Skip to content
Datablare

Governed database MCP server Let AI agents answer from your database.

Claude, ChatGPT, Cursor and any MCP client get read-only access to only the tables and columns you choose, and every query is on record.

Free plan with a sample dataset · 30-minute demo with the founder · or WhatsApp

  • Read-only

    enforced twice on every query

  • Down to the column

    you choose what agents read

  • Hosted in India

    priced in rupees

Datablare Audit page: the question “Which products sell the most?”, the SQL query that ran on the e-commerce sample, 10 rows returned in 1.3 seconds, asked from Claude Desktop by Priya Sharma.

Works with the AI tools your team already uses, on the databases you already run

The problem

Your team already asks AI about company data. Just not safely.

People want answers from the database without waiting for an analyst. Leadership wants AI on company data. Security says no — and they are right to, given how it usually happens today.

Datablare sits in between. Agents get a governed MCP link instead of a login: read-only, limited to what you allow, and recorded.

How a question travels

Checked three times. Recorded once.

Your team asks in the AI tool they already use. Datablare checks the SQL, the tables and the columns before anything touches your database — and writes it all down.

Illustration. A person asks in Claude, ChatGPT or Cursor: who are our top customers this month? The question reaches Datablare, which checks it three times: the SQL guard confirms it is a single read-only SELECT, the tables are on the project's allowed list, and the hidden phone column is not requested. The query runs on the database, which also keeps it read-only. Three rows come back without the phone column, and the call is added to the audit log. Then someone asks to delete last month's test orders: the DELETE statement is refused at the SQL guard, never reaches the database, and the refusal is recorded in the audit log too.

Your AI tool

Claude · ChatGPT · Cursor · VS Code

  • “Who are our top customers this month?” Answered
  • “Delete last month’s test orders.” Refused

Datablare checks

  1. SQL guard: read-onlyOne SELECT. Writes are refused.
  2. Allowed tables onlyorders, customers are on the list
  3. Hidden columns stay outphone is hidden by your admin

DELETE stopped at the SQL guard. It never reaches the database.

Your database

Runs the query, and the database itself keeps it read-only too: a second lock behind the guard.

Read-only, twice

Rows back to the agent

Customer Orders Spent Phone
Ananya Rao14₹1,24,800•••
Rohan Mehta11₹98,450•••
Kavya Iyer9₹86,200•••

Phone is hidden, so it is never returned. Results pass through and are not stored.

Audit log

  • 10:42Delete test orders Refused
  • 10:42Top customers this month Got data
  • 10:37Revenue by category Got data

Who asked, the SQL that ran, the tables it touched, how long it took.

Illustration of real behaviour. Names and figures are examples.

What you get

Read-only database access for AI, with the controls security asks for

  • Read-only, enforced twice

    Datablare’s SQL guard lets only a single read through, and the database itself keeps the query read-only. Agents cannot insert, update, delete or drop.

  • Down to the column

    Choose which tables each project exposes and hide individual columns — salary, Aadhaar, phone, diagnosis. Hidden means never returned.

  • Every query on record

    Audit shows who asked, the question, the SQL that ran, which tables it touched and how long it took. Export it as CSV on paid plans.

  • Works with the AI tools you use

    One MCP link per project for Claude, ChatGPT, Cursor, VS Code, Claude Code or any MCP client. People sign in with their own account.

Datablare Modeling page: the e-commerce sample’s ten tables, with the Products table open showing its friendly name and description, the context the agent reads before writing SQL.
Modeling: describe tables, add rules and example questions so the agent picks the right table and writes better SQL.

Multiple databases

One MCP link. All your databases.

Connect PostgreSQL, MySQL, Snowflake and more to one project. Your team adds a single link to Claude or ChatGPT and asks questions that span them, with one access policy and one audit log.

Illustration. Claude, ChatGPT and Cursor all connect to one Datablare MCP link for a project. The project has three databases: PostgreSQL holding orders, MySQL holding the CRM, and Snowflake holding finance data. When someone asks a question that spans them, the agent sends one read-only query to each database it needs. Datablare checks every query, runs it on the right database, and records it in the audit log. The agent then combines the results into one answer.

