Checking access…
US Telco data reaches Eureka via two paths: SFTP over SSH for batch file transfers, and Google Analytics Hub for direct BigQuery-to-BigQuery data sharing. Data landing in Eureka's GCP BigQuery replicates to AWS S3. Clients pull directly from S3 via STS AssumeRole temporary credentials.
Three telco datasets aggregate daily in Telco's GCP environment via Dataflow, land in GCS as Parquet, and leave at 02:00 UTC via the secure channel. Cloud KMS CMEK encrypts everything at rest before it moves.
~750M rows/day. First-party browsing signals, Parquet-encoded, partitioned by date.
~250M pings/day. GPS + network location signals for venue-level visitation.
60M subscribers, monthly refresh. Age, income, zip, segment — enrichment layer for all products.
5-min micro-batch aggregation. Daily export trigger at 02:00 UTC into staging GCS bucket. CMEK AES-256 throughout.
Data never touches the public internet. SFTP over SSH with PGP-encrypted payloads is the primary transfer method. SHA-256 checksums verify every file on receipt.
SSH Key Auth — PGP-signed payloads. No public internet routing.
Every payload signed. Signature verified on receipt before processing.
Checksum on every file on receipt. Mismatch triggers alert + retry.
KMS-SSE applied at write. MFA Delete active. VPC-only endpoint.
Three prefixes — one per product. But each client that accesses a product gets their own dedicated IAM role scoped to that prefix. Ten clients on Omni-Alpha means ten roles, all pointing at /omni-alpha/ — individually revocable, individually auditable. Bucket-level controls apply to all: VPC-only endpoint, KMS-SSE, MFA Delete, Object Lock (COMPLIANCE mode), no public access.
| Product | S3 Prefix | IAM Role Pattern | Roles Created | Active Window | Archive Policy |
|---|---|---|---|---|---|
| Omni-Alpha | /omni-alpha/YYYY-MM-DD/ | omni-alpha-{client}-reader | 1 per client | 12 months | Glacier IR → Deep Archive |
| Omni-Growth | /omni-growth/YYYY-MM-DD/ | omni-growth-{client}-reader | 1 per client | 12 months | Glacier IR → Deep Archive |
| Omni-Pinpoint | /omni-pinpoint/YYYY-MM-DD/ | omni-pinpoint-{client}-reader | 1 per client | 12 months | Glacier IR → Deep Archive |
Why one role per client — not one role per product?
✗ One shared role per product
✓ One role per client per product
s3:prefix condition pointing to the same product prefix — the prefix controls what data, the role controls who can access it.No client ever receives a long-lived AWS access key. Access is granted through one of two models: STS AssumeRole for standard per-client access, and S3 Access Points for clients requiring multiple products simultaneously.
Each client gets their own IAM role in Eureka's AWS account, with a trust policy allowing only that client's AWS account to assume it. They call sts:AssumeRole to get temporary credentials valid for 1–12 hours. No static keys ever leave Eureka.
s3:prefix conditionWhen a client needs access to multiple products (e.g., Growth + Pinpoint), each gets a dedicated S3 Access Point with its own ARN, bucket policy, and network control — fully isolated from other clients and other products.
STS AssumeRole Flow
sts:AssumeRoleClient × Access Method Matrix
| Client | Product(s) | Access Method | Has AWS Account? | Credential TTL | Multi-Product? |
|---|---|---|---|---|---|
| Client 1 | Omni-Alpha | Tier 1 — STS AssumeRole | Yes | 4 hr | No |
| Client 2 | Omni-Growth | Tier 1 — STS AssumeRole | Yes | 4 hr | No |
| Client 3 | Omni-Growth Omni-Pinpoint | Tier 2 — S3 Access Points | Yes | 4 hr | Yes — 2 APs |
| Client 4 | Omni-Pinpoint | Tier 1 — STS AssumeRole | Yes | 4 hr | No |
Data arrives in Eureka's BigQuery via two paths: Analytics Hub direct data sharing from US Telco's GCP, and replication from Eureka's AWS S3. All data stays inside Eureka's Google Cloud project — column-level security, row-level access policies, VPC Service Controls, and Data Catalog lineage applied across every dataset. BigQuery feeds all three product UIs via Analytics Hub grants — no data copy leaves the platform.
Dataset eureka.omni_alpha. Signal browsing, custom date ranges, column masking. Access-tier scoped to subscriber.
Dataset eureka.omni_growth. Category foot traffic, web indexing, demographic cross-tabs. Row-level security per client.
Dataset eureka.omni_pinpoint. Geospatial queries, trade area analysis. k-anonymity suppression below 50 devices/venue/day.
Security controls active in Eureka Google Cloud
Every data movement, access event, and lifecycle change is observable and verifiable by Telco, with contractual audit rights available at any time.
Transparency pillars
The DPA gives Telco the right to appoint an independent auditor annually, with access to any 90-day CloudTrail + BigQuery audit window on request.
AWS CloudTrail + S3 Access Logs streamed to Telco's SIEM via Kinesis Firehose (<60 s). Every GetObject, AssumeRole, and PutObject is tagged with timestamp, requester identity, and IP.
Transparency cadence
| Pillar | Frequency | Delivery channel | Contents |
|---|---|---|---|
| 01 · Third-Party Audit | Annual + on demand | Independent auditor appointed by Telco | Full DPA review; any 90-day CloudTrail + BQ audit window |
| 02 · Shared Audit Logs | On demand | Telco SIEM via Kinesis Firehose | Requester, object key, HTTP status, source IP, timestamp |
Controls Telco holds unilaterally
What Eureka commits to
Plain-English guide to all cost models, assumptions, and caveats across every product page.