Governed database MCP server Let AI agents answer from your database.
Claude, ChatGPT, Cursor and any MCP client get read-only access to only the tables and columns you choose, and every query is on record.
Free plan with a sample dataset · 30-minute demo with the founder · or WhatsApp
-
Read-only
enforced twice on every query
-
Down to the column
you choose what agents read
-
Hosted in India
priced in rupees
Works with the AI tools your team already uses, on the databases you already run
- Claude
- ChatGPT
- Cursor
- VS Code
- Claude Code
- + any MCP client
The problem
Your team already asks AI about company data. Just not safely.
People want answers from the database without waiting for an analyst. Leadership wants AI on company data. Security says no — and they are right to, given how it usually happens today.
-
Data pasted into chat windows
People export a spreadsheet and paste it into ChatGPT to get an answer. Nobody knows what left, or where it went.
-
A database login in a config file
The quick MCP setup hands an agent a connection string. It can do whatever that login can do, on every table.
-
No record of who asked what
When security asks which customer data an AI tool read last month, there is nothing to show them.
Datablare sits in between. Agents get a governed MCP link instead of a login: read-only, limited to what you allow, and recorded.
How a question travels
Checked three times. Recorded once.
Your team asks in the AI tool they already use. Datablare checks the SQL, the tables and the columns before anything touches your database — and writes it all down.
Illustration. A person asks in Claude, ChatGPT or Cursor: who are our top customers this month? The question reaches Datablare, which checks it three times: the SQL guard confirms it is a single read-only SELECT, the tables are on the project's allowed list, and the hidden phone column is not requested. The query runs on the database, which also keeps it read-only. Three rows come back without the phone column, and the call is added to the audit log. Then someone asks to delete last month's test orders: the DELETE statement is refused at the SQL guard, never reaches the database, and the refusal is recorded in the audit log too.
Your AI tool
Claude · ChatGPT · Cursor · VS Code
- “Who are our top customers this month?” Answered
- “Delete last month’s test orders.” Refused
Datablare checks
- SQL guard: read-onlyOne SELECT. Writes are refused.
- Allowed tables onlyorders, customers are on the list
- Hidden columns stay outphone is hidden by your admin
DELETE stopped at the SQL guard. It never reaches the database.
Your database
Runs the query, and the database itself keeps it read-only too: a second lock behind the guard.
Read-only, twice
Rows back to the agent
| Customer | Orders | Spent | Phone |
|---|---|---|---|
| Ananya Rao | 14 | ₹1,24,800 | ••• |
| Rohan Mehta | 11 | ₹98,450 | ••• |
| Kavya Iyer | 9 | ₹86,200 | ••• |
Phone is hidden, so it is never returned. Results pass through and are not stored.
Audit log
- 10:42Delete test orders Refused
- 10:42Top customers this month Got data
- 10:37Revenue by category Got data
Who asked, the SQL that ran, the tables it touched, how long it took.
What you get
Read-only database access for AI, with the controls security asks for
-
Read-only, enforced twice
Datablare’s SQL guard lets only a single read through, and the database itself keeps the query read-only. Agents cannot insert, update, delete or drop.
-
Down to the column
Choose which tables each project exposes and hide individual columns — salary, Aadhaar, phone, diagnosis. Hidden means never returned.
-
Every query on record
Audit shows who asked, the question, the SQL that ran, which tables it touched and how long it took. Export it as CSV on paid plans.
-
Works with the AI tools you use
One MCP link per project for Claude, ChatGPT, Cursor, VS Code, Claude Code or any MCP client. People sign in with their own account.
Multiple databases
One MCP link. All your databases.
Connect PostgreSQL, MySQL, Snowflake and more to one project. Your team adds a single link to Claude or ChatGPT and asks questions that span them, with one access policy and one audit log.
