Security is built into federation

SemanticFed enforces governance where it matters — at the query edge — and queries your data in place so you move and copy less. Here is how we approach security and data protection.

Policy at the query edge
Inherited RBAC & audit
Residency-friendly

SemanticFed is pre-launch. This page describes the security model being built, not a completed certification.

How we protect your data

The security model SemanticFed is built around, end to end

Encryption in transit & at rest

Connections to SemanticFed and to your sources use TLS, and platform secrets are held in a per-environment key vault rather than in config or code.

TLS for all client and source connections
Secrets held in a per-environment key vault
No source credentials stored in plaintext config
Encryption at rest for platform-managed data

Policy at the query edge

Row filters, column masking, and access rules are enforced on every federated query, before results return — consistently, no matter which underlying source the data came from.

Row-level security across all sources
Column masking for sensitive fields
One policy model instead of per-source drift
Least-privilege access by default

Inherited identity & RBAC

Authentication and role-based access control are inherited from the Burdenoff platform and enforced at the edge. SemanticFed never re-implements auth.

RBAC enforced at the edge
Identity with attributable actions
Multi-tenant isolation by workspace
Scoped access for every API field

Audit & lineage

Every federated query is attributable and logged with the policy that applied, and every dataset carries lineage back to its physical sources — so access reviews read as one consistent record.

Attributable, logged query history
End-to-end dataset lineage
Evidence-ready access reviews
Policy decisions recorded with each query

Privacy by architecture

Federation changes the privacy calculus — querying in place means moving and storing less.

Query in place

Because federation queries data where it lives, regulated data can stay inside its residency boundary instead of being copied out to be analyzed.

Data minimization

Push-down means a query reads only the rows and columns it needs — we move the minimum, not whole tables, and we keep no copy by default.

You keep custody

Your source systems remain yours. SemanticFed queries them with scoped credentials; it does not take ownership of your underlying data stores.

No data selling

We never sell your data or use it for anything other than providing the service to you.

Compliance posture

Where we are today and what is on the roadmap — stated honestly for a pre-launch product.

GDPR-aware by design

Built to support data-minimization, access, and residency requirements.

Data residency

Query-in-place keeps regulated data inside its jurisdiction.

Hosted in India

Hosted in India with selected services in the Mumbai region.

Certifications (roadmap)

SemanticFed is pre-launch and holds no formal certifications yet. SOC 2 and ISO 27001 are on the roadmap; we will publish status as we progress.

Operate securely

Practices we recommend to keep your federation deployment locked down

Scoped source credentials

Connect each source with least-privilege, read-scoped credentials so SemanticFed can only do what you intend.

Strong authentication

Use the platform’s authentication and RBAC, and grant access to models and sources on a need-to-know basis.

Review the query plan

Every federated query exposes an inspectable plan, so you can verify exactly what ran where before trusting a result.

Version your model

Keep semantic definitions and policy as reviewed, versioned changes so governance is traceable, not ad-hoc.

Responsible disclosure

If you discover a potential security issue in SemanticFed, please report it to us privately so we can investigate and fix it before any details are made public. We welcome responsible disclosure and will acknowledge your report.

Governed by design

Federation that enforces your policy everywhere and moves your data less. Join the waitlist to be among the first teams on SemanticFed.