— DATAFACTORY SHIELD

ETL pipelines, the SOC blind spot.

FLUX audits the ETL layer most cloud-security tools ignore: Azure Data Factory, Azure Synapse, and Cloud Composer. Flags credential-in-pipeline, sensitive-data-in-logs, and pipeline misconfiguration with consent-gated remediation. custom pricing standalone or part of the Data Pack.

ETL pipelines are where credentials hide, where PHI lands in error logs, and where service principals quietly hold owner rights on production. Most SIEMs and CSPMs do not look here. FLUX does.

Forty-plus auto-fix playbooks for the misconfigurations that matter.

Four capabilities, one license.

Pipeline security

ADF, Glue, Step Functions, Dataflow

Audits every pipeline definition, every linked service, and every dataset for credential references, public storage targets, and cross-tenant authentication.

Azure ADF · Azure Synapse
Credential detection

Credential-in-pipeline scanner

Detects hard-coded secrets, expired connection strings, and SAS tokens with excessive scope or lifetime. Flags within minutes of pipeline publication.

DLP · secrets scanning
Logs scanner

Sensitive-data-in-logs

Reads pipeline logs and flags PHI, PII, PCI, and source-code patterns leaking through error traces. Suggests log-redaction policies.

PHI / PII / PCI
Airflow

Managed Airflow audit

MWAA and Cloud Composer DAG audit, including connection-secret review, public-Internet egress detection, and DAG-permission drift.

MWAA · Cloud Composer

See your environment in ten minutes.

Read-only scan. No credit card. Full evidence pack on every finding.