Supper | Security & Enterprise Features

Built for companies that can't afford to get data wrong.

Supper is designed from the ground up for enterprise data environments — granular access controls, field-level privacy, bring-your-own infrastructure, and a full audit trail on every query. Security isn't an add-on. It's how the platform works.

Talk to our team Request documentation

Certifications & posture

Third-party verified. Continuously maintained.

Available on request — reach out and we'll share the right documents for your review process.

SOC 2 Type II

Annual audit · report on request

Penetration testing

Regular third-party tests · summary available

GDPR-compliant

EU data handling & residency controls

Data handling

Infrastructure access

Enterprise security features

Advanced controls for organizations that need more than the standard stack.

The features below are available on Enterprise plans. They're designed for organizations with strict compliance requirements, sensitive data environments, or specific infrastructure policies that standard cloud software can't accommodate.

Field-level controls

Sensitive data stays where it belongs.

Supper's query engine includes field-level controls (FLC) that prevent sensitive information from ever leaving your environment — enforced at SQL runtime, before a result is returned. You define which fields are sensitive. Supper handles the rest.

Maintain a column-level list of sensitive fields — PII, PHI, or anything your compliance team flags — and choose how each is handled when a query touches it.

Permanent obfuscation

Sensitive fields are one-way hashed at SQL runtime. The raw value never reaches Supper — or anyone else. Use this for PII you never need to recover.

Reversible obfuscation

Fields are encrypted with a customer-owned key at SQL runtime. You can decrypt when needed. Use this for PHI or data where future access may be required.

All SQL queries are retained. Every field access and encryption event has a full audit trail.

How it works

  1. Define sensitive fields in your column-level list
  2. Set obfuscation type per field: permanent or reversible
  3. Supper applies controls at SQL runtime - before results leave your environment
  4. Full audit trail retained for every field access

User entitlements

Permissions that match how your organization actually works.

Supper follows cloud IAM best practices for user entitlements. Every permission is defined at the level that makes sense — schema, table, or column — with cascading rules that let you set broad access with precise exceptions.

Permissions are enforced at query time, not just at the UI level. If a user can't see a field, no query run on their behalf will return it — ever.

Migration Phase

BYO Infrastructure

Your infrastructure. Supper's intelligence.

For organizations that can't send data or model inference outside their own environment. Supper's BYO capabilities let you keep everything in-house while running the full platform.

BYO LLM

Bring your own model

Provide your own API keys for OpenAI (GPT) or Anthropic (Claude) instead of Supper-managed model access. Model usage aligns with your internal procurement, security, and compliance policies — while Supper's orchestration layer, semantic modeling, and tool pipelines remain unchanged.

Organizations with strict vendor requirements can run all inference through a single provider. Supper routes different workloads to the model best suited for each task — SQL generation, natural language reasoning, business logic summarization — but BYO LLM lets you control or override that routing.

BYO S3

Bring your own storage

All query results and data outputs are written directly to a customer-owned AWS S3 bucket instead of Supper-managed storage. Your data never rests in a third-party environment — it stays within your AWS account and VPC.

Access is governed through customer-managed IAM policies, giving your security team full control over permissions, auditing, and data lifecycle. All Supper data sources — SaaS connectors, live warehouse queries, and agent outputs — route to the designated bucket.

Additional resources

Documentation available on request.

We know enterprise security reviews require more than a marketing page. Everything you need for a thorough evaluation is available — reach out and we'll share the right documents for your process.

Our security team is available for direct calls with your InfoSec or procurement reviewers. We've been through this process with customers at every stage of compliance maturity.

FAQ

Does Supper store my data?

No. Supper connects to your existing data sources and queries them directly. Your data stays where it lives — in your warehouse, your SaaS tools, your databases. No copies, no intermediate staging. Enterprise customers who want additional assurance can bring their own S3 bucket, so even query outputs never leave their environment.

Is Supper read-only? Can it modify my data?

Yes — Supper is strictly read-only. We connect to your warehouse and data sources through dedicated read-only credentials. There is no mechanism in the platform for writing, modifying, or deleting data in any connected source.

How does Supper handle PII and sensitive fields?

Enterprise customers can define a column-level list of sensitive fields — PII, PHI, or any data your compliance team designates. Supper applies field-level controls at SQL runtime: permanent one-way hashing for fields that should never be exposed, or reversible encryption with a customer-owned key for fields where future access may be needed. The raw value never reaches Supper in either case. Full audit trail retained on every access.

What AI models does Supper use? Can I use my own?

By default, Supper manages model access and routes workloads to the most appropriate model for each task — SQL generation, reasoning, summarization. Enterprise customers can bring their own API keys for OpenAI (GPT) or Anthropic (Claude), aligning model usage with internal procurement and compliance policies. Organizations with strict vendor requirements can run all inference through a single provider without losing core platform functionality.

How are user permissions managed?

Supper follows cloud IAM best practices. Permissions are defined at the role, schema, table, and column level. Cascading allow/deny rules let you set broad access with precise exceptions — "allow all from schema X, except table Y and column Z." Permissions are enforced at query time, not just at the UI level. If a user can't see a field, no query run on their behalf will return it.

Where is Supper hosted? What regions are supported?

Supper runs on AWS infrastructure. Enterprise customers with data residency requirements can discuss region configuration and BYO storage options with our team. Reach out to talk through your specific requirements.

What compliance documentation is available?

We provide SOC 2 Type II reports, penetration testing summaries, pre-filled security questionnaires, privacy and security policies, disaster recovery documentation, and compliance statements for GDPR and HIPAA readiness. All available on request — reach out to our security team and we'll share what you need for your evaluation process.