Six Layers. No Exceptions.
Metadata only
Altimate never reads, stores, or processes your actual data. Only metadata — table names, schemas, query shapes — enters the platform. Your data stays in your environment.
Multi-tenant isolation
Every customer instance gets its own isolated environment with a unique URL. No shared compute, no shared storage between tenants.
Encryption everywhere
All metadata is encrypted in transit (TLS 1.2+) and at rest using AES-256 via our cloud providers. Keys are rotated automatically.
Human approval on critical steps
Agents operating on production systems require explicit human sign-off before executing write actions. No autonomous mutation without governance clearance.
Customer-configurable guardrails
Define your own security perimeter: which warehouses agents can touch, which schemas are off-limits, which actions require dual approval.
LLM isolation
We do not use customer data or metadata to train any LLM. Prompts are scoped to the session and never persisted to model providers.
Your Data Never Leaves Your Environment
When an agent analyses your Snowflake warehouse, it reads query execution plans, cost metadata, and schema definitions — not your actual rows. The same principle applies across every integration: Airflow, dbt, Databricks, GitHub. Shape, not substance.
Write actions (query changes, pipeline edits, warehouse config updates) are gated by governance guardrails and, where configured, human approval workflows. Agents don't act on production systems without clearance.
Common Questions
We do not use actual data for any Altimate AI features. We use only metadata e.g. table names, column schemas, query shapes. Your data never leaves your environment.
No. We do not train any LLM using customer data or metadata.
Our agents are calibrated with confidence thresholds. They proceed autonomously at high confidence, present options at medium confidence, and escalate below a minimum threshold rather than guessing. You can always see the agent's reasoning trace.
Yes. Altimate AI is SOC 2 Type II certified. Certification documentation is available under NDA upon request.
Yes. Enterprise customers can deploy Altimate in a VPC or on-premise environment. Contact us to discuss your architecture requirements.
More questions? Check the documentation or contact our security team.