Your first-party data, activated — without it ever leaving your cloud.
The Marketing Data Foundation deploys a brand-owned, secure marketing-data environment into your own AWS or GCP account in days. 1P data lands, identity resolves, and audiences flow out to media — clean-room-matched and consent-governed at the edge — so PII never leaves your governance. The bridge between hardened enterprise systems and the adtech ecosystem.
Deploys in your own AWS or GCP account · you own the data and the keys
You've got the first-party data. There's nowhere safe to use it.
Cookies are dying, identity coverage collapsed, and every audience you push to Meta or Google copies PII out to a platform your security team can't govern. The data exists — but there's no sanctioned place to land it, match it, and activate it.
- Copy PII out to martech SaaS and you own the liability — pixel/CIPA suits hit 800+ in 2025, with a $46M healthcare settlement.
- Cram it into the hardened data warehouse and it can't move at marketing speed — so marketing routes around IT into shadow tools anyway.
- Build it bespoke and it's an SI project: $300K–$1M+ and a year, or 3–5 data engineers you don't have.
Connect your cloud, we deploy the Foundation, your data goes to work — governed.
Fixed-scope and productized, end to end. It deploys into your own AWS or GCP account; you own the environment, the data and the keys from day one.
Connect your cloud
You grant a customer-revocable role in your own AWS or GCP account. No standing admin, no data leaves.
We deploy the Foundation
The full environment is provisioned: ingest, PII vault, identity, governed compute, clean-room and activation — pre-wired.
Data lands & resolves
1P data, behavioral streams and creative flow in; identity resolves; audiences and models build — all inside your boundary.
Activate, governed
Matched audiences flow out to media with consent & suppression enforced at the edge. PII stays in; every push is audit-logged.
A complete marketing-data environment — and the governance that keeps it safe.
Everything below is deployed into your own AWS or GCP account and handed over running. Not a clean room, not another CDP — the secure environment that ties them together, operable by your marketing team, not a pipeline org.
Environment deployed
your cloudProvisioned, hardened, and wired together — AWS or GCP.
- Ingest — streaming + batch1P PII, CRM, web/app behavioral & engagement streams, creative + performance data, and AI/agentic datasets land in one place.
- PII vault + identityEncrypted with your own keys, tokenized; identity resolution built in, with pluggable LiveRamp / UID2 / ID5. The only copy of raw PII — and it never leaves.
- Governed compute zoneWarehouse / lakehouse for audience building, enrichment, modeling, BI and agentic workloads — scoped by policy to the vault.
- Clean-room connectorsPre-wired to AWS Clean Rooms / BigQuery / Snowflake DCR and the walled gardens — match without PII leaving.
- Governed activationOutbound to Meta CAPI, Google, TikTok, CTV — only matched, consented audiences flow out.
Governance & evidence
privacy by constructionThe layer that ends the marketing-vs-IT standoff — built in, not bolted on.
- Consent & suppression at the edgeEvery activation enforces consent and suppression before a record leaves. No leaky CSV uploads.
- Deletion / DSAR propagationRight-to-delete propagates across the adtech tail — the gap that drives CIPA, MHMDA and Delete Act exposure.
- Attestation pack + auditMachine-generated control mapping, immutable audit trail and a data-residency posture your CISO can sign.
Start governed. Add isolation as your data demands it.
One capability, three isolation postures on the same spine — so "compliant at the core" is a ladder you climb, not a box you buy once. Compliant and hardware-isolated are separate axes: every tier is compliance-eligible; the higher tiers add hardware isolation.
1 · Lakehouse + Activation · available now
Your secure marketing-data environment: network + logical + cryptographic isolation — customer-managed keys, private-only endpoints, clean-room privacy rules. HIPAA-eligible under a BAA. The fast, cost-effective enablement tier — offered as a tool you run, or a service we run for you.
2 · Confidential / Hybrid · near-term
Hardware-enforced privacy for data in use — sensitive matching runs inside a confidential-computing enclave (AWS Nitro Enclaves / GCP Confidential Space) with attestation, so not even the cloud provider can read it. Lighter-weight than a full private cloud, for privacy-preserving multi-party collaboration.
3 · True Private Cloud · premium
Single-tenant hardware end to end — dedicated hosts / sole-tenant nodes, single-tenant HSM, self-run warehouse, up to air-gapped on-prem. Provable, hardware-isolated, compliant at the core. For regulated workloads with a contractual isolation requirement.
One blueprint, configured for your vertical — not rebuilt for it.
Fixed-scope, productized editions. Custom is the last option.
Each edition is the same Foundation plus a configuration profile — guardrails, default policies, data-handling templates and an attestation pack — so regulated coverage is a setting, not a bespoke project. Core ships first; regulated editions follow on the same spine.
- Core (Commercial) — retail / CPG / DTC / B2B. The full secure environment with standard consent & suppression governance. Available now.
- Healthcare / Pharma (HIPAA) — PHI controls, BAA-ready posture, k-anonymity join thresholds, pixel-free activation. Next.
- Financial Services (GLBA) — GLBA + state-amendment controls, purpose limitation, FinServ attestation pack. Next.
Need something bespoke?
Custom schemas, a net-new connector, or a topology outside the editions live in a separate, premium Custom engagement — scoped to you. It's the last option, not the default.
Talk to us about CustomPublished, fixed-scope pricing. A fraction of a bespoke build.
Year-1 ~$70–270K all-in vs $630K–$900K+ for a suite-CDP or SI build. You own the environment — no per-MTU SaaS meter. Looking for the SOC 2 landing zone? It's here →
Your data, your cloud, your keys. PII never leaves.
You own everything
Your AWS or GCP account, your data, your keys, your spend. The Foundation deploys into your account — we never hold your data, and there's no per-MTU SaaS meter.
PII never leaves governance
Raw PII lives only in your vault. Matching happens in clean rooms; only consented, suppressed, matched audiences flow out — every push audit-logged.
Revocable, least-privilege
We operate through a role you can revoke at any time. No standing admin, no money movement, no lock-in. Revoke it and the environment is yours alone.
Straight answers about the boundary.
Does our PII ever leave our cloud?
AWS or GCP?
Is this a CDP or a clean room?
What's productized vs custom?
What does it cost to run?
Looking for the SOC 2 landing zone?
Bring the work to your data.
Stand up a secure, brand-owned marketing-data environment in your own AWS or GCP cloud — 1P data activated, PII never leaving your governance — in days, not a 12-month build.