Product · Secure Data Tunnel

AthenaDB Secure Data Tunnel

A planned application exchange path where AthenaDB securely fetches and moves data on behalf of your app. Short-lived tunnel keys are designed to rotate regularly across Lite, Server, and CSP deployments. This is request-driven app exchange, distinct from AthenaDB Sync's planned ongoing replica reconciliation.

Planned
Planned / Early Access design
Instance Trust FabricAthenaDB LiteAthenaDB Sync

Built for app providers

The approved design gives AthenaDB responsibility for the secure path: authenticate, rotate keys, fetch or push under policy, and return results to your app. This named product surface is not yet GA.

  • Designed for AthenaDB-mediated app exchange without a separate data API gateway
  • Planned bidirectional secure tunnel for moving data back and forth under policy
  • Short-lived session keys designed to rotate regularly
  • Planned across AthenaDB Lite, Server, and CSP Edition
  • Separate from whole or scoped replica synchronization

How it works

App asks AthenaDB
The planned flow starts when an application requests a fetch, push, or exchange through AthenaDB Lite or Server.
Tunnel opens with rotating keys
AthenaDB is designed to authenticate the peer, negotiate short-lived tunnel keys, and open a policy-governed path with rotation at session and lease boundaries.
Database moves the data
AthenaDB is designed to perform the transfer and return results or status to the app under Trust Fabric rules — structured, permission-filtered exchange, not raw remote SQL.

Lite, Server, and CSP

The planned model lets AthenaDB Lite open a tunnel from an embedded application, or AthenaDB Server do the same for a networked service. CSP Edition is designed to use that model on provider-operated nodes.

The tunnel rides AthenaDB’s Trust Fabric identity and Sync session cryptography — permission-filtered, auditable exchange rather than exposing raw remote SQL to every app.

Secure Data Tunnel serves request-driven application exchange. AthenaDB Sync is the separate planned model for whole or explicitly scoped two-way replica reconciliation after offline operation.

FAQ

Is this only for cloud service providers?
No. The design is product-wide: Lite in your app, AthenaDB Server, and CSP Edition alike. The named Secure Data Tunnel surface is Planned / Early Access, not GA.
Does my app still need an API gateway to fetch database data?
The planned AthenaDB-mediated exchange is designed to remove that requirement: your app asks AthenaDB, and AthenaDB handles the secure fetch or exchange.
How do the keys work?
The design negotiates short-lived tunnel keys that rotate regularly and discards prior session keys so later compromise of ephemeral material does not unlock older traffic.
Is it available now?
It is in Early Access planning. Trust Fabric identity and Sync session crypto foundations exist in the engine; the named Secure Data Tunnel product surface is being built.