Trust and deployment
Where your data lives is your choice
Databasin was built in production at academic medical centre scale, which shaped the product in one specific way: we assume you cannot hand your data to a vendor.
So there are three ways to run Databasin. The difference between them is who holds the infrastructure.
- Hosted. Databasin operates the service and holds the infrastructure. Right when you want to start today and your data classification allows a hosted service.
- Self-installed in your own Azure tenant. Your subscription, your storage, your keys, your VNets. Databasin runs inside your boundary, and we do not hold your storage account, your keys, or a path into your network. Right for regulated data or a posture that does not permit vendor-held data.
- Alongside the platform you already run. Keep your existing Databricks, Snowflake, or Microsoft Fabric environment and put Databasin over it.
The same product in all three. Not a cut-down edition, and not a separate tier with the security features priced back in.
What is true in every mode
- Agents are read-only. An agent can investigate, explain, and deliver. It cannot write to, alter, or delete a production source. That is a property of how they are built, not a setting someone has to remember to switch on.
- Every answer carries its query. The SQL that produced a number is attached to the number. An answer you cannot inspect is not an answer you should act on.
- Row-level security and column masking are enforced in the governed layer, so they apply to the question a business user asks in plain English, not only to a hand-written query.
- Single sign-on, so access follows the identity your organisation already manages.
- Audit logging and lineage stay within your security boundary.
Regulated data
HIPAA-ready is the term we use, and we use it in a limited sense on purpose. It means the architecture and the contracting can be reviewed for a regulated use case. It does not mean a certificate exists, and it does not transfer your own assessment responsibility for the deployment, data flow, access controls, and operating procedures you choose.
A BAA is available on the standard plan, not gated behind a tier upgrade.
If PHI is in scope, start with a technical architecture review rather than a plan comparison. The deployment mode, data classification, connected systems, and network boundary all change the answer, and no marketing label settles it.
Our specific security commitments are written into the Data Use Agreement, which describes safeguards drawn from the HIPAA Security Rule, the NIST Cybersecurity Framework, and the SOC 2 Trust Services Criteria.
Certifications, stated plainly
Databasin is currently a subsidiary of Technology Partners and is in the process of separating into its own company.
Databasin does not hold its own SOC 1 or SOC 2 report today. We are not going to imply otherwise by pointing at a parent company's certificate, because the entity a certificate covers is the first thing a reviewer checks, and it would not be ours.
We will pursue SOC 2 Type II for the Databasin entity after the corporate separation completes. We are not promising a date, because a date we cannot control is not a commitment.
Until then, what we can offer a security review is the thing a certificate stands in for: an architecture you can inspect, a deployment mode where the data never leaves your tenant, controls you can test yourself, and a signed agreement.
What is not on this page yet
A trust page that lists only strengths is not much use to someone running a real review. These are open, and named rather than quietly omitted.
- A published subprocessor list scoped per deployment mode.
- A reviewed source-to-serving data-flow diagram, including the model-provider path.
- Mode-specific encryption and key-management documentation.
- A monitored security-incident intake address. Until one exists, do not treat a general sales or support contact as an incident channel.
- A Databasin-entity SOC 2 report, as above.
If your review needs any of these before it can proceed, ask. We will tell you where the item actually stands rather than send a document that does not cover your deployment.
Continue a review
For a regulated or private-Azure evaluation, the useful next step is a conversation with the people who built it, not a trial signup.
- Request a technical architecture review for the deployment mode, data boundary, and controls that apply to yours.
- Talk to us about self-install inside your own Azure subscription.
- Epic and clinical data if that is the system in scope.