytics. Final safeguards should be validated in the deployment design.

Can Dataforge run without internet access?

Air-gapped and on-premise options are listed for stricter infrastructure control.

Does data leave our environment?

That depends on deployment. Private VPC and on-premise models are designed for stronger data control.

How are user permissions enforced?

Access should be scoped by role, source, and approved business rules.

Can users inspect generated queries?

Yes. The product experience centers SQL, source tables, filters, and answer evidence.

Can Dataforge connect to a read replica?

Read-replica support is part of the security positioning and should be validated during POC.

Bring your security team into the evaluation.