Security

How we protect your data

Quayen needs access to two of your most important systems. Here is exactly what that access is, and how it's protected.

Last updated October 4, 2026

Least-privilege access

  • MySQL: a dedicated user with SELECT on the databases you choose and the two replication privileges needed to read the binary log. It can't change data, schemas or users.
  • BigQuery: a service account with BigQuery Data Editor and BigQuery Job User only, so no access to other Google Cloud services.
  • You can revoke access at any time by dropping the MySQL user or deleting the service-account key.

Your data stays yours

  • Row data passes through our workers in memory on its way to BigQuery; we don't keep a copy of it.
  • BigQuery tables are created in your own Google Cloud project, under your control and your retention settings.
  • We store operational metadata only: table names, row counts, timestamps, binary log positions and error messages, to run and display your pipelines.

Encryption

  • Database passwords, service-account keys and your organization's SSH key are encrypted at rest with AES-256-GCM before they are stored.
  • Private databases can be reached through your SSH bastion; the bastion's host key is pinned on first connection so a different server is refused.
  • Connections to MySQL use TLS whenever the server supports it (required on Azure); BigQuery APIs are always called over TLS.
  • Account passwords are stored as bcrypt hashes.

Isolation and access control

  • Every request is scoped to your organization; no query can read another organization's pipelines or credentials.
  • Admin and member roles control who can manage your team.
  • BigQuery tables are labelled with the pipeline that owns them, and Quayen refuses to modify or delete tables it didn't create.

Reliability

  • Progress is saved only after BigQuery accepts each batch, so a restart resumes exactly where it left off.
  • If changes ever wait longer than your change-history retention allows, the affected table is re-copied automatically rather than left with a gap.

Report a vulnerability

Email support@quayen.com.

Your MySQL data in BigQuery today

Free during early access. Set it up yourself in about 15 minutes, or we'll do it with you on a call.