Security

Built for teams that cannot put shadow AI on production databases.

DBGorilla is a centralized, IT-managed agent runtime. Your security team sets the policies. Agents mediate access. Changes are proven on clones before they touch production.

Security

Built for teams that cannot put shadow AI on production databases.

DBGorilla is a centralized, IT-managed agent runtime. Your security team sets the policies. Agents mediate access. Changes are proven on clones before they touch production.

How we think about access

How we think about access

AI next to your database should not mean unmanaged AI in your database

Most "chat with your database" setups put a model one hop from production credentials. That is easy for a developer and hard for security to live with.

DBGorilla is an intelligent layer between your team and your infrastructure — a runtime IT controls. People and tools talk to agents that already understand the environment. They do not get a free-form session on production by default.

Principles:

- Centralized runtime, not a personal plug-in

- Least privilege on every connection you attach

- Human approval on the path to production change

- Audit trail on investigations and actions

- Clone validation before risky change


Trust model

Trust model

Earn production trust the way a new hire would

You would not hand a new engineer unrestricted write access on day one. The runtime should work the same way: observe, explain, prove, then act only where you allow it.

Transparency

Findings in plain language: what was examined, what was hypothesized, what the proof showed.

Consent

Production-affecting change requires the approval path you configure.

Auditability

Who connected what, what was investigated, what was approved — available for review.

Boundaries

Roles, environments, and deployment posture define where the runtime can operate.

Reversibility

Prefer change paths you can describe how to undo; clones exist to test before you commit.

Isolation options

SaaS, private VPC / bring-your-own cloud, dedicated / on-prem, and air-gapped patterns for estates that need them.

Progressive authority

Progressive authority

Observe first. Act only where you unlock it.

Database changes must be explainable, reversible, and auditable. DBGorilla validates solutions on instant database clones with production-like workloads before anyone applies a change to the real system.

Clones are built for experimentation — not for copying your entire production estate into our cloud by default. Where PII handling matters, clones use PII-clean or mock data patterns so teams can test safely. **[CONFIRM: exact PII-scrub / masking behavior by deployment mode — SaaS vs customer VPC vs on-prem]**

You stay responsible for backups, change control, and production readiness. We give you proof and rollback paths — not a black box that “just ships the fix.”

01 Observe

Connect with the least privilege required — typically read-oriented access for analysis unless a feature you enable needs more. Agents learn topology, workload shape, and what "normal" looks like for your systems.

02 Recommend

Investigations surface root cause, options, and clone-backed proof where relevant. Humans decide what ships.

03 Act (where you enable it)

Only the action classes you authorize, under your roles and policies — still logged, still attributable.

Data handling

Data handling

Your databases stay yours.

DBGorilla processes the operational signals required to run the agent runtime: performance and workload metadata, investigation context, logs, and outputs tied to the features you use. Your databases are not stored by us as full copies in the ordinary course of the product.

What we protect
  • Encryption in transit (TLS)

  • Encryption at rest where appropriate for stored secrets and platform data [CONFIRM scope]

  • Encrypted handling of credentials and configs you provide [CONFIRM KMS story]

  • MFA and least privilege for privileged internal access

  • Retention aligned to plan (product data) plus minimum retention for security/audit logs [

What we are not here to harvest:
  • Your row-level business content as a training corpus for other customers

  • Unrelated application secrets beyond the access you intentionally grant

Enterprise customers can negotiate DPAs, security addenda, retention, and dedicated tenancy under a signed agreement.

Deployment

Meet the environment you already have.

Privacy and compliance requirements are why many of our best-fit customers cannot “just move everything to a managed cloud.” DBGorilla supports deployment postures that match that reality:

SaaS

Fastest path to value with DBGorilla-hosted control plane

Private VPC / bring-your-own cloud
Private VPC / bring-your
-own cloud

Keep data paths inside your cloud boundary (Business+)

Dedicated / on-prem

Enterprise fleets and procurement-driven installs

Air-gapped

Environments that cannot depend on public network egress

Enterprise plans can include dedicated tenancy, custom data retention, custom security terms, and compliance documentation under a negotiated agreement.

Compliance & assurance

Built for the questionnaire — not around it.

Security and procurement teams should not have to reverse-engineer an AI product from a demo. We support enterprise review with clear architecture answers, security documentation, and plan features that map to common controls (SSO, RBAC, audit export, dedicated deploy).

SOC 2

Pricing promises “SOC 2 & compliance support” on Enterprise.

Security questionnaire

Prefer a single intake (security@ or contact-sales) and a standard packet (architecture overview, data flow, subprocessors).

Penetration testing

Customer-initiated testing of the Services requires prior written consent per Terms. We can discuss coordinated testing under NDA for Enterprise.

ADD LINKS????- Privacy Policy | Terms of Service | Contact sales / security review| Product docs (deployment & access)

Compliance

Built for the questionnaire — not around it.

Security and procurement teams should not have to reverse-engineer an AI product from a demo. We support enterprise review with clear architecture answers, security documentation, and plan features that map to common controls (SSO, RBAC, audit export, dedicated deploy).

Current
  • IT-managed access: RBAC, SSO (OIDC/SAML) on Business+; Enterprise adds SCIM and custom roles

  • Audit log export on Business+

  • Deployment options above for regulated buyers

  • Privacy Policy and Terms

In progress / support
  • SOC 2 — say only what is true: certified, in audit, or "compliance support / questionnaire packet."

  • DPA / security questionnaire process for procurement

Planned or by arrangement
  • Coordinated penetration testing under written agreement (customer-initiated testing of the Services requires prior consent per Terms)

ADD LINKS????- Privacy Policy | Terms of Service | Contact sales / security review| Product docs (deployment & access)

Shared responsibility

We secure the platform. You secure the connections.

DBGorilla is not a substitute for your security, compliance, or DBA teams. You remain responsible for:

Credentials, IAM roles, and database permissions you grant
Change control and production approvals
Backups, disaster recovery, and regulatory obligations on your data
How your organization uses Output and connected third-party tools

The runtime is designed so those responsibilities are enforceable — roles, audit, least privilege, deployment choice — instead of hoping a personal AI tool stays inside policy.