Skip to main content

How it works — query data without moving it

From query to answer — without moving your data.

Instead of moving your data to the users, Virtual Data Platform brings the query to the data. Here is what happens between a question and its answer.

See the platform in action

A quick, silent click-through of the Portal — from the dashboard to locations and gateways, system lines, Virtual Datasets and the Test Bench.

The request lifecycle

  1. 1

    Authenticate

    The client signs in with Microsoft Entra ID. The user's identity — not a service account — travels with the request.

  2. 2

    Validate

    The Dispatcher validates the request and the user's licenses and access before any work begins.

  3. 3

    Sandbox

    A private, isolated sandbox spins up — your sandbox is ready in under 100 ms, with secure R and Python runtimes inside.

  4. 4

    Route

    The platform routes the query — via the MessageQueue and the Gateway's gRPC proxy — to the Gateway at the right one of your locations. Gateways connect outbound only.

  5. 5

    Query at source

    The Gateway translates the user's identity to what the source speaks and executes the query live against the system.

  6. 6

    Stream back

    Results stream back end-to-end encrypted into the sandbox, where a secure in-memory database combines them at memory speed. Nothing is written to disk.

Virtual Data Platform architectureHow a query travels from your tools through the Azure platform to data at your locations and back.IdentityYour toolsPlatform (Your tenant)Your locationsissues tokensvalidates tokenEntra IDExcelvia our Excel Add-inPower BIvia SQL endpointRvia our R packagePythonvia our Python packageAny AI/MCP clientvia MCP endpointAny SQL clientvia SQL endpointAny OData clientvia OData endpointUniversal ConnectorTDSRESTODataMCP ServerAPI Gateway · firewallAPI Gateway · firewallDispatchermodeling logicRPythonPer-user sandboxone isolated sandbox per user — many run in parallelCentral servicesConfiguration APIMetadata APIInsights APIRealtime ServicesGraph API+ moreSandboxManager APIorchestrates every sandboxMessageQueueProxy · gRPCbidirectional gRPC streamconnected outbound by the GatewayYour HQGatewaySAP BWSAP HANASQL ServerYour subsidiaryGatewaySnowflakeSalesforceSharePointWorkday+ moreYour toolsExcel · R · Python · Any AI/MCP client · Power BIPlatform (Your tenant)DispatcherPer-user sandboxmodeling logic · R · PythonYour locationsGatewayoutbound onlyno inbound firewall rulesSAP · Snowflake · SharePoint · + more
  • TLS on every connection
  • end-to-end encrypted
  • outbound only — no inbound rules
  • 1–6 · the request lifecycle
Every request carries a Microsoft Entra ID token — your identity provider remains the root of trust. The Dispatcher validates the token and the request, then provides a private sandbox. The platform routes it to the Gateway at the right one of your locations; the Gateway — connected outbound only — translates the user's identity to whatever the source speaks (SAP Logon Ticket, SAML, legacy credentials), queries the system and streams results back end-to-end encrypted into the user's sandbox — one of many running in parallel, one per active user. The sandbox is the brain of the request: it executes the modeling logic and combines data across systems in a secure in-memory database at memory speed. For the Portal, the Excel add-in, R and Python, that encryption extends all the way into the client. Nothing is written to disk. Nothing is exposed. Your HQ runs SAP BW, SAP HANA, SQL Server, each connected through its connector to the Gateway, which holds one outbound gRPC stream to the platform. Your subsidiary runs Snowflake, Salesforce, SharePoint, Workday, each connected through its connector to the Gateway, which holds one outbound gRPC stream to the platform.

Why virtual beats copied

Time to first answer

ETL / warehouse
Weeks to months — build a pipeline first
Virtual Data Platform
Minutes — model a Virtual Dataset and query

Freshness

ETL / warehouse
As fresh as the last load
Virtual Data Platform
Live — queried at the source on every refresh

Governance surface

ETL / warehouse
A second copy and a second permission system to secure
Virtual Data Platform
No copy; the source's own permissions apply per user

Infrastructure cost

ETL / warehouse
Storage, compute and pipelines to run and reconcile
Virtual Data Platform
No central store — compute runs per query, then disappears

See your own data live in 30 minutes.

Start with a live demo — we'll show your use case in Excel, Power BI, R, or through an AI assistant. Then take it further with a free trial in your own isolated tenant.

Virtual Data Platform