Data governance
Every asset owned. Every change traced.
Lineage, owners, tiers and access control, right next to your pipelines.
Catalog / snowflake / mart
mart.revenue_daily
Tier 1Table · 6 columnsDaily net revenue by order date, after refunds and discounts.
- Owner
- finance-analytics
- Tier
- Tier 1
- Meta-keys
- domain: revenue
- pii: false
- cost_center: fin-01
- Glossary
- Net revenue
- Updated
- by maya, 2 days ago
Lineage
Revenue dashboard, Monday brief, +5 more
Checks 4 of 4 passing
- not_null · order_date
- unique · order_date
- non_negative · revenue
- matches Stripe payouts
Trusted by forward-thinking teams
Lineage
From the source to the AI answer.
Column-level, generated from the pipelines that run. Never hand-drawn.
Source
- order_id
- amount
- status
- charge_id
- amount
- currency
Staging
- order_id
- amount_usd
- status
Mart
- order_date
- revenue
Used by
- Revenue
- Orders
- Revenue
Owners & tiers
Defined once. Known everywhere.
Owners, tiers and meta-keys live in the asset file, versioned with the code.
/* @bruin
name: mart.revenue_daily
type: sf.sql
owner: finance-analytics
description: Daily net revenue by order date, after refunds and discounts.
meta:
tier: 1
domain: revenue
pii: false
columns:
- name: order_date
type: date
checks:
- name: not_null
- name: unique
- name: revenue
type: float
description: Net revenue in USD, after refunds and discounts.
checks:
- name: non_negative
@bruin */
select order_date, sum(amount_usd) as revenue
from stg.orders
group by order_daterevenue Net revenue in USD, after refunds and discounts.
Access & audit
Who can see it. Who changed it.
SSO, roles and audit logs in Bruin Cloud. ISO 27001 certified, SOC 2 Type 2 attested.
mart.revenue_daily to finance-analystsWebmart.revenue_dailySlackmart.customer_ltv to Tier 1Webdaily_sales from main, 3 assets changedCIraw.stripe_charges from contractorsWebEnterprise-ready
Built for the security review.
Your cloud, VPC or on-prem
Managed by Bruin, or deployed inside your own network.
No direct prod DB access
Work from read replicas, exports or incremental loads.
Private connectivity
VPC peering and private links to your sources.
Open source at the core
The Apache 2.0 Bruin CLI holds the dependency graph and runs the checks.
Customer results
Numbers from teams on Bruin.
The platform
Part of the Bruin platform.
Every piece reads the same owners, tiers and lineage, from ingestion to the AI answer.
01 · Move
02 · Model & govern
03 · Use
Your stack, your call
Replace the modern data stack.
One layer or every layer. Keep what works, swap what doesn't.
Today
On Bruin
Layer
What teams run today
On Bruin
Ingestion
On Bruin: Data Ingestionon open-source ingestr
Transformation & orchestration
On Bruin: SQL & Python + Bruin Cloud
Quality, lineage & catalog
On Bruin: Data Quality + Data Governance
BI & dashboards
Power BI
On Bruin: AI Dashboards + Data Apps
AI on your data
On Bruin: AI Data Analyst + Scheduled Agents
Frequently asked
Questions about data governance.
What does data governance cover in Bruin?
Column-level lineage, a catalog with owners, asset tiers and meta-keys, quality checks, and SSO, role-based access and audit logs. It all lives in Bruin Cloud, next to the pipelines.
Does Bruin replace a data catalog?
For everything that runs on Bruin, yes: the catalog is built from the pipelines, so it does not drift. Teams can keep a wider catalog for systems Bruin does not run.
Is governance part of the open-source Bruin CLI?
The Apache 2.0 Bruin CLI knows the full dependency graph and runs the quality checks. The interactive catalog, lineage and access controls are part of Bruin Cloud.
How does Bruin build its lineage?
From the pipelines that run: the SQL, the declared dependencies and the ingestion behind them. It is column-level, and there is nothing to draw by hand.
Where do owners, tiers and meta-keys come from in Bruin?
From the asset file, next to the SQL or Python, so they are versioned with the code. Bruin Cloud shows them in the catalog and on the lineage.
Who can see what in Bruin?
Access is role-based, with sign-in through your SSO provider. Grants, asset changes and queries are recorded in the audit log.
Can Bruin run without direct access to our production database?
Yes. Bruin works from read replicas, exports or incremental loads, and runs in Bruin's cloud, your VPC or on-prem.
Is Bruin ISO 27001 and SOC 2 compliant?
Bruin is ISO/IEC 27001:2022 certified and SOC 2 Type 2 attested. The SOC 2 report is available under NDA.
Govern the data where it's built.
$100 in credits and 50 AI tasks. No credit card.
A demo walks through your own data.
