Transforms are deployed on a Transform Server, which typically has access to the data it is required to interact with. This could be in an environment with elevated permissions, to perform tasks such as SQL queries, access to internal documents, or scanning of log-files within a secure environment.
Only a Transform Distribution Server (TDS) connects to this Transform Server.