Product · Secure Data Tunnel
AthenaDB Secure Data Tunnel
A planned application exchange path where AthenaDB securely fetches and moves data on behalf of your app. Short-lived tunnel keys are designed to rotate regularly across Lite, Server, and CSP deployments. This is request-driven app exchange, distinct from AthenaDB Sync's planned ongoing replica reconciliation.
Built for app providers
The approved design gives AthenaDB responsibility for the secure path: authenticate, rotate keys, fetch or push under policy, and return results to your app. This named product surface is not yet GA.
- Designed for AthenaDB-mediated app exchange without a separate data API gateway
- Planned bidirectional secure tunnel for moving data back and forth under policy
- Short-lived session keys designed to rotate regularly
- Planned across AthenaDB Lite, Server, and CSP Edition
- Separate from whole or scoped replica synchronization
How it works
Lite, Server, and CSP
The planned model lets AthenaDB Lite open a tunnel from an embedded application, or AthenaDB Server do the same for a networked service. CSP Edition is designed to use that model on provider-operated nodes.
The tunnel rides AthenaDB’s Trust Fabric identity and Sync session cryptography — permission-filtered, auditable exchange rather than exposing raw remote SQL to every app.
Secure Data Tunnel serves request-driven application exchange. AthenaDB Sync is the separate planned model for whole or explicitly scoped two-way replica reconciliation after offline operation.
FAQ
- Is this only for cloud service providers?
- No. The design is product-wide: Lite in your app, AthenaDB Server, and CSP Edition alike. The named Secure Data Tunnel surface is Planned / Early Access, not GA.
- Does my app still need an API gateway to fetch database data?
- The planned AthenaDB-mediated exchange is designed to remove that requirement: your app asks AthenaDB, and AthenaDB handles the secure fetch or exchange.
- How do the keys work?
- The design negotiates short-lived tunnel keys that rotate regularly and discards prior session keys so later compromise of ephemeral material does not unlock older traffic.
- Is it available now?
- It is in Early Access planning. Trust Fabric identity and Sync session crypto foundations exist in the engine; the named Secure Data Tunnel product surface is being built.

