AI next to your database should not mean unmanaged AI in your database
Most "chat with your database" setups put a model one hop from production credentials. That is easy for a developer and hard for security to live with.
DBGorilla is an intelligent layer between your team and your infrastructure — a runtime IT controls. People and tools talk to agents that already understand the environment. They do not get a free-form session on production by default.
Principles:
- Centralized runtime, not a personal plug-in
- Least privilege on every connection you attach
- Human approval on the path to production change
- Audit trail on investigations and actions
- Clone validation before risky change
Earn production trust the way a new hire would
You would not hand a new engineer unrestricted write access on day one. The runtime should work the same way: observe, explain, prove, then act only where you allow it.
Transparency
Findings in plain language: what was examined, what was hypothesized, what the proof showed.
Consent
Production-affecting change requires the approval path you configure.
Auditability
Who connected what, what was investigated, what was approved — available for review.
Boundaries
Roles, environments, and deployment posture define where the runtime can operate.
Reversibility
Prefer change paths you can describe how to undo; clones exist to test before you commit.
Isolation options
SaaS, private VPC / bring-your-own cloud, dedicated / on-prem, and air-gapped patterns for estates that need them.
Observe first. Act only where you unlock it.
Database changes must be explainable, reversible, and auditable. DBGorilla validates solutions on instant database clones with production-like workloads before anyone applies a change to the real system.
Clones are built for experimentation — not for copying your entire production estate into our cloud by default. Where PII handling matters, clones use PII-clean or mock data patterns so teams can test safely. **[CONFIRM: exact PII-scrub / masking behavior by deployment mode — SaaS vs customer VPC vs on-prem]**
You stay responsible for backups, change control, and production readiness. We give you proof and rollback paths — not a black box that “just ships the fix.”
01 Observe
Connect with the least privilege required — typically read-oriented access for analysis unless a feature you enable needs more. Agents learn topology, workload shape, and what "normal" looks like for your systems.
02 Recommend
Investigations surface root cause, options, and clone-backed proof where relevant. Humans decide what ships.
03 Act (where you enable it)
Only the action classes you authorize, under your roles and policies — still logged, still attributable.
Your databases stay yours.
DBGorilla processes the operational signals required to run the agent runtime: performance and workload metadata, investigation context, logs, and outputs tied to the features you use. Your databases are not stored by us as full copies in the ordinary course of the product.
What we protect
Encryption in transit (TLS)
Encryption at rest where appropriate for stored secrets and platform data [CONFIRM scope]
Encrypted handling of credentials and configs you provide [CONFIRM KMS story]
MFA and least privilege for privileged internal access
Retention aligned to plan (product data) plus minimum retention for security/audit logs [
What we are not here to harvest:
Your row-level business content as a training corpus for other customers
Unrelated application secrets beyond the access you intentionally grant
Enterprise customers can negotiate DPAs, security addenda, retention, and dedicated tenancy under a signed agreement.
Deployment
Meet the environment you already have.
Privacy and compliance requirements are why many of our best-fit customers cannot “just move everything to a managed cloud.” DBGorilla supports deployment postures that match that reality:
SaaS
Fastest path to value with DBGorilla-hosted control plane
Keep data paths inside your cloud boundary (Business+)
Dedicated / on-prem
Enterprise fleets and procurement-driven installs
Air-gapped
Environments that cannot depend on public network egress
Enterprise plans can include dedicated tenancy, custom data retention, custom security terms, and compliance documentation under a negotiated agreement.
Compliance & assurance
Built for the questionnaire — not around it.
Security and procurement teams should not have to reverse-engineer an AI product from a demo. We support enterprise review with clear architecture answers, security documentation, and plan features that map to common controls (SSO, RBAC, audit export, dedicated deploy).
SOC 2
Pricing promises “SOC 2 & compliance support” on Enterprise.
Security questionnaire
Prefer a single intake (security@ or contact-sales) and a standard packet (architecture overview, data flow, subprocessors).
Penetration testing
Customer-initiated testing of the Services requires prior written consent per Terms. We can discuss coordinated testing under NDA for Enterprise.
ADD LINKS????- Privacy Policy | Terms of Service | Contact sales / security review| Product docs (deployment & access)
Compliance
Built for the questionnaire — not around it.
Security and procurement teams should not have to reverse-engineer an AI product from a demo. We support enterprise review with clear architecture answers, security documentation, and plan features that map to common controls (SSO, RBAC, audit export, dedicated deploy).
Current
IT-managed access: RBAC, SSO (OIDC/SAML) on Business+; Enterprise adds SCIM and custom roles
Audit log export on Business+
Deployment options above for regulated buyers
Privacy Policy and Terms
In progress / support
SOC 2 — say only what is true: certified, in audit, or "compliance support / questionnaire packet."
DPA / security questionnaire process for procurement
Planned or by arrangement
Coordinated penetration testing under written agreement (customer-initiated testing of the Services requires prior consent per Terms)
ADD LINKS????- Privacy Policy | Terms of Service | Contact sales / security review| Product docs (deployment & access)
Shared responsibility
We secure the platform. You secure the connections.
DBGorilla is not a substitute for your security, compliance, or DBA teams. You remain responsible for:
Credentials, IAM roles, and database permissions you grant
Change control and production approvals
Backups, disaster recovery, and regulatory obligations on your data
How your organization uses Output and connected third-party tools
The runtime is designed so those responsibilities are enforceable — roles, audit, least privilege, deployment choice — instead of hoping a personal AI tool stays inside policy.
