With encrypted transit, role-based access controls, and full compliance with global standards and privacy laws, Hevo is engineered for integrity at every layer.
All data is encrypted in transit (TLS 1.2+), at rest (AES), and during processing (SSL for Kafka). Customer-specific credential encryption keys minimize risk and ensure data confidentiality and integrity.
Connections are kept secure and private, exposing zero data to the public internet. Access is controlled with SAML SSO and role-based permissions to ensure only authorized users can connect.
Pipeline data follows storage limitation principles, is processed solely to support pipeline operations with end to end encryption and automatic deletion when no longer needed.
Hevo processes only the data you configure in your pipelines. Sensitive fields like PII or PHI can be excluded, masked, or hashed to maintain privacy control.
Your data stays in the selected cloud region (EU, US, or APAC). Hevo does not transfer pipeline data across regions, supporting GDPR, HIPAA, CPRA, and DORA.
Hevo does not mine or analyze your pipeline data. Only platform usage metrics are tracked to improve the product. Your data content remains private.
Hevo is certified by AICPA independent auditors for all five Trust Services Criteria, ensuring secure and reliable data processing across your pipelines.
We meet HIPAA Security, Privacy, and Breach Notification requirements by safeguarding ePHI through rigorous controls.
We process personal data in line with GDPR’s principles of lawful, transparent, and purpose-limited processing.
Hevo provides complete data visibility and control by supporting consumer rights to access, delete, correct, opt-out, and port their personal information.
Built with financial-sector needs in mind, with ICT controls, risk mitigation, and incident readiness, Hevo ensures operational resilience.
We offer Data Processing and Business Associate Agreements to clarify responsibilities and support compliance with global privacy standards across.
The simplest way to connect - using database credentials, API keys, or OAuth tokens. Best suited for publicly accessible databases and SaaS apps.
Securely connect to databases behind firewalls using SSH or Reverse SSH tunnels. Ideal when public exposure is not an option. Note: Available for database sources only.
Connect to private on-prem or non-AWS cloud environments using an IPSec VPN tunnel. Offers enterprise-grade access control and compliance flexibility.
Connect via AWS VPC Peering, VPC Endpoints, PrivateLink for MongoDB, or Transit Gateway and make sure your data remains within AWS.