Least-privilege access
- MySQL: a dedicated user with
SELECTon the databases you choose and the two replication privileges needed to read the binary log. It can't change data, schemas or users. - BigQuery: a service account with BigQuery Data Editor and BigQuery Job User only, so no access to other Google Cloud services.
- You can revoke access at any time by dropping the MySQL user or deleting the service-account key.
Your data stays yours
- Row data passes through our workers in memory on its way to BigQuery; we don't keep a copy of it.
- BigQuery tables are created in your own Google Cloud project, under your control and your retention settings.
- We store operational metadata only: table names, row counts, timestamps, binary log positions and error messages, to run and display your pipelines.
Encryption
- Database passwords, service-account keys and your organization's SSH key are encrypted at rest with AES-256-GCM before they are stored.
- Private databases can be reached through your SSH bastion; the bastion's host key is pinned on first connection so a different server is refused.
- Connections to MySQL use TLS whenever the server supports it (required on Azure); BigQuery APIs are always called over TLS.
- Account passwords are stored as bcrypt hashes.
Isolation and access control
- Every request is scoped to your organization; no query can read another organization's pipelines or credentials.
- Admin and member roles control who can manage your team.
- BigQuery tables are labelled with the pipeline that owns them, and Quayen refuses to modify or delete tables it didn't create.
Reliability
- Progress is saved only after BigQuery accepts each batch, so a restart resumes exactly where it left off.
- If changes ever wait longer than your change-history retention allows, the affected table is re-copied automatically rather than left with a gap.
Report a vulnerability
Email support@quayen.com.