Security & Architecture

Alethiom deploys in your cloud account. We operate it through a role you grant — and can revoke.

That’s the pattern under review. This page enumerates the rest: what runs in your account, what moves and what never moves, and the controls that stay in your hands — the logs you can read, the access you can revoke.

Data flow

Where data lives, what moves, what never moves.

There is no vendor-side data store: customer data is never copied to an Alethiom cloud. The whole product runs inside your account — the UI your team opens, the APIs behind it, the AI service, the sync workers — so query results flow from your cloud straight to your users’ browsers. One outbound channel reaches Alethiom — configuration, health, and billing metering, never customer data.

data plane
Event sourcesvendor exports · CDP · server-side streams — however your pipeline works today
your cloud account
Your warehousesystem of record
Alethiom deploymentengine · UI · APIs
sync workers
Your team’s browsersquery results, passed securely

what moves: bounded, scheduled sync queries from warehouse to serving layer, using your warehouse’s native CDC capabilities (inside the account)
what never moves: customer event data, to Alethiom or anyone else

Deployment model

One stack, one role, revocable at any time.

  1. You run one infrastructure stack from us. It creates one scoped role in your account, granted to us — that role is the entire surface of Alethiom’s access.
  2. Through that role, we build and operate the Alethiom stack inside your account: provisioning, upgrades, monitoring, incident response. You never operate our software; you host it.
  3. You can revoke access at any time. Revocation cuts our access immediately; your data was never anywhere else to begin with.
Ships as
Alethiom ships one way: managed, inside your cloud account. AWS and GCP today; Azure coming soon.
Warehouse access
Snowflake and BigQuery today; Databricks coming soon. A read-only role you grant, scoped to the datasets you choose. Only scheduled sync queries touch the warehouse — native CDC, as often as every 15 minutes, with record-level appends, edits, and deletes all supported. Interactive queries never reach it.
Operations
Our access runs through roles and credentials that you grant and can revoke; your cloud’s audit logs record our infrastructure actions.
Encryption
TLS in transit; at rest under your cloud’s storage encryption. The warehouse credential is stored encrypted inside your account and never leaves it.

The stack

What runs in your account.

Everything below runs inside your account. These are the components — all inspectable:

ClickHouse
The serving layer: open-source, columnar — a disposable cache built from your warehouse, stored in sequence order and sharded by person, with sessions, stitching, and attribution computed at query time. Rebuildable at any time; the warehouse stays the system of record. Deletes and updates propagate on the next sync — deletion and update requests are honored in one place: your warehouse.
Postgres
Metadata: definitions, boards, saved work, configuration.
Keycloak
Authentication, federating your identity provider — your SSO, your MFA policy, your deprovisioning. Alethiom holds no separate password store.
Application services
The UI your team opens, the APIs behind it, the AI service, the sync workers.

AI posture

AI on your terms — including “off.”

The AI analyst is opt-in with a real kill switch. Not buried, not defaulted on, not “contact support to disable.”

AI off

Zero model-provider traffic; the only outbound channel is the operations endpoint.

Everything else in the product works exactly the same.

AI on

Model calls run under commercial API terms that are processing-never-training — your data is never used to train anyone’s models.

Prefer your own agreement? Bring your own Anthropic key: AI runs under the model-provider contract you negotiated.

When AI is on, every answer it gives is a traceable query — the same governed layer your team uses, with the same permissions as the person asking.

Compliance

We claim only what we hold.

You won’t find a badge wall here. We state our actual certification posture on request, in writing — and we’d rather say “in progress” plainly than imply something we can’t hand you an audit report for. Ask us and we’ll send the current list, dated.

Questions this page didn’t answer?

Send them over — unpolished answers from the people who built it. Or book a demo and bring your security reviewer along; we’d genuinely rather have them in the room.

Talk to usBook a demobooking link — GTM open item