“Which customers in the CRM spent over ₹1 lakh last month?”

The agent queried CRM and Orders separately and combined the results. Both queries are in Audit, under the person who asked.

Illustration. One query runs on one database; the agent combines the answers. Names and figures are examples.

Access control

Same question, different access

Every person reaches the data through their own sign-in, so the agent can only read what that person is allowed to. Switch roles to see what comes back.

Ask as

Same question in Claude: “Who were our top customers last quarter, and how do I reach them?”

Sales source ERP source Phone hidden by an admin
Customer Channel Orders Spent Phone
Mehta Traders Wholesale 6 ₹3,10,000 hidden
Sharma Distributors Wholesale 4 ₹2,45,500 hidden
Ananya Rao Online store 14 ₹1,24,800 hidden
Rohan Mehta Online store 11 ₹98,450 hidden
Kavya Iyer Online store 9 ₹86,200 hidden

Owner or manager: the agent can read every source in the project. Hidden columns stay hidden for everyone, owners included.

Analyst given the Sales source only: rows that live in the ERP source are never returned to their agent.

Viewer: their agent cannot read data in this project. In Audit they see that calls happened, not the questions, SQL or answers.

Illustration of real behaviour. Names and figures are examples.

How it works

From database to answers in four steps

See how it works in detail
  1. Step 1

    Step 1

    Connect a database

    Add PostgreSQL, MySQL, MariaDB, SQL Server, Oracle, ClickHouse or Snowflake — directly or through an SSH tunnel. Or try the e-commerce sample in one click.

  2. Step 2

    Step 2

    Choose what agents may read

    Pick the tables each project exposes, hide sensitive columns, and give people a role: manager, analyst or viewer.

  3. Step 3

    Step 3

    Connect your AI tool

    Copy the project’s MCP link into Claude, ChatGPT, Cursor, VS Code or Claude Code. Sign in to Datablare and click Allow.

  4. Step 4

    Step 4

    Ask, and see every query

    Ask in plain English. The agent writes SQL, Datablare checks it and runs it read-only, and Audit records who asked and what ran.

Build, borrow or use Datablare

What a governed MCP gateway saves you building

You can wire an agent to a database with an open-source MCP server in an afternoon. Making it safe for a whole company is the part that takes months.

Datablare compared with an open-source MCP server and a build-it-yourself approach
What you need Datablare Open-source MCP server Build it yourself
Read-only enforcement Yes: SQL guard, and read-only at the database too Partly: Typically depends on the login you give it Partly: You build and test it
Choose tables and hide columns Yes: Per project, in the app Partly: Typically via database grants you maintain Partly: You build it
Per-person roles and sign-in Yes: Manager, analyst, viewer; OAuth sign-in No: Typically one shared connection string Partly: You build it
Audit log of every query Yes: Who asked, the SQL, tables, timing; CSV export No: Typically local logs only Partly: You build and store it
Works with Claude, ChatGPT, Cursor, VS Code Yes: One remote MCP link per project Partly: Often a local install on each laptop Partly: You build the MCP server
Context for the agent (descriptions, rules) Yes: Modeling: tables, columns, rules, example questions No: Typically raw schema only Partly: You build it
Hosting and billing Yes: Hosted in India, billed in INR; your own cloud for Enterprise Partly: You host and run it Partly: You host, run and maintain it

Generic comparison of common approaches, not of any named product. Open-source servers vary; check the one you are considering.

Deployment

Hosted in India, or in your own cloud

Datablare Cloud

Free, Team and Business

  • Hosted in India, billed in rupees with GST invoices
  • Connect databases directly or through an SSH tunnel
  • Credentials encrypted; query results never stored
Start free

Your own cloud

Enterprise

  • For regulated data or in-country hosting requirements
  • Negotiated limits and a deployment scoped with you
  • Help with your security review
Book a call

Use cases

Chat with your database, team by team

Real questions people ask of the e-commerce sample you can try on the Free plan.

  • Sales

    Know what is selling and who comes back, without waiting for a report.