Illustration. Claude, ChatGPT and Cursor all connect to one Datablare MCP link for a project. The project has three databases: PostgreSQL holding orders, MySQL holding the CRM, and Snowflake holding finance data. When someone asks a question that spans them, the agent sends one read-only query to each database it needs. Datablare checks every query, runs it on the right database, and records it in the audit log. The agent then combines the results into one answer.
“Which customers in the CRM spent over ₹1 lakh last month?”
The agent queried CRM and Orders separately and combined the results. Both queries are in Audit, under the person who asked.
Illustration. One query runs on one database; the agent combines the answers. Names and figures are examples.
Access control
Same question, different access
Every person reaches the data through their own sign-in, so the agent can only read what that person is allowed to. Switch roles to see what comes back.
Same question in Claude: “Who were our top customers last quarter, and how do I reach them?”
Owner or manager: the agent can read every source in the project. Hidden columns stay hidden for everyone, owners included.
Analyst given the Sales source only: rows that live in the ERP source are never returned to their agent.
Viewer: their agent cannot read data in this project. In Audit they see that calls happened, not the questions, SQL or answers.
Illustration of real behaviour. Names and figures are examples.
How it works
From database to answers in four steps
- Step 1
Step 1
Connect a database
Add PostgreSQL, MySQL, MariaDB, SQL Server, Oracle, ClickHouse or Snowflake — directly or through an SSH tunnel. Or try the e-commerce sample in one click.
- Step 2
Step 2
Choose what agents may read
Pick the tables each project exposes, hide sensitive columns, and give people a role: manager, analyst or viewer.
- Step 3
Step 3
Connect your AI tool
Copy the project’s MCP link into Claude, ChatGPT, Cursor, VS Code or Claude Code. Sign in to Datablare and click Allow.
- Step 4
Step 4
Ask, and see every query
Ask in plain English. The agent writes SQL, Datablare checks it and runs it read-only, and Audit records who asked and what ran.
Build, borrow or use Datablare
What a governed MCP gateway saves you building
You can wire an agent to a database with an open-source MCP server in an afternoon. Making it safe for a whole company is the part that takes months.
| What you need | Datablare | Open-source MCP server | Build it yourself |
|---|---|---|---|
| Read-only enforcement | Yes: SQL guard, and read-only at the database too | Partly: Typically depends on the login you give it | Partly: You build and test it |
| Choose tables and hide columns | Yes: Per project, in the app | Partly: Typically via database grants you maintain | Partly: You build it |
| Per-person roles and sign-in | Yes: Manager, analyst, viewer; OAuth sign-in | No: Typically one shared connection string | Partly: You build it |
| Audit log of every query | Yes: Who asked, the SQL, tables, timing; CSV export | No: Typically local logs only | Partly: You build and store it |
| Works with Claude, ChatGPT, Cursor, VS Code | Yes: One remote MCP link per project | Partly: Often a local install on each laptop | Partly: You build the MCP server |
| Context for the agent (descriptions, rules) | Yes: Modeling: tables, columns, rules, example questions | No: Typically raw schema only | Partly: You build it |
| Hosting and billing | Yes: Hosted in India, billed in INR; your own cloud for Enterprise | Partly: You host and run it | Partly: You host, run and maintain it |
Generic comparison of common approaches, not of any named product. Open-source servers vary; check the one you are considering.
Deployment
Hosted in India, or in your own cloud
Datablare Cloud
Free, Team and Business
- Hosted in India, billed in rupees with GST invoices
- Connect databases directly or through an SSH tunnel
- Credentials encrypted; query results never stored
Your own cloud
Enterprise
- For regulated data or in-country hosting requirements
- Negotiated limits and a deployment scoped with you
- Help with your security review
Use cases
Chat with your database, team by team
Real questions people ask of the e-commerce sample you can try on the Free plan.
-
Sales
Know what is selling and who comes back, without waiting for a report.
- “Which products sell the most?”
- “How many of our customers have ordered more than once?”
-
Finance
Revenue and order value by month or category, straight from the source.
