Securing your data in Matillion's Data Productivity Cloud

As businesses increasingly rely on cloud technology for data operations, ensuring the security of data in transit is more important than ever. Matillion's Data Productivity Cloud offers robust services for extracting, loading, and transforming data, and securing these processes is crucial. This guide will show you how to protect your data using cloud security best practices during deployment and processing.
What is Matillion's Data Productivity Cloud?
Matillion Data Productivity Cloud consists of two primary components:
- Control Plane: This is the interface where design and control your pipelines, act as the command center for managing your data workflows.
- Data Plane: This is where your data processing tasks take place. There are two ways of defining your data plan, one is to utilize the Hybrid agent offering which uses Docker technology to enhance efficiency and scalability. The other is a Full Saas option that removes the need for infrastructure management.

Data Productivity Cloud Architecture
Options for deploying Data Productivity Cloud agents
Matillion Data Productivity Cloud, allows the flexibility to choose between two deployment options for your data plane, each catering to different security and control needs:
- Full SaaS: This is fully managed by Matillion Data Productivity Cloud, offering a straightforward, maintenance-free solution ideal for businesses looking to minimize administrative overhead. While this hosted solution provides a secure environment and infrastructure, the data this integrates with is transferred over the internet, albeit encrypted when supported. This setup is suitable for many scenarios but may conflict with organizational requirements for data sovereignty or industry-specific data governance restrictions.
- Hybrid SaaS: If your needs include stringent security controls and the ability to access resources within a private network, then the Data Productivity Cloud agents are the optimal choice. By managing agents yourself, you can tightly control their configuration, security, and the data they access. This option is particularly beneficial for enterprises that require access to private resources, such as internal databases and applications not exposed to the public internet.

Security best practices for Customer-Hosted Agents in Matillion Data Productivity Cloud
To ensure the highest level of security for your Hybrid agents in Matillion Data Productivity Cloud, consider implementing the following best practices:
Secure Networking for Agents

Goal: The primary goal is to protect your data and operations from unauthorized external access and control outbound traffic to prevent sensitive data from leaving your network without proper authorization.
Benefits: Secure networks and managed outbound traffic help prevent cyber threats and attacks. They ensure secure communication, maintain compliance with data protection regulations, and enforce internal security policies.
Recommendations:
- Deploy agents in a private subnet: Make your agents inaccessible from the internet by deploying them in private subnets within your cloud network. They will need a NAT gateway to connect to the internet – essential for keeping the Control and Data planes connected.
- Use Routing Tables, ACLs, and Security Groups: Configure these with minimal required ingress and egress rules to restrict access. Agents need outbound access to the control plane and source systems, but no open inbound connections.
- Control Outbound Traffic: Use network security groups and ACLs to enforce outbound traffic policies by defining rules that specify allowable destinations, protocols, and ports. Implement egress filtering and deep packet inspection to examine outbound traffic for any signs of malicious activity or data breach attempts.
- Implement Additional Firewalls: Define and enforce security policies that restrict access via additional firewall servers and services as appropriate, maintaining the integrity and confidentiality of your operations.
- Employ Logging and Continuous Monitoring: Detect and respond to unauthorized attempts to access external networks through comprehensive logging and monitoring.
Encrypting Data in Matillion Data Productivity Cloud

Goal: Protect sensitive data from unauthorized access during transit and while stored, ensuring compliance with data protection regulations.
Benefits:
- Ensures data is unreadable by unauthorized parties.
- Helps meet compliance requirements for data security.
- Reduces the risk of data breaches and data theft.
Recommendations:
In Transit:
- Use TLS for all data transmissions to ensure secure and encrypted data flows.
- Establish VPN tunnels for added security in sensitive or highly regulated data transfers.
At Rest:
- Enable default encryption on all storage solutions.
- Use AES-256 for strong, resilient data protection.
Key Management:
- Utilize managed services like AWS KMS or Azure Key Vault for key management.
- Regularly rotate keys and restrict key access to authorized personnel only.
Monitoring:
- Implement access logging and conduct regular security audits to maintain and improve encryption practices.
Managing Secrets in Matillion Data Productivity Cloud

Matillion Data Productivity Cloud Hybrid agents are specifically engineered to ensure secure data interactions without storing sensitive information such as passwords, SSH keys, or other credentials internally. Instead, they utilize a method to access secrets that are securely managed and stored in your cloud platform's dedicated secrets manager. This approach minimizes the risk of exposure and enhances overall security.
By leveraging cloud-native secrets managers, Matillion Data Productivity Cloud Hybrid agents maintain a high level of security by accessing only encrypted and managed secrets when needed. This method effectively reduces the attack surface by not storing sensitive data on the agents themselves.
Recommendations: Implement secrets managers such as AWS Secrets Manager or Azure Key Vault to handle credentials and other sensitive data. Configure these managers to automatically rotate secrets to further reduce potential vulnerabilities. Ensure that access policies and permissions are strictly controlled to allow only authorized agents and services to retrieve these secrets.
Regular Updates

Your agents are automatically kept up to date, by default, with the latest security patches and software updates, to protect against new vulnerabilities and enhance functionality
Conclusion
Ensuring cloud data security is crucial. Matillion provides robust security the Data Productivity Cloud Full SaaS, establishing a strong foundation for data management. However, by adopting the Data Productivity Cloud Hybrid agents and additional security practices, you can further enhance data protection within Matillion Data Productivity Cloud. Remember to always stay vigilant and proactive in safeguarding your valuable data, and consider all available options to ensure your data is sufficiently secured.
James Kosterman
DevOps Sales Solutions Consultant
Featured Resources
Big Data London 2025: Key Takeaways and Maia Highlights
There’s no doubt about it – Maia dominated at Big Data London. Over the two-day event, word spread quickly about Maia’s ...
Learn more BlogSay Hello to Ask Matillion, Your New AI Assistant for Product Answers
We’re excited to introduce a powerful new addition to the Matillion experience: Ask Matillion.
Learn more BlogRethinking Data Pipeline Pricing
Discover how value-based data pipeline pricing improves ROI, controls costs, and scales data processing without billing surprises.
Learn more
Share: