Six Layers. No Exceptions.
Metadata only
Altimate never reads, stores, or processes your actual data. Only metadata — table names, schemas, query shapes — enters the platform. Your data stays in your environment.
Multi-tenant isolation
Every customer instance gets its own isolated environment with a unique URL. No shared compute, no shared storage between tenants.
Encryption everywhere
All metadata is encrypted in transit (TLS 1.2+) and at rest using AES-256 via our cloud providers. Keys are rotated automatically.
Human approval on critical steps
Agents operating on production systems require explicit human sign-off before executing write actions. No autonomous mutation without governance clearance.
Customer-configurable guardrails
Define your own security perimeter: which warehouses agents can touch, which schemas are off-limits, which actions require dual approval.
LLM isolation
We do not use customer data or metadata to train any LLM. Prompts are scoped to the session and never persisted to model providers.
Your Data Never Leaves Your Environment
When an agent analyses your Snowflake warehouse, it reads query execution plans, cost metadata, and schema definitions — not your actual rows. The same principle applies across every integration: Airflow, dbt, Databricks, GitHub. Shape, not substance.
Write actions (query changes, pipeline edits, warehouse config updates) are gated by governance guardrails and, where configured, human approval workflows. Agents don't act on production systems without clearance.