Update
July 20, 2026
Metadata only: our security promise
What VectorData can see, what it never sees, and why read-only warehouse access is non-negotiable.

REDWOOD CITY, CALIFORNIA — Some data tools ask for access to your rows to “monitor quality.” That solves the wrong problem and creates a new one. VectorData is built around metadata: information_schema update times, job stats, bytes billed, dbt artifacts. Customer PII, order lines, and event payloads stay in your project.
Access is read-only. We prefer a dedicated service account with the narrowest roles that make monitoring work. If a vendor cannot explain their IAM ask on one page, walk away. Ours is on /security, and security reviewers can email hello@vectornosis.com to walk a questionnaire line by line.
This is the same stance as the product feature: refusing to sample rows is how VectorData stays sharp, and it is how a deal survives review. The promise is not a badge wall. It is an architecture you can inspect.

What leaves the warehouse is structure: timestamps, jobs, artifacts. Not the payload.
“If we cannot describe the access model in a meeting, we do not deserve the service account.”
Ricky Jiménez Sparks, CEO of Vectornosis
Read-only in practice
The dedicated service account should be able to read the metadata VectorData needs and nothing else. It should not write tables. It should not export rows. It should not be a human’s leftover admin key. If a vendor’s setup guide starts with broad roles “for convenience,” the convenience is theirs. Ours is on /security, on purpose, so a reviewer does not have to reverse-engineer a slide.
When a contract ends, there are no warehouse copies to unwind. That is the operational payoff of refusing to sample. You are not running a second copy of customer data in someone else’s cloud and hoping the DPA is enough.

How to start a review
Send the questionnaire to hello@vectornosis.com. Walk /security first so the answers match the page. If you want to see the product before IAM, the command center is already open. That order is intentional: architecture in public, credentials after the software has shown you a failure.
We will answer in the same language as this newsroom. What we can see. What we never see. What Watchdog does with the rest. If that is not enough for the deal, the deal was never about monitoring.
Read the full breakdown. If you are in procurement or security review, send the questionnaire. We will answer it in the same language as this newsroom — what we can see, what we never see, and what the product does with the rest.


