---
title: Security | Hevo Data
description: With encrypted transit, role-based access controls, and full compliance with global standards and privacy laws, Hevo is engineered for integrity at every layer.
canonical_url: https://hevodata.com/security/
content_type: page
word_count: 1117
source: https://hevodata.com/security.md
---

# Security | Hevo Data

Hevo secures pipeline data with end-to-end encryption, region-locked processing, and role-based access control, and supports SOC 2 Type II, HIPAA, GDPR, CPRA, and DORA compliance for regulated workloads.

## Key facts

- Rated 4.4/5 on G2 (290+ reviews).
- Used by 2,000+ data teams.
- Data encrypted in transit (TLS 1.2+), at rest (AES-256), and during processing (SSL for Kafka).
- Customers choose their processing region — Frankfurt, Mumbai, Oregon, Virginia, Singapore, or Sydney — and Hevo never transfers pipeline data across regions.
- Pipeline data is not retained permanently: a maximum of 24 hours in staging, or 7 days for failed events, before it's processed, skipped, or deleted.
- Certified for SOC 2 Type II, HIPAA, GDPR, CPRA, and DORA.

## Secure architecture

- **End-to-end encryption:** all data is encrypted in transit (TLS 1.2+), at rest (AES), and during processing (SSL for Kafka), with customer-specific credential encryption keys.
- **Private and secure connectivity:** connections expose zero data to the public internet; access is controlled with SAML SSO and role-based permissions.
- **Purpose-limited processing:** pipeline data is processed only to support pipeline operations, with end-to-end encryption and automatic deletion once no longer needed.

## Privacy-first, regionally isolated

- **Data flows only by design:** Hevo processes only the data configured in a pipeline; sensitive fields like PII or PHI can be excluded, masked, or hashed.
- **Regional processing, no silent transfers:** data stays in the selected cloud region (EU, US, or APAC); Hevo does not transfer pipeline data across regions, supporting GDPR, HIPAA, CPRA, and DORA.
- **No profiling, no inference:** Hevo does not mine or analyze pipeline data content — only platform usage metrics are tracked to improve the product.

## Compliance certifications

- **SOC 2 Type II:** certified by AICPA independent auditors across all five Trust Services Criteria.
- **HIPAA:** meets HIPAA Security, Privacy, and Breach Notification requirements for ePHI.
- **GDPR:** personal data processed under GDPR's principles of lawful, transparent, purpose-limited processing.
- **CPRA:** supports consumer rights to access, delete, correct, opt out of, and port personal information.
- **DORA:** ICT controls, risk mitigation, and incident readiness built for financial-sector operational resilience.

Data Processing Agreements (DPAs) and Business Associate Agreements (BAAs) available to clarify compliance responsibilities.

## Connectivity options

- **Direct connection:** database credentials, API keys, or OAuth tokens — best for publicly accessible databases and SaaS apps.
- **SSH & Reverse SSH:** securely connect to databases behind firewalls when public exposure isn't an option (database sources only).
- **VPN (IPSec):** connect to private on-prem or non-AWS cloud environments with enterprise-grade access control.
- **AWS-native options:** VPC Peering, VPC Endpoints, PrivateLink for MongoDB, or Transit Gateway, keeping data inside AWS.

## FAQ

### Where can I access Hevo's legal, compliance, and security documentation?

Visit the Trust Center (https://trust.hevodata.com/) for security and compliance documentation such as reports, policies, and more. The Legal Resources page (https://hevo.me/legal-resources/) has the Privacy Policy, DPA, and Terms of Service.

### Where is my data processed, and can I choose the location?

Yes. During onboarding, you choose your processing region like Frankfurt, Mumbai, Oregon, Virginia, Singapore, or Sydney. Pipeline data never leaves the selected region, supporting data residency requirements under GDPR, CPRA, and other frameworks, at no additional cost. Details: https://docs.hevo.me/getting-started/creating-your-hevo-account/regions/

### How is my data protected while it moves through Hevo?

Through end-to-end encryption: TLS v1.2+ during transmission, AES-256 at rest, and SSL during Kafka stream processing. Details: https://docs.hevo.me/introduction/security/customer-data-retention-and-encryption/#encryption-on-data-in-transit

### Who manages encryption keys and how is data isolation maintained?

Each customer is assigned a unique encryption key and team ID, ensuring strict logical separation in Hevo's multi-tenant environment. Keys are managed internally with role-based access and rotation capabilities. Details: https://docs.hevo.me/introduction/security/customer-data-retention-and-encryption/#encryption-on-data-in-transit

### Does Hevo permanently store my pipeline data?

No. Data is stored only temporarily up to 24 hours in staging, or 7 days for failed events such as before being processed, skipped, or deleted, in line with data minimization principles. Details: https://docs.hevo.me/introduction/security/customer-data-retention-and-encryption/#retention-and-encryption-of-data-at-rest

### Can Hevo handle healthcare, financial, or other regulated data?

Yes. Hevo supports regulated workloads across healthcare, financial services, and other compliance-sensitive sectors, with HIPAA-compliant BAAs, GDPR/CPRA-aligned DPAs, and DORA-specific contractual clauses as required. Trust Center: https://trust.hevodata.com/

### Can I prevent sensitive fields from being synced or stored in my destination?

Yes. Any table, field, or object can be excluded during connector setup, and Hevo's transformation layer can mask or hash sensitive data like PII or ePHI before it reaches the destination.

### Can Hevo access my systems or data?

No, not without explicit consent. Support access, when required, is time-bound (default 30 days), consent-based, fully revocable by the account admin, and logged and auditable. Details: https://docs.hevo.me/account-management/team-settings/granting-temporary-access-to-hevo-support/

### How is access to my Hevo workspace controlled?

Through Role-Based Access Control (RBAC), defining what each team member can see or do by role (admin, collaborator, or observer), plus optional Multi-Factor Authentication (MFA) and SAML SSO integration with identity providers like Okta or Azure AD.

### Can I delete or export my data at any time?

Yes. Customers can request export of team/user metadata or initiate full account deletion via the dashboard or support. On deletion, the account closes at the end of the billing cycle and all associated data is permanently and irreversibly purged, per Hevo's secure disposal policy.

## Customer outcomes

- ThoughtSpot cut platform costs by 85% and maintained 100% uptime after moving to Hevo. Case study: https://hevodata.com/success-stories/thoughtspot/
- Icelandair moved to hourly data refresh and cut pipeline setup from weeks to hours, with zero engineering hours spent on pipeline maintenance. Case study: https://hevodata.com/success-stories/iceland-air/
- Postman saves 40+ hours per month with 40+ sources connected through Hevo. Case study: https://hevodata.com/success-stories/postman/
- Deliverr doubled the data volume it processes and increased productivity 10% using Hevo's real-time replication. Case study: https://hevodata.com/success-stories/deliverr/

All customer stories: https://hevodata.com/customers/

## Pricing

Hevo uses transparent, usage-based pricing with no credit card required to start.
