Skip to Content
SecurityOverview

Security

Zeotap is designed with a security-first architecture. The warehouse-native approach means your customer data stays in infrastructure you control, and Zeotap’s role is to orchestrate — not store — your data. This section covers how Zeotap handles data, protects credentials, maintains audit trails, and supports compliance requirements.

Security Principles

Warehouse-Native by Design

Zeotap’s most important security property is architectural: your customer data lives in your data warehouse, not in Zeotap. All computation — computed attribute evaluation, audience building, identity resolution — happens as SQL queries executed against your warehouse. Zeotap stores metadata (model definitions, audience configurations, sync schedules) but not your customer records.

Least Privilege Access

Zeotap connects to your warehouse with the credentials you provide. We recommend creating a dedicated service account with read-only access to the specific schemas containing customer data. Zeotap only needs write access to its own operational schemas (CDP_PLANNER, CDP_AUDIT).

Encryption Everywhere

All data in transit is encrypted with TLS 1.2+. Warehouse and destination credentials are never held in Zeotap’s metadata database — they are written to a secret manager and referenced by name, so the database holds a pointer rather than the secret. API keys are stored as SHA-256 hashes and cannot be retrieved after creation.

Complete Audit Trail

Every user action, API call, sync run, and AI operation is logged with the actor, action, resource, and timestamp. Audit logs are written to both Zeotap’s internal store and your warehouse’s audit schema, giving you full visibility and the ability to query audit data with SQL.

Security Topics

TopicDescription
Data HandlingHow Zeotap processes, stores, and protects data across the platform
ComplianceGDPR, CCPA, SOC 2 compliance support and governance features

Security Architecture Overview

Security architecture: data stays in your infrastructure

Key Security Features

FeatureDescription
Encryption in transitTLS 1.2+ for all connections — browser, warehouse, destinations, internal services
Credential storageHeld in a secret manager, separate from the metadata database, which stores only the reference. On Google Cloud that is Secret Manager, which encrypts at rest
API key hashingSHA-256 — keys are shown only once at creation, and support rotation and expiry
Audit loggingEvery user action logged with actor, action, resource, timestamp, and source (UI, API, AI)
RBACFine-grained role-based access control with 120 permissions across 43 resource categories
Access policiesRow-level access control for team-based data isolation
Destination policiesGovernance policies controlling which data flows to which destinations
AI guardrailsSafety boundaries for AI-initiated operations with approval workflows

Quick Security Facts

QuestionAnswer
Where does customer data live?In your data warehouse. Zeotap queries it but doesn’t copy it.
What data leaves the warehouse?Only activation data sent to destinations: audience member identifiers and mapped fields.
How are credentials stored?In a secret manager, referenced by name from the metadata database. Never logged, never returned by the API, and redacted in the audit log.
How are API keys secured?Stored as a SHA-256 hash, which is what an incoming key is matched against. The full key is shown only once at creation, and keys can be rotated and given an expiry.
What’s logged?Every user action, API call, sync run, and AI operation with actor, action, resource, and timestamp.
What encryption is used in transit?TLS 1.2+ for all connections.
Is SOC 2 supported?Yes. Zeotap provides audit trails, access controls, and monitoring capabilities that support SOC 2 Type II compliance.
Is GDPR supported?Yes. Warehouse-native architecture, data minimization, right to deletion, and consent management support GDPR requirements.
  • Data Handling — Detailed data processing and protection practices
  • Compliance — Regulatory compliance support
  • Govern — RBAC, destination policies, and access policies
  • AI Guardrails — Safety controls for AI operations
Last updated on