Skip to main content
Security & Compliance

We never see your warehouse data

TribeBlend is a local-first desktop app: open-source models run on the analyst's machine, under your existing Unity Catalog permissions. Warehouse data and query results never reach our servers, so most of the security questionnaire answers itself.

Compliance status

Where we stand today

We publish the real state of every control instead of a badge we have not earned.

SOC 2 Type II is in progress

We don't display a certification we haven't completed. Request our security package for the current SOC 2 status, penetration-test summary, and DPA.

SOC 2 Type II

In progress

Audit in progress. Request our security package for current status.

GDPR (EU)

In place

Article 30 record published; DPA available on request.

Encryption in transit

In place

TLS 1.2+ across every endpoint.

Encryption at rest

In place

All stored personal data is encrypted at rest.

MFA, SSO & SCIM

In place

TOTP MFA, SAML/OIDC SSO, and SCIM provisioning.

Audit logging

In place

Security-relevant events are logged and retained.

Databricks remains the execution boundary under Unity Catalog permissions. Selected tables and results can be cached locally; TribeBlend's control plane receives account, license, and audit metadata.

Data handling

What the desktop app sends, and what it never does

Telemetry is opt-in. When it's on, only anonymized signals leave the device.

Opt-in telemetry sends

  • Anonymized usage events

    Which features are used and whether actions succeed, never document contents.

  • Installation UUID

    A random per-install identifier, not tied to a person or a Databricks identity.

  • AI feedback hashes

    Hashed thumbs-up/down signals used to measure answer accuracy over time.

  • Structural SQL patterns

    The shape of generated queries (joins, functions), never literals, filters, or values.

Never leaves your environment

  • Warehouse data and cell values

    Row, column, and cell contents stay in Databricks or on the analyst's device.

  • Query results

    Result sets are never transmitted to TribeBlend.

  • Credentials and tokens

    OAuth tokens live in the OS keychain on the device and are never collected.

Legal basis
Consent: opt-in, switchable in the desktop app
Retention
365 days
Processors
Cloudflare Workers, Turso (EU)

Sub-processors

Every vendor that can touch personal data

The full list, kept in sync with our GDPR Article 30 record. None of them process your Databricks warehouse data.

TribeBlend sub-processors
Sub-processorPurposeData categoriesLocation
TursoPrimary database (accounts, licensing, audit logs, telemetry)Name, email, password hash, machine fingerprints, audit eventsEU
Cloudflare WorkersWebsite and API hosting, telemetry ingestionIP address, anonymized usage eventsGlobal edge
Keygen.shSoftware license activation and validationEmail, organization, machine fingerprints, IP addressUSA (SCCs)
HubSpotSales pipeline and customer relationship managementName, email, company, job title, messageUSA (SCCs)
SlackInternal sales-lead notificationsName, email, company, messageUSA (SCCs)
Cal.comDemo schedulingName, email, meeting detailsUSA (SCCs)
ResendTransactional and marketing email deliveryEmail, nameUSA (SCCs)
Google AnalyticsWebsite usage analysis (consent-gated)Anonymized usage data, IP addressUSA (SCCs)