Row- and column-level security
Policies are attached to the dataset and enforced by Cortex SQL at query time, so the same rule applies in a dashboard, a notebook, and an agent answer. Column masking and row filters follow the data through lineage.
On a fragmented stack, access policy lives in five admin consoles and the audit trail is reassembled from five log formats. On Genedata the policy is enforced where the query runs, secrets are encrypted in the same platform that uses them, and one append-only log records every grant, read, and rotation — so the evidence an auditor asks for is a query, not a project.
Policies are attached to the dataset and enforced by Cortex SQL at query time, so the same rule applies in a dashboard, a notebook, and an agent answer. Column masking and row filters follow the data through lineage.
Connector credentials are encrypted at rest with AES-256, carried over TLS 1.3, and never shown back in plain text. Rotation is scheduled per secret and recorded in the audit log.
Every grant, query, policy change, and secret rotation is written to an append-only log and retained for seven years under object lock. Export a scoped slice for an auditor without giving them the console.
Access is granted against a dataset, enforced at the row and column on every read, written to the audit log, reviewed on a schedule, and the secrets behind it rotated — with each step recorded by the same platform. An auditor can follow any one grant around the whole loop.
We describe our position as controls mapped to the frameworks customers ask about, with the mapping published and the evidence behind each control exportable from the audit log. The compliance page lists the frameworks and the current status of each. We do not describe the platform as certified.
What a security reviewer asks in the first call.
In the query engine. A row filter or column mask is attached to the dataset in GeneCatalog and applied by Cortex SQL on every read, whichever surface issued it — a dashboard, a notebook, a shared dataset, or a Cortex AI agent. There is no separate policy copy in the BI layer to drift out of sync.
Encrypted at rest with AES-256 using keys the platform manages per workspace, and sent to the source over TLS 1.3. Credentials are write-only in the UI: you can replace or rotate them but never read them back. Each rotation is an audit event.
Grants and revocations, policy changes, every query with its principal and the datasets it touched, pipeline releases and rollbacks, and secret rotations. Entries are append-only and retained for seven years under object lock. You can export a scoped time range or principal for an auditor.
We describe our position as controls mapped, not certified. The compliance page lists each framework we map to, the control mapping, and the current status, and we keep that page as the single source of truth rather than restating it in marketing copy.
Four proofs of the same point: a platform that owns the seams lets a small team run what used to take five tools and five vendors. See the frameworks we map to, or go back to where the argument starts.