Skip to content

Security

Isolation and least privilege, by design.

Your NetSuite data moves from your ERP to a destination dedicated to your company. SuiteStream reads, replicates and gets out of the way — it doesn’t pool customer data, and it never writes to NetSuite.

Controls

What protects your data

A dedicated destination

Each customer’s replicated data lands in its own SQL Server or Snowflake database. There are no shared customer data tables.

Your data stays yours

Replicated NetSuite data is written to your destination. SuiteStream doesn’t retain your business data beyond what’s needed to run replication.

Read-only NetSuite access

SuiteStream connects through SuiteAnalytics Connect, a read-only reporting interface. It cannot create, change or delete NetSuite records.

Secrets in Azure Key Vault

NetSuite and destination credentials are stored in Azure Key Vault, referenced per customer, and never displayed in full in the portal.

Strong sign-in

Email verification, Google or Microsoft sign-in, authenticator-app two-factor authentication, and rate-limited login attempts.

Audit trails

Configuration changes are logged with who made them and when, and sign-in activity is recorded in a security audit log.

Data flow

Where your data goes — and where it doesn’t.

Data is read from NetSuite and written to your destination. Connections are tested before they’re saved, so a mistyped credential never starts a half-configured pipeline.

  1. SOURCENetSuiteYour ERP of record
  2. ACCESSSuiteAnalytics ConnectRead-only ODBC bulk reads
  3. SUITESTREAMContinuous replicationChange detection, monitoring, alerts
  4. DESTINATIONSQL Server or SnowflakeYour dedicated destination

FAQ

Security questions

Can SuiteStream change data in NetSuite?

No. SuiteStream connects through SuiteAnalytics Connect, which provides read-only access for reporting. It cannot create, update or delete NetSuite records.

Does SuiteStream keep a copy of my NetSuite data?

Replicated data is written to your dedicated destination. SuiteStream doesn’t retain your business data beyond what is required to operate replication on your behalf.

Where are my credentials stored?

NetSuite and destination credentials are stored in Azure Key Vault and referenced per customer. They are never stored in the application database or shown in full in the portal.

Is my data kept separate from other customers?

Yes. Every customer gets a dedicated destination — its own SQL Server or Snowflake database. There are no shared customer data tables.

How do people sign in to the portal?

With a verified email and password, or Google or Microsoft sign-in. Authenticator-app two-factor authentication is available, and repeated failed logins are rate-limited.

Have a security questionnaire? Send it over through our contact page and we’ll work through it with your team.

Talk to us about your requirements.

We’ll walk your team through isolation, credentials and access before you sign up.