Governed data platform for platform teams
Security asks who reads raw payments. Reply with the log.
Every change audited. AI agents see only what you expose.
Trusted by forward-thinking teams
Governance as code
Your standards, in the repo. Checked on every PR.
/* @bruin
name: mart.support_customers
type: sf.sql
owner: [email protected]
description: Support lookup. No card data.
tags: [governed, support]
materialization:
type: table
depends:
- stg.customers
columns:
- name: customer_id
primary_key: true
checks:
- name: not_null
- name: unique
@bruin */
select customer_id, email, plan, country
from stg.customers$ bruin validate .
- pipelines/payments14 assets
- pipelines/support9 assets
- asset-has-checks23 of 23
- asset-has-primary-key23 of 23
- asset-has-ownermart.refund_export
1 policy failure: mart.refund_export has no owner, so the pull request can't merge.
Column-level lineage
Tag a sensitive column once. See where it goes.
Source
- payment_id
- card_last4
- amount
Staging
- card_last4
- amount_eur
Mart
- card_last4
- revenue
Used by
From a CTO
“I was playing with dbt, and I realized I had to put multiple stacks around it: orchestrate it, validate it, connect it to my CI, observe the pipeline itself. Bruin joined all of them into one tool.”
“Bruin was a new tool that nobody had experience with, so I expected onboarding to be hard. Within a week the new person was already there. It was way easier than I expected.”
Demirhan AydınCo-founder & CTO, Fabrikatör- orchestration, validation, CI, observability
- 1 tool
- to onboard a new engineer
- ~1 week
- internal and customer-facing pipelines
- 2 surfaces
Built on the Bruin platform
One platform to secure, from ingestion to AI answers.
01 · Move
02 · Model & govern
03 · Use
Frequently asked
Questions from platform teams.
Where can Bruin run, and can we choose the region?
In Bruin Cloud, your VPC on AWS, GCP or Azure, or on-prem, including air-gapped. You pick the region your tenant runs in, including the EU.
Does Bruin need access to our production database?
No. It loads from read replicas, exports or incremental loads, so nothing connects to your primary. Transformations run inside your warehouse, so customer data stays in your infrastructure.
How do access control and audit logs work in Bruin?
Role-based access down to the asset, SSO with SAML 2.0 or OAuth on enterprise plans, SCIM provisioning and audit logs. Bruin is SOC 2 Type 2 attested and ISO/IEC 27001:2022 certified.
How do we connect AI agents to our data through Bruin?
Through Bruin MCP. The server holds the warehouse connection, so agents never see credentials. It exposes only the assets you choose, changed in a reviewed PR.
Can we enforce standards like owners and checks on every Bruin pipeline?
Yes. Rules such as every asset has an owner, a description, a primary key and checks live in policy.yml. bruin validate runs them in CI and before every run, so a change that breaks one fails the pull request.
Can Bruin show where a sensitive column ends up downstream?
Yes. Column-level lineage traces a field like card_last4 through every model to the dashboards and agents that read it, so an access review starts from the graph, not from guesses.
Can Bruin show what our data pipelines cost in the warehouse?
Yes. Bruin Cloud shows what your pipelines spend in the warehouse, so you can find the ones driving the bill.
Can Bruin replace running dbt, Airflow and a catalog ourselves?
Yes, as one system to secure and upgrade instead of several. Ingestion, models, checks, orchestration and lineage share one repo, one access model and one audit log.
Is Bruin open source, and what does Bruin Cloud add?
The Bruin CLI is open source (Apache 2.0) and ingestr is source-available (FSL); both run locally, in CI or in your own orchestrator. Bruin Cloud adds managed scheduling, the catalog, column-level lineage, SSO, roles, audit logs and cost insights.
How much does Bruin cost, and is it per seat?
The Bruin CLI (open source, Apache 2.0) and ingestr (source-available) are free to run in your own infrastructure. Bruin Cloud bills compute per second by instance size, about $2.50 an hour for SQL and $10 on a standard instance, with no seats and no per-row charge. Committed-use discounts lower the rate as usage grows. VPC or on-prem: book a demo.
Walk into the access review with the answers ready.
$100 in credits and 50 AI tasks. No credit card.
A demo walks through your own data.
