Security

Secure AI interactions end-to-end

Every prompt, every record accessed, every action taken: secured at each step of AI execution.

Trusted by global teams connecting data and AI at scale
GSK
Palantir
Anthropic
Office Depot
Google

Complete security and governance for AI data access and action

Every control your security team expects, built into the platform and applied to every record an agent accesses and every action it takes.

Get the CData Security Kit

Will this pass my security review?

Compliance certifications, preset data security rules, and the credential and audit posture your security team will ask about.

Compliance

  • SOC 2 Type II
  • ISO 27001
  • HIPAA
  • GDPR

Data security rules

  • PII Masking
  • API keys & bearer tokens
  • Custom regex rules

Credentials

  • Azure Key Vault integration
  • Resolved at query time
  • Rotate without reconfiguring

Audit & SIEM

  • Query-level audit logs
  • Real-time SIEM forwarding

Secure every path into your systems

From individual developer tokens to full OAuth integrations—admins enforce token hygiene and scope access precisely.

Token security with admin-enforced expiration

Global expiration policy

Admins set 30, 60, 90 days, or custom, applied to every user in the account. Expired tokens fail immediately with no silent fallback.

Rotation & revocation

Rotate or revoke tokens without touching connections, expired tokens display immediately in the admin portal.

Fully audited

Every token creation, use, and revocation is logged in the audit trail.

Personal access tokens
POLICY · EXPIRE AFTER 60 DAYS · SET BY ADMIN
pat-jchen-laptop expires in 12 days
pat-mruiz-ci expires in 41 days
pat-svc-legacy expired · access denied

Expired tokens fail closed—every denial lands in the audit log.

Secure from query to credential to log

Five steps run inside a single request—credentials resolved from your vault, rules enforced, everything logged.

Security in Action
Nick Bisciotti
“Security is a real concern with the current MCP server marketplace. We want to leverage OAuth specifically, so users are properly identified and the permissions we've established for them extend seamlessly into AI functionality. CData can do that.”
Nick Bisciotti
Director of IT
FAQ

Questions security teams ask.

  • Does Connect AI store or cache our data?
  • Where do our credentials live?
  • Can our SecOps team see Connect AI activity in our SIEM?
  • How do the data security rules map to regulations?
  • What certifications does Connect AI hold?

The AI data layer your security team will approve

Talk to our team about how Connect AI fits your security requirements—from compliance posture to deployment architecture.