Zero Trust Architecture for Data Pipelines
Supaflow separates the control plane from the data plane so teams can run pipelines in customer-controlled environments while Supaflow Cloud stores orchestration metadata and encrypted connection metadata.
In customer-controlled deployments, agents run within your AWS account or Snowflake Snowpark Container Services (SPCS) and communicate with Supaflow exclusively via outbound HTTPS polling. No inbound firewall rules, IP allowlists, or SSH access are required.
With VPC or Snowflake-native agents, pipeline records move between your source and destination through that environment. Connector-generated error files may be retained in Supaflow Cloud for troubleshooting under the MSA and DPA.

What This Means in Practice
The security model on this page is designed to answer the questions infrastructure and compliance teams usually ask first: network direction, data residency, and key control.
No inbound access required
The Supaflow Agent polls for work over outbound HTTPS only. The security model does not depend on inbound firewall rules, SSH sessions, or IP allowlists.
Processing in your data plane
Customer-controlled agents move records between your source and destination. Supaflow Cloud coordinates execution and may retain connector-generated error files containing Customer Data for troubleshooting.
Customer-managed keys stay with you
Where customer-managed keys are configured, the agent decrypts sensitive connection settings and credentials locally using keys held in your environment. Those keys do not encrypt retained control-plane error files.
How Supaflow Agent Works
For customer-controlled agents, data flows directly from source to destination.
Agent Polls for Jobs
The Supaflow Agent runs in your AWS environment or Snowflake SPCS and polls Supaflow for work using outbound HTTPS only. No inbound network access is required.
Agent Decrypts Job
Where customer-managed keys are configured, the agent decrypts sensitive connection settings and credentials locally using keys held in your environment.
Agent Runs Pipeline
The agent connects to your configured sources and destinations and executes the pipeline. Supaflow Cloud coordinates execution and may retain connector-generated error files for troubleshooting under the MSA and DPA.
Enterprise Security Features
Zero Trust Architecture
No ingress connections required. Agent polls control plane via HTTPS egress only, ensuring your network perimeter remains secure.
Customer-Managed Encryption
Where customer-managed keys are configured for private agents, the agent decrypts sensitive connection settings and credentials using keys held in your environment.
Data Plane Isolation
Customer-controlled agents process pipeline records in your VPC or Snowflake SPCS. Retained error files may contain Customer Data and remain subject to the applicable MSA and DPA protections.
Control-Plane Storage
Supaflow Cloud stores configuration and operational metadata and may retain connector-generated error files for troubleshooting. Customer Data in those files remains Customer Data.
Tenant Credential Encryption
Customer-managed tenant or workspace keys, where configured, protect sensitive connection settings and credentials. Retained error files use separate provider-managed storage encryption.
Audit Logging
Track pipeline configurations, job executions, and user actions for compliance reviews and operational visibility.
Data Residency & Retention
Lives in Supaflow Cloud
- •Pipeline configurations
- •Lineage metadata
- •User and workspace settings
- •System orchestration data and diagnostic logs
- •Encrypted connection credentials
- •Retained connector-generated error files, which may contain Customer Data
In Your Agent Environment
- Customer-managed keys, where configured
- Pipeline execution and temporary staging
- Access to your configured source and destination
Data handling: Metadata and diagnostic logs can contain sensitive information. Customer Data reproduced in an error file or log remains Customer Data. The DPA applies to Personal Data processed on your behalf, including Personal Data in retained error files. See the MSA and DPA for the applicable terms.
Flexible Deployment Options
AWS VPC Deployment
Deploy Supaflow Agent in your AWS account with full control over networking, IAM, and compute resources. No firewall rules or SSH bastions needed—agent uses standard HTTPS egress.
Snowflake SPCS Native
Run the agent natively in Snowflake Snowpark Container Services for ultimate data gravity and security. Zero infrastructure setup required.
Learn how Snowflake native ETL works →
Watch how to deploy the Supaflow Agent in Snowflake SPCS in minutes
Additional Security Controls
Role-Based Access Control (RBAC)
Strict identity and access management boundaries at workspace and project levels.
Audit Trail
Track pipeline configurations, deployments, and user actions for compliance and operational reviews.
Encryption in Transit & At Rest
Industry-standard TLS encryption for all network communication. Metadata encrypted at rest in our database.
Frequently Asked Questions
Common questions from teams evaluating network, key management, and deployment requirements.
Does customer data pass through Supaflow Cloud?
Does Supaflow require inbound firewall rules or SSH access?
Where do encryption keys live?
How long are troubleshooting error files retained?
What is the status of the SOC 2 examination?
Where can the Supaflow Agent run?
Ready to secure your data pipelines?
Start building with Supaflow's zero trust architecture today.