/ security & access control

Maximum capability. Least privilege.

TextQL treats its own agent as an untrusted principal. Every query clears four gates — identity, entitlement, execution, audit — before a byte of your data moves.

/ soc 2 type ii/ hipaa/ gdpr/ your vpc or air-gapped
[ independently audited ]

Don’t take our word for it.

SOC 2 Type II certified

Audited annually · report on request

HIPAA compliant

BAAs signed · PHI never leaves your cloud

GDPR ready

DPA available · EU data residency

[ data protection ]

Built in, not bolted on.

/ 01

Isolated per run

A gVisor sandbox per session, destroyed when it ends. Nothing is shared between customers, or between two of your own users.

/ 02

Encrypted end to end

TLS 1.2+ in transit, AES-256 at rest, and your own KMS keys where you want to hold them.

/ 03

Deployed to your infrastructure

Your VPC, your datacentre, or fully air-gapped with no outbound route. Same product, smaller blast radius.

/ 04

Never trained on your data

Not our models, not a provider’s, with no contractual carve-out. Bring your own Bedrock, Vertex or Azure OpenAI deployment and inference never leaves your account.

[ as per your protocols ]

It fits the controls you already run.

Authentication, authorization, network and key management, configured to your standards rather than ours.

Authentication and users

SAML 2.0 and OIDC against any compliant provider, IdP-initiated and SP-initiated. JIT provisioning on first login, SCIM 2.0 for lifecycle, domain claim enforcement, and MFA enforced at your IdP rather than duplicated at ours.

Authorization

Roles compose from named grants and resolve per request, not at login. Row filters and column masks are evaluated by your warehouse — Snowflake row access policies, Unity Catalog column masks, BigQuery policy tags — so revoking a grant upstream takes effect on the next query.

Network and isolation

Every run gets a gVisor-isolated sandbox, destroyed with the session. Outbound traffic passes a domain allowlist and a credential-injecting egress proxy. PrivateLink, VPC peering and static egress IPs are available on enterprise deployments.

Keys and encryption

TLS 1.2+ in transit, AES-256 at rest, and customer-managed keys through your own KMS on VPC and on-prem installs. Credentials live in a vault the agent process cannot read.

[ how it is enforced ]

Follow one query.

Four gates clear before an answer comes back — in code, on every request, never by policy.

“Which enterprise accounts churned in Q3?” sarah.chen@acme.com
sarah.chen@acme.com signs in finance-core okta group Analyst textql role
resolved from your idp · sso or scim 01 / 04
[ inherited, not re-implemented ]

Your warehouse decides.

We connect as the person who asked, with the role you assigned them. If that role cannot see a column in your warehouse, no prompt can talk us into returning it.

Snowflake
Databricks
BigQuery
Redshift
Postgres
SQL Server
Tableau
Power BI
[ deployment ]

It runs inside your perimeter.

Your VPC on AWS, Azure or GCP, your datacentre, or a fully air-gapped network with no outbound route — with your model, on your hardware.

your environment aws · azure · gcp · datacentre · air-gapped
your compute
your storage
your database
your models ClaudeGeminiOpenAI
TextQL ana
sales
finance
engineering
no outbound route your model · your hardware · your keys
[ faq ]

What security reviews ask.

Our cloud, your VPC on AWS, Azure or GCP, your own datacentre, or a fully air-gapped network with no outbound route. The product surface is identical in all four; what changes is where the compute sits and who holds the keys. Regulated customers run a large share of their workloads on-prem.

[ try textql ]

Bring Us Your Hardest Problem