Datlas Enterprise
Datlas Enterprise

Database access control for the whole company.

Everyone signs in with the company account and reaches only the databases, schemas and actions their role allows. Every query is audited, and no one gets a database password.

SSO with Google, Microsoft or OktaRole-based permissionsAudit of every query
For the people using it

Sign in. Everything is already there.

Business users configure nothing. On sign-in, Datlas brings the projects their role allows, with the team’s queries, dashboards and context.

Sign in with the company account

Google, Microsoft Entra ID or any OIDC provider, with the MFA the company already uses.

Get what the role allows

Allowed projects, sources and schemas appear by themselves. Access removed, they leave the computer.

Ask in plain language

The AI writes SQL from the database’s real structure. People check it before it runs.

Share with the team

Queries, dashboards, alerts and AI context synced for everyone in the project.

Architecture

Two thousand people. One connector. Zero open ports.

People talk only to Datlas, over the internet, with the company sign-in. The connector talks to the databases; IT installs it once inside the company network. It only makes outbound connections: nothing from outside gets in.

0open ports or allowed IPs on the database
1install by IT, with one command
60 smaximum validity of each signed command
For the IT team

Ready in an afternoon.

No integration project. Three steps, and from then on registered sources connect by themselves.

1

Company sign-in

In the Datlas console, connect your identity provider (OIDC). Everyone signs in with the corporate account.

2

Connector in the network

Create the connector in the console and run the line it shows on a server that reaches the databases. No configuration file.

docker run -d --restart unless-stopped \
  -v datlas-connector:/data \
  -e DATLAS_ENROLL_TOKEN=one-time-token \
  ghcr.io/cendyandreoli/datlas-connector
3

Sources and permissions

Register the databases and decide who sees what, by project, source or schema. Sources connect through the connector by themselves, and people get the projects at their next sign-in.

Full connector documentation (and instructions for AI agents) →

Security

Built to pass your security team’s review.

Everything below is in the product today.

Outbound connections only

The connector opens a TLS channel to Datlas and keeps it open. No inbound port, no exposed database, no IP to allow.

Key-based authentication, no reusable secret

The connector creates its own key and hands over only the public half. Each connection proves who it is by signing a fresh challenge. The install token works once, for one hour.

Signed commands and answers

Each command is valid for 60 seconds and runs once. Each answer comes back signed. No one in the middle can inject, replay or alter a query.

Passwords sealed for the connector

Database credentials arrive encrypted with the connector’s key. Only it can open them. Datlas keeps only ciphertext.

SSO, MFA and controlled sessions

OIDC with PKCE, required MFA for Datlas accounts, sessions that end at once when someone leaves or loses access.

Role-based permissions

Read, copy, export, AI and changes granted by project, source and schema, to people or groups. The server authorizes every operation.

Protected production

Expensive queries are refused by their execution plan, with row, byte and time limits. Read-only by default.

Governed changes

Database edits only where the policy allows, always in a transaction reviewed before commit.

Tamper-evident audit

Who did what, on which database, through which connector and when. Hash-chained records with verifiable receipts and export.

AI under company control

Provider, model and key set by administrators. The AI sees the database structure; data samples only if administrators allow them, and every request is recorded.

Instant revocation

One click in the console turns off a connector, a session or a person. No waiting for expiry.

Restricted reach

IT can limit which databases each connector may reach. It never becomes a bridge to the rest of the network.

Deployment

The way your company requires.

Recommended

Datlas cloud + connector

We run Datlas. The connector stays in your network.

  • Ready in an afternoon
  • Databases and passwords never leave your network
  • Updates with no work for IT
High availability

Replicated connector

For critical operations.

  • Two or more replicas sharing one identity
  • Health checks and Prometheus metrics
  • Key rotation without reinstalling
Regulated

In your cloud

All of Datlas inside your infrastructure.

  • Nothing leaves your environment
  • Your IdP, your logs, your network
  • For banking, healthcare and the public sector
FAQ

What IT usually asks.

Do we need to allow any IP on the database?

No. The connector lives inside your network and connects to the database. Datlas never opens a connection to your databases, so there is no IP to allow and no port to open.

What if we have a thousand people working from home?

They reach Datlas over the internet with the company sign-in. None of them connects to the database or needs a VPN. The database keeps accepting only the connector.

Where are the database passwords?

Encrypted with the connector’s key, the only one able to open them. No password goes to people’s computers.

Is data stored in Datlas?

Results pass through Datlas to apply permissions and limits and are delivered to the person, without being stored. The AI gets the database structure, not its content.

What if someone leaves the company?

Disable them in the identity provider or the console. Sessions end at once, and projects leave their computer on the next access.

Which databases are supported?

With Enterprise permissions and audit: PostgreSQL, MySQL and MariaDB, including RDS, Aurora, Cloud SQL and Azure. The Datlas app also connects Oracle, MongoDB, Cassandra, ClickHouse, Redis, Redshift, SQLite and CSV, and these databases are coming into Enterprise governance.

What happens if the connector goes down?

Its sources are unavailable until it’s back, and nothing is lost. To avoid depending on one machine, run two or more replicas.

Let’s put your company’s data in the right hands.

Tell us about your setup. We’ll show Datlas Enterprise working with your databases.

Book a 30-minute callPick a time: the call is on Google Meet and the invite goes to your e-mail.
Open the calendar in a new tab ↗

Prefer e-mail? Write to [email protected]

Datlas for individuals →