Database access control for the whole company.
Everyone signs in with the company account and reaches only the databases, schemas and actions their role allows. Every query is audited, and no one gets a database password.
Sign in. Everything is already there.
Business users configure nothing. On sign-in, Datlas brings the projects their role allows, with the team’s queries, dashboards and context.
Sign in with the company account
Google, Microsoft Entra ID or any OIDC provider, with the MFA the company already uses.
Get what the role allows
Allowed projects, sources and schemas appear by themselves. Access removed, they leave the computer.
Ask in plain language
The AI writes SQL from the database’s real structure. People check it before it runs.
Share with the team
Queries, dashboards, alerts and AI context synced for everyone in the project.
Two thousand people. One connector. Zero open ports.
People talk only to Datlas, over the internet, with the company sign-in. The connector talks to the databases; IT installs it once inside the company network. It only makes outbound connections: nothing from outside gets in.
People
Datlas app, from home or the office. No database password on the machine.
Governance
Sign-in, role permissions, limits, the company’s AI and an audit trail of every operation.
Connector
In the company network, next to the databases. Keeps the passwords and runs only what Datlas signs.
Your databases
PostgreSQL, MySQL and MariaDB. Still closed to the internet.
No inbound port open
Ready in an afternoon.
No integration project. Three steps, and from then on registered sources connect by themselves.
Company sign-in
In the Datlas console, connect your identity provider (OIDC). Everyone signs in with the corporate account.
Connector in the network
Create the connector in the console and run the line it shows on a server that reaches the databases. No configuration file.
docker run -d --restart unless-stopped \ -v datlas-connector:/data \ -e DATLAS_ENROLL_TOKEN=one-time-token \ ghcr.io/cendyandreoli/datlas-connector
Sources and permissions
Register the databases and decide who sees what, by project, source or schema. Sources connect through the connector by themselves, and people get the projects at their next sign-in.
Full connector documentation (and instructions for AI agents) →
Built to pass your security team’s review.
Everything below is in the product today.
Outbound connections only
The connector opens a TLS channel to Datlas and keeps it open. No inbound port, no exposed database, no IP to allow.
Key-based authentication, no reusable secret
The connector creates its own key and hands over only the public half. Each connection proves who it is by signing a fresh challenge. The install token works once, for one hour.
Signed commands and answers
Each command is valid for 60 seconds and runs once. Each answer comes back signed. No one in the middle can inject, replay or alter a query.
Passwords sealed for the connector
Database credentials arrive encrypted with the connector’s key. Only it can open them. Datlas keeps only ciphertext.
SSO, MFA and controlled sessions
OIDC with PKCE, required MFA for Datlas accounts, sessions that end at once when someone leaves or loses access.
Role-based permissions
Read, copy, export, AI and changes granted by project, source and schema, to people or groups. The server authorizes every operation.
Protected production
Expensive queries are refused by their execution plan, with row, byte and time limits. Read-only by default.
Governed changes
Database edits only where the policy allows, always in a transaction reviewed before commit.
Tamper-evident audit
Who did what, on which database, through which connector and when. Hash-chained records with verifiable receipts and export.
AI under company control
Provider, model and key set by administrators. The AI sees the database structure; data samples only if administrators allow them, and every request is recorded.
Instant revocation
One click in the console turns off a connector, a session or a person. No waiting for expiry.
Restricted reach
IT can limit which databases each connector may reach. It never becomes a bridge to the rest of the network.
The way your company requires.
Datlas cloud + connector
We run Datlas. The connector stays in your network.
- Ready in an afternoon
- Databases and passwords never leave your network
- Updates with no work for IT
Replicated connector
For critical operations.
- Two or more replicas sharing one identity
- Health checks and Prometheus metrics
- Key rotation without reinstalling
In your cloud
All of Datlas inside your infrastructure.
- Nothing leaves your environment
- Your IdP, your logs, your network
- For banking, healthcare and the public sector
What IT usually asks.
Do we need to allow any IP on the database?
No. The connector lives inside your network and connects to the database. Datlas never opens a connection to your databases, so there is no IP to allow and no port to open.
What if we have a thousand people working from home?
They reach Datlas over the internet with the company sign-in. None of them connects to the database or needs a VPN. The database keeps accepting only the connector.
Where are the database passwords?
Encrypted with the connector’s key, the only one able to open them. No password goes to people’s computers.
Is data stored in Datlas?
Results pass through Datlas to apply permissions and limits and are delivered to the person, without being stored. The AI gets the database structure, not its content.
What if someone leaves the company?
Disable them in the identity provider or the console. Sessions end at once, and projects leave their computer on the next access.
Which databases are supported?
With Enterprise permissions and audit: PostgreSQL, MySQL and MariaDB, including RDS, Aurora, Cloud SQL and Azure. The Datlas app also connects Oracle, MongoDB, Cassandra, ClickHouse, Redis, Redshift, SQLite and CSV, and these databases are coming into Enterprise governance.
What happens if the connector goes down?
Its sources are unavailable until it’s back, and nothing is lost. To avoid depending on one machine, run two or more replicas.
Let’s put your company’s data in the right hands.
Tell us about your setup. We’ll show Datlas Enterprise working with your databases.
Prefer e-mail? Write to [email protected]
Datlas for individuals →