Why Genedata · SecurityGENEDATA / 01

Security you can show an auditor.

On a fragmented stack, access policy lives in five admin consoles and the audit trail is reassembled from five log formats. On Genedata the policy is enforced where the query runs, secrets are encrypted in the same platform that uses them, and one append-only log records every grant, read, and rotation — so the evidence an auditor asks for is a query, not a project.

Shared context · Lineage · Governance
Connected
Your sources
Data sources
Business context
Policy & access
Connected intelligenceGenedata
Governance
Business impactDecisions & action
Shared contextLineageGovernance
+Illustrative workflow01 / 03
1 / 3
01

Row- and column-level security

Policies are attached to the dataset and enforced by Cortex SQL at query time, so the same rule applies in a dashboard, a notebook, and an agent answer. Column masking and row filters follow the data through lineage.

02

Secrets, encrypted and rotated

Connector credentials are encrypted at rest with AES-256, carried over TLS 1.3, and never shown back in plain text. Rotation is scheduled per secret and recorded in the audit log.

03

An audit trail that holds up

Every grant, query, policy change, and secret rotation is written to an append-only log and retained for seven years under object lock. Export a scoped slice for an auditor without giving them the console.

The control loop

Grant, enforce, log, review, rotate — in one system.

Access is granted against a dataset, enforced at the row and column on every read, written to the audit log, reviewed on a schedule, and the secrets behind it rotated — with each step recorded by the same platform. An auditor can follow any one grant around the whole loop.

One audit logseven-year retention1Grantrole → dataset2Enforcerow / column at query3Logappend-only event4Reviewscheduled access review5Rotatesecrets on a schedule
AES-256 + TLS 1.3Encryption
7 yearsAudit retention
At query timePolicy enforcement
Controls mappedCompliance
The next step

Controls mapped, not badges claimed.

We describe our position as controls mapped to the frameworks customers ask about, with the mapping published and the evidence behind each control exportable from the audit log. The compliance page lists the frameworks and the current status of each. We do not describe the platform as certified.

FAQ

Security, answered.

What a security reviewer asks in the first call.

Where is access policy enforced?

In the query engine. A row filter or column mask is attached to the dataset in GeneCatalog and applied by Cortex SQL on every read, whichever surface issued it — a dashboard, a notebook, a shared dataset, or a Cortex AI agent. There is no separate policy copy in the BI layer to drift out of sync.

How are connector credentials stored?

Encrypted at rest with AES-256 using keys the platform manages per workspace, and sent to the source over TLS 1.3. Credentials are write-only in the UI: you can replace or rotate them but never read them back. Each rotation is an audit event.

What is in the audit log, and for how long?

Grants and revocations, policy changes, every query with its principal and the datasets it touched, pipeline releases and rollbacks, and secret rotations. Entries are append-only and retained for seven years under object lock. You can export a scoped time range or principal for an auditor.

Are you certified against SOC 2 or ISO 27001?

We describe our position as controls mapped, not certified. The compliance page lists each framework we map to, the control mapping, and the current status, and we keep that page as the single source of truth rather than restating it in marketing copy.

The argument, complete

One engine, one record, one monitor, one audit log.

Four proofs of the same point: a platform that owns the seams lets a small team run what used to take five tools and five vendors. See the frameworks we map to, or go back to where the argument starts.