- “What is our revenue by product category?”
- “What is the average order value in each month?”
-
Operations
Stock and assortment questions answered from live tables.
- “Which products are running low on stock?”
- “Which sizes and colours sell best?”
-
Leadership
A quick read on the business, in plain English, with the SQL on record.
- “How many orders did we get each month, and what did they bring in?”
- “How is the webshop doing this quarter?”
Built for regulated data
Helps you meet the privacy laws your customers ask about
Datablare gives you the controls auditors look for when AI tools touch personal data. Compliance stays yours; these make it much easier to show.
Helps you meet
- DPDP
- GDPR
- HIPAA
- CCPA/CPRA
- PDPL
-
Read-only
Enforced by the SQL guard and by the database itself.
-
Column-level control
Hide personal data columns from every agent.
-
Full audit trail
Who asked, the SQL, the tables touched, when.
-
Hosted in India
Or deployed in your own cloud for Enterprise.
FAQ
Questions CTOs ask first
Something else? Ask Kamal directly on WhatsApp or at [email protected].
What is a database MCP server?
MCP (Model Context Protocol) is the open standard AI tools like Claude, ChatGPT, Cursor and VS Code use to call outside tools. A database MCP server gives those tools a way to read a database: list tables, write SQL and get rows back. Datablare is a hosted, governed one: it checks every query, keeps it read-only, limits it to the tables and columns you choose, and records it.
Can the AI change or delete data?
No. Every query is checked by Datablare’s SQL guard, which only lets a single read through. It then runs with the database itself keeping it read-only: a read-only session on PostgreSQL, MySQL, MariaDB, Oracle and ClickHouse, and a transaction that is always rolled back on SQL Server and Snowflake. Inserts, updates, deletes and schema changes are refused.
Does the AI see my data?
It sees the rows it asks for, and only from the tables and columns you allow. Hide a column (a phone number, salary or Aadhaar number) and it is never returned to any agent. Results pass through Datablare to the AI tool and are never stored by Datablare; the AI provider handles them under its own terms.
Which databases and AI tools work with Datablare?
Databases: PostgreSQL, MySQL, MariaDB, SQL Server, Oracle, ClickHouse and Snowflake, directly or through an SSH tunnel. AI tools: Claude, ChatGPT, Cursor, VS Code (GitHub Copilot), Claude Code and any other MCP client that supports remote servers.
How do people connect their AI tool?
Each project has one MCP link. Paste it into the AI tool, sign in to Datablare and click Allow: that OAuth sign-in is the default for every client. A personal key is the fallback for tools that cannot sign in (ChatGPT is sign-in only). Analysts and above can approve a connection themselves; viewers send a request to an admin.
Can one MCP link query multiple databases?
Yes. Every database you add to a project is reachable through that project’s single MCP link, and they can be different engines: say PostgreSQL for orders, MySQL for the CRM and Snowflake for finance. The agent lists the project’s data sources and sends each read-only query to the database it belongs to; for a question that spans two, it queries each and combines the results. One SQL statement runs on one database, so there are no cross-database joins. You can still limit a person to particular databases on the same link.
Where is Datablare hosted, and what does it store?
Datablare Cloud is hosted in India. It stores your connection details (encrypted), the context you write about your tables, and an audit record of each call: who asked, the question, the SQL, the tables touched and timings. It never stores query results.
Can I try it without connecting my own database?
Yes. The Free plan includes a one-click e-commerce sample dataset, so you can connect Claude and ask real questions in a couple of minutes before you connect anything of your own.
Can we run Datablare in our own cloud?
For Enterprise customers, deploying in your own cloud is a conversation we scope together, usually for regulated data or in-country hosting requirements. Talk to us on WhatsApp or email.
Give your team answers, not database logins.
Start free with the e-commerce sample or your own database. Connect Claude in about two minutes.
30 minutes with the founder. Or WhatsApp / [email protected]