Adea can look, but never touch.

Adea writes a question for your database. Guardian checks it before it runs, and your database answers through a user that can only read.

AI modelProposes a query. Never runs anything itself.
GuardianChecks every query before it runs

A normal question

SELECT count(*) FROM bookings WHERE …
Read-only userCan only read. You create it.GRANT SELECT
Your databasePostgres, MySQL, BigQuery and more. A read replica is best.

11.6 s of database time today

Answer with sourcesWritten from the result, never from your rows

How many new members did we get in September?

874+9% vs August

new members in September

9% more than in August, and the best month this year.

Sources

DatabaseQuery

SELECT count(*) FROM members
WHERE joined_at >= '2026-09-01'

UnderstandingWhen is a member new?

“A member is new in their first paid month.”

Approved by Jonas, your developer

Your database and the read-only user stay with you. Adea and Guardian run in the EU.

  • Your rows are never copied. Adea reads what it needs, works out the numbers and forgets the rows.

  • Every query is logged. You can see what was asked, by whom, and what Guardian decided.

  • Never used to train AI. Your data and your questions stay yours.

  • Yours alone. No other customer can see your data, ever.

Six layers that protect you.

Each one works on its own, so no single mistake opens your data.

  • Read-only

    Adea connects with a database user that can only read, and refuses one that can write. Every question is checked before it runs: one plain read, with a time limit and a row limit.

  • Your data is yours alone

    No other company can see your numbers or your code. The wall is built into the database itself, so even a mistake in the app can't show your data to anyone else. Each question runs in its own short-lived process.

  • Encrypted

    Everything between you and Adea travels over HTTPS. The passwords and tokens you give Adea are encrypted with a key that belongs to your company alone, and the AI never sees them. Adea always connects from the same fixed addresses, so you can close your database to everything else.

  • Access by role

    On Pro and Business, an administrator can hide tables and columns from a role, or show a column as ••••, such as salaries. The rule applies before a question runs, so no answer can get around it.

  • Secrets stay out

    Files with passwords and keys, such as .env files, are never read. Anything that looks like a key or a password is replaced with [hidden] before Adea uses it.

  • Everything logged

    Everything Guardian stops, flags or changes is written to a security log, on every plan. Administrators can read it, and on Business they can export it.

A login alone can't take your customer data.

Guardian checks every question before data leaves your database, whoever asks: a person, Slack or an AI assistant. It watches for:

  • Personal data in bulk
  • Whole tables
  • Exports of personal data
  • Paging through tables
  • Prompt injection

Why it matters

A stolen login is one of the most common ways customer data leaks. The attacker doesn't need to break anything: they simply ask, as the person they pretend to be.

That's why approval goes to the administrators by email, and approving asks for a passkey or a fresh sign-in. A stolen login or a forwarded mail can't approve a request, and new administrators only get approval links after 24 hours, so an attacker can't invite their own approver.

On every plan

  • Anything unusual is flagged, and ordinary work is never blocked.
  • Lowering a protection waits 24 hours, or needs a second administrator.

On Business, also

  • Large downloads and personal data are held until an administrator approves.
  • Your own rules, written in plain words, such as “Exports over 500 rows need approval”.

No copy of your code.

Adea doesn't keep a copy of your code. It's fetched from your git host when Adea needs it, held in memory only while in use, and deleted 20 minutes after last use.

  1. 1

    Fetched only when needed

    From your git host, when Adea needs it, and held in memory only while in use.

  2. 2

    Read in a sealed space

    No internet, read-only, and gone 20 minutes after last use. Never whole files, never the repository.

  3. 3

    What Adea keeps

    • Short notes about what your code does
    • What Adea understands about your data, which your developers can correct
    • The few lines of code an answer shows as its source

What the AI sees, and doesn't.

Adea uses an AI model to understand questions and write queries. It works with as little of your data as it can.

It sees

  • The names of the tables and columns you're allowed to see
  • Up to 60 rows from each query it asked for. Longer lists go only to your screen
  • Lines of your code, with anything that looks like a secret removed

It never

  • Sees your passwords or connection details
  • Chooses which company it works for: that comes from your sign-in
  • Sends anything out on its own: it writes drafts and lists
  • Confirms a risky action itself: that takes a person's click
  • Trains on your data or your questions

Retention and deletion.

  1. After 30 days

    Result rows that hold personal data are deleted.

  2. When you delete your company

    Nobody can open it and every connection is cut at once. For 30 days an administrator can bring it back.

  3. After those 30 days

    Everything is erased and your company's key is destroyed.

  4. Within 35 days

    Backups are gone with the normal rotation.

Questions from your security lead.

What we are asked most often when a security lead takes a look. If something is missing, write to us.

Found a vulnerability or have more questions? security@adea.app

Can Adea change anything in our database?

No. Adea connects through a user that can only read, and Guardian checks every query before it runs: only one plain read is allowed, with a time limit and a row limit. When you connect, Adea checks that the user can't write, and refuses one that can.

Does Adea keep a copy of our code?

No. The code is fetched from your git host when Adea needs it, held in memory only while in use, and deleted 20 minutes after last use. Adea keeps short notes about what the code does and the few lines an answer shows as its source. Never whole files, and never the repository.

What does the AI model see?

The names of the tables and columns the person may see, lines of your code with anything that looks like a secret removed, and up to 60 rows from each query it asked for. Longer lists go only to the person's screen. Columns an administrator has masked arrive as ••••. Never your passwords or connection details.

Can the AI model run code?

No. It can ask to see tables, read code and propose a read query. Adea carries that out itself, and Guardian checks every query. An assistant works as the person who connected it, and it can never confirm a risky action: that takes a person's click in Adea.

Where is our data, and who are the sub-processors?

Adea and its database run in the EU. A few sub-processors, such as the AI model from Anthropic, handle data outside the EU under agreed safeguards. The full list is on the sub-processors page.

Is our data used to train AI?

No. Not by Adea, and not by Anthropic, which provides the AI model.

Can we limit who sees what?

Yes, on Pro and Business. An administrator can hide or mask tables and columns for each role, and give a colleague only their own location. The rules are applied before a query runs.

Can we require sign-in with Google or Microsoft?

Yes, on Business. An administrator can require everyone to sign in with Google or Microsoft. Without that rule, people can also sign in with an email link or a passkey.

How do we delete our data?

An administrator can delete the company in Adea. Nobody can open it afterwards and every connection is cut at once. After 30 days everything is erased, and backups are gone within 35 days.

See for yourself.

Try Adea free on your own data, or see the demo without signing up.