Customer 360 Enterprise Data Platform — Denodo on Azure · View 34 of 39 · Assurance
Decisions
- No secret is held by a consumer and none by a pod. Every source credential is fetched at runtime under a managed identity with a short lease.
- Every data store is reachable by private endpoint only. There is no path from the application zone to a public data plane endpoint, so a compromised pod cannot exfiltrate over the internet.
- The control zone is a separate subscription with separate administrators, and the audit path into it is one-directional. A platform operator cannot alter the record of what they did.
Where an attacker arrives
- Credential stuffing against the consumer applications, stopped at token validation rather than at the network edge.
- Scripted extraction by a legitimate but over-entitled user — the case the gateway cannot see. It is contained by row limits, quota and the usage telemetry on view 31, and it remains the most realistic breach path.
Encryption
- TLS 1.3 in transit everywhere including source connections; customer-managed keys on ADLS and the cache database; audit archive immutable for 13 months.