We never see your warehouse data
TribeBlend is a local-first desktop app: open-source models run on the analyst's machine, under your existing Unity Catalog permissions. Warehouse data and query results never reach our servers, so most of the security questionnaire answers itself.
Compliance status
Where we stand today
We publish the real state of every control instead of a badge we have not earned.
SOC 2 Type II is in progress
We don't display a certification we haven't completed. Request our security package for the current SOC 2 status, penetration-test summary, and DPA.SOC 2 Type II
In progress
Audit in progress. Request our security package for current status.
GDPR (EU)
In place
Article 30 record published; DPA available on request.
Encryption in transit
In place
TLS 1.2+ across every endpoint.
Encryption at rest
In place
All stored personal data is encrypted at rest.
MFA, SSO & SCIM
In place
TOTP MFA, SAML/OIDC SSO, and SCIM provisioning.
Audit logging
In place
Security-relevant events are logged and retained.
Databricks remains the execution boundary under Unity Catalog permissions. Selected tables and results can be cached locally; TribeBlend's control plane receives account, license, and audit metadata.
Data handling
What the desktop app sends, and what it never does
Telemetry is opt-in. When it's on, only anonymized signals leave the device.
Opt-in telemetry sends
Anonymized usage events
Which features are used and whether actions succeed, never document contents.
Installation UUID
A random per-install identifier, not tied to a person or a Databricks identity.
AI feedback hashes
Hashed thumbs-up/down signals used to measure answer accuracy over time.
Structural SQL patterns
The shape of generated queries (joins, functions), never literals, filters, or values.
Never leaves your environment
Warehouse data and cell values
Row, column, and cell contents stay in Databricks or on the analyst's device.
Query results
Result sets are never transmitted to TribeBlend.
Credentials and tokens
OAuth tokens live in the OS keychain on the device and are never collected.
- Legal basis
- Consent: opt-in, switchable in the desktop app
- Retention
- 365 days
- Processors
- Cloudflare Workers, Turso (EU)
Sub-processors
Every vendor that can touch personal data
The full list, kept in sync with our GDPR Article 30 record. None of them process your Databricks warehouse data.
| Sub-processor | Purpose | Data categories | Location |
|---|---|---|---|
| Turso | Primary database (accounts, licensing, audit logs, telemetry) | Name, email, password hash, machine fingerprints, audit events | EU |
| Cloudflare Workers | Website and API hosting, telemetry ingestion | IP address, anonymized usage events | Global edge |
| Keygen.sh | Software license activation and validation | Email, organization, machine fingerprints, IP address | USA (SCCs) |
| HubSpot | Sales pipeline and customer relationship management | Name, email, company, job title, message | USA (SCCs) |
| Slack | Internal sales-lead notifications | Name, email, company, message | USA (SCCs) |
| Cal.com | Demo scheduling | Name, email, meeting details | USA (SCCs) |
| Resend | Transactional and marketing email delivery | Email, name | USA (SCCs) |
| Google Analytics | Website usage analysis (consent-gated) | Anonymized usage data, IP address | USA (SCCs) |