dtwo Policy Store

Policies tagged "sql"

bigquery · ingress

Block BigQuery Exfiltration and Cross-Project Writes

Inspects the raw GoogleSQL string carried by BigQuery SQL tools and denies any statement that moves data out of the tenant's own project — even when the call…

bigqueryguard-warehouse-exportingresssqlexfiltrationsoc2pci-dssgdpr-ccpa

notion · ingress

Block Destructive and Export SQL on Notion Data Sources

Inspects Notion data-source query tool calls (notion-query-data-sources on the hosted server, query-data-source on the official local server) and denies any…

notionguard-warehouse-sqlingresssqlreadonlysoc2

snowflake · ingress

Block Destructive and Mutating Snowflake SQL

Inspects the SQL text that Snowflake MCP tools carry in their query argument and denies any statement in a mutating or destructive class — DROP, TRUNCATE,…

snowflakeguard-warehouse-sqlingresssqlreadonlysoc2pci-dsssox

bigquery · ingress

Block Destructive SQL in BigQuery Queries

Inspects the raw GoogleSQL string carried by BigQuery write-capable query tools and denies any statement in a state-changing class — DML…

bigqueryguard-warehouse-sqlingresssqlreadonlysoc2pci-dsssox

databricks · ingress

Guard Databricks SQL Against Writes and DDL

Inspects the SQL statement string that Databricks SQL-executing tools carry in their argument and denies any statement that performs a write, schema change,…

databricksguard-warehouse-sqlingresssqlreadonlypci-dsssoxsoc2