Your data stays where you can see it.
Beetl reads from your systems, works on a copy, and writes only where you have said it may. Everything it runs is SQL your team can read, and every change waits for a person to approve it.
Hosted in Germany · read-only by default
Processed in the EU, kept in open tables.
Beetl runs on infrastructure in Germany. What it produces is stored as open Delta Lake tables, so the data stays readable by your own tools, and can be delivered to storage you own.
What we commit to.
Beetl reads from your source systems and never modifies them. A write goes only to a destination you have explicitly approved.
Beetl runs on Hetzner infrastructure in Germany. Your data is not processed on a US cloud.
New pipelines, new rules and deploys wait for someone on your side or ours to approve them, including changes an AI assistant proposes.
Every run is kept with the query behind it, and every call made through Beetl's MCP server is logged.
Mappings and business rules are SQL and mapping definitions, versioned with a working and a deployed copy. There is no black box to trust.
Systems inside your network are reached through a small connector that opens an outbound connection, so your firewall stays closed.
FAQ
Can Beetl change data in our ERP?
Where is Beetl hosted?
What about systems that cannot be reached from outside our network?
Who do we ask about security or data protection?
Send us your security questionnaire.
We answer it before any access is granted, and walk your team through the setup.