Security
Isolation and least privilege, by design.
Your NetSuite data moves from your ERP to a destination dedicated to your company. SuiteStream reads, replicates and gets out of the way — it doesn’t pool customer data, and it never writes to NetSuite.
Controls
What protects your data
A dedicated destination
Each customer’s replicated data lands in its own SQL Server or Snowflake database. There are no shared customer data tables.
Your data stays yours
Replicated NetSuite data is written to your destination. SuiteStream doesn’t retain your business data beyond what’s needed to run replication.
Read-only NetSuite access
SuiteStream connects through SuiteAnalytics Connect, a read-only reporting interface. It cannot create, change or delete NetSuite records.
Secrets in Azure Key Vault
NetSuite and destination credentials are stored in Azure Key Vault, referenced per customer, and never displayed in full in the portal.
Strong sign-in
Email verification, Google or Microsoft sign-in, authenticator-app two-factor authentication, and rate-limited login attempts.
Audit trails
Configuration changes are logged with who made them and when, and sign-in activity is recorded in a security audit log.
Data flow
Where your data goes — and where it doesn’t.
Data is read from NetSuite and written to your destination. Connections are tested before they’re saved, so a mistyped credential never starts a half-configured pipeline.
- SOURCENetSuiteYour ERP of record
- ACCESSSuiteAnalytics ConnectRead-only ODBC bulk reads
- SUITESTREAMContinuous replicationChange detection, monitoring, alerts
- DESTINATIONSQL Server or SnowflakeYour dedicated destination
FAQ
Security questions
Can SuiteStream change data in NetSuite?
No. SuiteStream connects through SuiteAnalytics Connect, which provides read-only access for reporting. It cannot create, update or delete NetSuite records.
Does SuiteStream keep a copy of my NetSuite data?
Replicated data is written to your dedicated destination. SuiteStream doesn’t retain your business data beyond what is required to operate replication on your behalf.
Where are my credentials stored?
NetSuite and destination credentials are stored in Azure Key Vault and referenced per customer. They are never stored in the application database or shown in full in the portal.
Is my data kept separate from other customers?
Yes. Every customer gets a dedicated destination — its own SQL Server or Snowflake database. There are no shared customer data tables.
How do people sign in to the portal?
With a verified email and password, or Google or Microsoft sign-in. Authenticator-app two-factor authentication is available, and repeated failed logins are rate-limited.
Talk to us about your requirements.
We’ll walk your team through isolation, credentials and access before you sign up.