Bring Your Own Cloud
Your Cloud. Your Data. Your Data Team.
OptimaFlo deploys into your own AWS or GCP account. Your data never leaves it, you keep the IAM boundary, and your cloud bill goes straight to AWS or GCP, not through us.
How BYOC Actually Works
BYOC is not a marketing label on top of a shared platform. It changes where your data and compute physically run.
Terraform builds the stack, storage, compute, and the data catalog, directly inside your own AWS or GCP project. Nothing sits in a shared OptimaFlo environment.
OptimaFlo authenticates with short-lived, scoped credentials: AWS STS AssumeRole or GCP Workload Identity Federation. No long-lived keys are stored or exchanged.
Compute and storage run on your own AWS or GCP account, billed to you by AWS or GCP. OptimaFlo does not mark up cloud usage.
An Apache Polaris catalog registers your storage location per workspace, so tables stay isolated between projects and queryable from tools you already use.
BYOC vs. a Fully-Hosted Platform
Neither approach is free. A fully-hosted platform trades control for convenience. BYOC trades convenience for control. Here is the honest tradeoff.
Faster to start: no cloud account or IAM setup required before your first pipeline.
Your data and query results live in the vendor's infrastructure, not yours.
Usage-based billing set by the vendor, on top of whatever they pay their own cloud provider.
Setup takes longer: a cloud account and IAM permissions come before the first pipeline.
Your data, tables, and query results stay inside your own AWS or GCP account at all times.
Flat plan price for the platform. Cloud compute and storage bill separately, at your cloud provider's cost.
The Access Control Under BYOC
Access control runs on Apache Polaris's own RBAC: grants at the catalog, namespace, table, and view level, not a bolted-on permission layer. Inside a workspace, five roles, owner, admin, member, analyst, and viewer, set who can build pipelines and who can only view results.
Every query through chat, dashboards, or the API writes to an audit log. Database policies allow inserts but block updates and deletes, so an entry can't be edited or removed after the fact.
This is the kind of control layer SOC 2 and HIPAA audits check for. OptimaFlo is not currently certified under either. If a certification is a hard requirement for your team, confirm that with us directly before you commit.
Pick Your Cloud
Cloud Run, Cloud Composer, GCS, and BigQuery, provisioned in your own GCP project.
See the detailsS3, Amazon MWAA, and IAM roles via STS AssumeRole, provisioned in your own AWS account.
See the detailsAlready comfortable with the tradeoffs? Read the GCP setup guide for the exact APIs, IAM roles, and deployment steps.
More data than people? Put an AI data team on it.
From raw data to live dashboards in one conversation.
Now in early beta. One flat plan, no per-query tax. Runs in your cloud. Your data never leaves.