    • “Which products sell the most?”
    • “How many of our customers have ordered more than once?”
  • Finance

    Revenue and order value by month or category, straight from the source.

    • “What is our revenue by product category?”
    • “What is the average order value in each month?”
  • Operations

    Stock and assortment questions answered from live tables.

    • “Which products are running low on stock?”
    • “Which sizes and colours sell best?”
  • Leadership

    A quick read on the business, in plain English, with the SQL on record.

    • “How many orders did we get each month, and what did they bring in?”
    • “How is the webshop doing this quarter?”

Built for regulated data

Helps you meet the privacy laws your customers ask about

Datablare gives you the controls auditors look for when AI tools touch personal data. Compliance stays yours; these make it much easier to show.

Helps you meet

  • DPDP
  • GDPR
  • HIPAA
  • CCPA/CPRA
  • PDPL
  • Read-only

    Enforced by the SQL guard and by the database itself.

  • Column-level control

    Hide personal data columns from every agent.

  • Full audit trail

    Who asked, the SQL, the tables touched, when.

  • Hosted in India

    Or deployed in your own cloud for Enterprise.

FAQ

Questions CTOs ask first

Something else? Ask Kamal directly on WhatsApp or at kamal@datablare.com.

What is a database MCP server?

MCP (Model Context Protocol) is the open standard AI tools like Claude, ChatGPT, Cursor and VS Code use to call outside tools. A database MCP server gives those tools a way to read a database: list tables, write SQL and get rows back. Datablare is a hosted, governed one: it checks every query, keeps it read-only, limits it to the tables and columns you choose, and records it.

Can the AI change or delete data?

No. Every query is checked by Datablare’s SQL guard, which only lets a single read through. It then runs with the database itself keeping it read-only: a read-only session on PostgreSQL, MySQL, MariaDB, Oracle and ClickHouse, and a transaction that is always rolled back on SQL Server and Snowflake. Inserts, updates, deletes and schema changes are refused.

Does the AI see my data?

It sees the rows it asks for, and only from the tables and columns you allow. Hide a column (a phone number, salary or Aadhaar number) and it is never returned to any agent. Results pass through Datablare to the AI tool and are never stored by Datablare; the AI provider handles them under its own terms.

Which databases and AI tools work with Datablare?

Databases: PostgreSQL, MySQL, MariaDB, SQL Server, Oracle, ClickHouse and Snowflake, directly or through an SSH tunnel. AI tools: Claude, ChatGPT, Cursor, VS Code (GitHub Copilot), Claude Code and any other MCP client that supports remote servers.

How do people connect their AI tool?

Each project has one MCP link. Paste it into the AI tool, sign in to Datablare and click Allow: that OAuth sign-in is the default for every client. A personal key is the fallback for tools that cannot sign in (ChatGPT is sign-in only). Analysts and above can approve a connection themselves; viewers send a request to an admin.

Can one MCP link query multiple databases?

Yes. Every database you add to a project is reachable through that project’s single MCP link, and they can be different engines: say PostgreSQL for orders, MySQL for the CRM and Snowflake for finance. The agent lists the project’s data sources and sends each read-only query to the database it belongs to; for a question that spans two, it queries each and combines the results. One SQL statement runs on one database, so there are no cross-database joins. You can still limit a person to particular databases on the same link.

Where is Datablare hosted, and what does it store?

Datablare Cloud is hosted in India. It stores your connection details (encrypted), the context you write about your tables, and an audit record of each call: who asked, the question, the SQL, the tables touched and timings. It never stores query results.

Can I try it without connecting my own database?

Yes. The Free plan includes a one-click e-commerce sample dataset, so you can connect Claude and ask real questions in a couple of minutes before you connect anything of your own.

Can we run Datablare in our own cloud?

For Enterprise customers, deploying in your own cloud is a conversation we scope together, usually for regulated data or in-country hosting requirements. Talk to us on WhatsApp or email.

Give your team answers, not database logins.

Start free with the e-commerce sample or your own database. Connect Claude in about two minutes.

30 minutes with the founder. Or WhatsApp / kamal@datablare.com