Skip to main content

Bring Your Own Cloud

Your Cloud. Your Data. Your Data Team.

OptimaFlo deploys into your own AWS or GCP account. Your data never leaves it, you keep the IAM boundary, and your cloud bill goes straight to AWS or GCP, not through us.

How BYOC Actually Works

BYOC is not a marketing label on top of a shared platform. It changes where your data and compute physically run.

Deploys into your account

Terraform builds the stack, storage, compute, and the data catalog, directly inside your own AWS or GCP project. Nothing sits in a shared OptimaFlo environment.

You keep the IAM boundary

OptimaFlo authenticates with short-lived, scoped credentials: AWS STS AssumeRole or GCP Workload Identity Federation. No long-lived keys are stored or exchanged.

You pay your cloud bill directly

Compute and storage run on your own AWS or GCP account, billed to you by AWS or GCP. OptimaFlo does not mark up cloud usage.

Each workspace gets its own catalog

An Apache Polaris catalog registers your storage location per workspace, so tables stay isolated between projects and queryable from tools you already use.

BYOC vs. a Fully-Hosted Platform

Neither approach is free. A fully-hosted platform trades control for convenience. BYOC trades convenience for control. Here is the honest tradeoff.

Fully-hosted platform

Faster to start: no cloud account or IAM setup required before your first pipeline.

Your data and query results live in the vendor's infrastructure, not yours.

Usage-based billing set by the vendor, on top of whatever they pay their own cloud provider.

OptimaFlo BYOC

Setup takes longer: a cloud account and IAM permissions come before the first pipeline.

Your data, tables, and query results stay inside your own AWS or GCP account at all times.

Flat plan price for the platform. Cloud compute and storage bill separately, at your cloud provider's cost.

The Access Control Under BYOC

Native catalog-level RBAC

Access control runs on Apache Polaris's own RBAC: grants at the catalog, namespace, table, and view level, not a bolted-on permission layer. Inside a workspace, five roles, owner, admin, member, analyst, and viewer, set who can build pipelines and who can only view results.

Append-only audit logging

Every query through chat, dashboards, or the API writes to an audit log. Database policies allow inserts but block updates and deletes, so an entry can't be edited or removed after the fact.

This is the kind of control layer SOC 2 and HIPAA audits check for. OptimaFlo is not currently certified under either. If a certification is a hard requirement for your team, confirm that with us directly before you commit.

Pick Your Cloud

BYOC on GCP

Cloud Run, Cloud Composer, GCS, and BigQuery, provisioned in your own GCP project.

See the details
BYOC on AWS

S3, Amazon MWAA, and IAM roles via STS AssumeRole, provisioned in your own AWS account.

See the details

Already comfortable with the tradeoffs? Read the GCP setup guide for the exact APIs, IAM roles, and deployment steps.

More data than people? Put an AI data team on it.

From raw data to live dashboards in one conversation.

Now in early beta. One flat plan, no per-query tax. Runs in your cloud. Your data never leaves.

We value your privacy

We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. You can customize your preferences or learn more in our Cookie Policy and Privacy Policy.