---
title: "Security · Adea"
description: "How Adea looks after your data: read-only access, Guardian checks every query, your rows are never copied, hosted in the EU."
url: https://adea.app/security
---

# Adea can look, but never touch.

Adea writes a question for your database. Guardian checks it before it runs, and your database answers through a user that can only read.

**AI model ** Proposes a query. Never runs anything itself.

**Guardian ** Checks every query before it runs

A normal question

`SELECT count(*) FROM bookings WHERE …`

**Read-only user ** Can only read. You create it.`GRANT SELECT`

**Your database ** Postgres, MySQL, BigQuery and more. A read replica is best.

**11.6 s ** of database time today

**Answer with sources ** Written from the result, never from your rows

How many new members did we get in September?

874 *+9% vs August*

new members in September

9% more than in August, and the best month this year.

Sources

*Database***Query **

```
SELECT count(*) FROM members
WHERE joined_at >= '2026-09-01'
```

*Understanding***When is a member new? **

“A member is new in their first paid month.”

Approved by Jonas, your developer

Your database and the read-only user stay with you. Adea and Guardian run in the EU.

- **Your rows are never copied. ** Adea reads what it needs, works out the numbers and forgets the rows.
- **Every query is logged. ** You can see what was asked, by whom, and what Guardian decided.
- **Never used to train AI. ** Your data and your questions stay yours.
- **Yours alone. ** No other customer can see your data, ever.

On this page Six layers that protect you.A login alone can't take your customer data.No copy of your code.What the AI sees, and doesn't.Retention and deletion.Questions from your security lead.

## Six layers that protect you.

Each one works on its own, so no single mistake opens your data.

### Read-only

Adea connects with a database user that can only read, and refuses one that can write. Every question is checked before it runs: one plain read, with a time limit and a row limit.

### Your data is yours alone

No other company can see your numbers or your code. The wall is built into the database itself, so even a mistake in the app can't show your data to anyone else. Each question runs in its own short-lived process.

### Encrypted

Everything between you and Adea travels over HTTPS. The passwords and tokens you give Adea are encrypted with a key that belongs to your company alone, and the AI never sees them. Adea always connects from the same fixed addresses, so you can close your database to everything else.

### Access by role

On Pro and Business, an administrator can hide tables and columns from a role, or show a column as ••••, such as salaries. The rule applies before a question runs, so no answer can get around it.

### Secrets stay out

Files with passwords and keys, such as.env files, are never read. Anything that looks like a key or a password is replaced with [hidden] before Adea uses it.

### Everything logged

Everything Guardian stops, flags or changes is written to a security log, on every plan. Administrators can read it, and on Business they can export it.

## A login alone can't take your customer data.

Guardian checks every question before data leaves your database, whoever asks: a person, Slack or an AI assistant. It watches for:

- **Personal data in bulk **
- **Whole tables **
- **Exports of personal data **
- **Paging through tables **
- **Prompt injection **

### Why it matters

A stolen login is one of the most common ways customer data leaks. The attacker doesn't need to break anything: they simply ask, as the person they pretend to be.

That's why approval goes to the administrators by email, and approving asks for a passkey or a fresh sign-in. A stolen login or a forwarded mail can't approve a request, and new administrators only get approval links after 24 hours, so an attacker can't invite their own approver.

### On every plan

- Anything unusual is flagged, and ordinary work is never blocked.
- Lowering a protection waits 24 hours, or needs a second administrator.

### On Business, also

- Large downloads and personal data are held until an administrator approves.
- Your own rules, written in plain words, such as “Exports over 500 rows need approval”.

## No copy of your code.

Adea doesn't keep a copy of your code. It's fetched from your git host when Adea needs it, held in memory only while in use, and deleted 20 minutes after last use.

1. 1

### Fetched only when needed

From your git host, when Adea needs it, and held in memory only while in use.

2. 2

### Read in a sealed space

No internet, read-only, and gone 20 minutes after last use. Never whole files, never the repository.

3. 3

### What Adea keeps

  - Short notes about what your code does
  - What Adea understands about your data, which your developers can correct
  - The few lines of code an answer shows as its source

## What the AI sees, and doesn't.

Adea uses an AI model to understand questions and write queries. It works with as little of your data as it can.

### It sees

- The names of the tables and columns you're allowed to see
- Up to 60 rows from each query it asked for. Longer lists go only to your screen
- Personal values swapped for stand-ins, such as “Person 1” instead of a name. Your screen shows the real ones
- Lines of your code, with anything that looks like a secret removed

### It never

- Sees your passwords or connection details
- Chooses which company it works for: that comes from your sign-in
- Sends anything out on its own: it writes drafts and lists
- Confirms a risky action itself: that takes a person's click
- Trains on your data or your questions

## Retention and deletion.

1. **After 30 days **

Result rows that hold personal data are deleted.

2. **When you delete your company **

Nobody can open it and every connection is cut at once. For 30 days an administrator can bring it back.

3. **After those 30 days **

Everything is erased and your company's key is destroyed.

4. **Within 35 days **

Backups are gone with the normal rotation.

## Questions from your security lead.

What we are asked most often when a security lead takes a look. If something is missing, write to us.

Documents

[Data processing agreementRead online](https://adea.app/dpa) [Sub-processors11 sub-processors · 30 days' notice](https://adea.app/subprocessors)

Docs and privacy policy[Docs](https://adea.app/docs) · [Privacy policy](https://adea.app/privacy)

Found a vulnerability or have more questions? [security@adea.app](mailto:security@adea.app)

### Can Adea change anything in our database?

No. Adea connects through a user that can only read, and Guardian checks every query before it runs: only one plain read is allowed, with a time limit and a row limit. When you connect, Adea checks that the user can't write, and refuses one that can.

### Does Adea keep a copy of our code?

No. The code is fetched from your git host when Adea needs it, held in memory only while in use, and deleted 20 minutes after last use. Adea keeps short notes about what the code does and the few lines an answer shows as its source. Never whole files, and never the repository.

### What does the AI model see?

The names of the tables and columns the person may see, lines of your code with anything that looks like a secret removed, and up to 60 rows from each query it asked for. Personal values in those rows, such as names, emails, phone numbers and addresses, are replaced with stand-ins like “Person 1” before the model sees them, and the person's screen shows the real ones. Longer lists go only to the person's screen. Columns an administrator has masked arrive as ••••. Never your passwords or connection details.

### Can the AI model run code?

No. It can ask to see tables, read code and propose a read query. Adea carries that out itself, and Guardian checks every query. An assistant works as the person who connected it, and it can never confirm a risky action: that takes a person's click in Adea.

### Where is our data, and who are the sub-processors?

Adea and its database run in the EU. A few sub-processors, such as the AI model from Anthropic, handle data outside the EU under agreed safeguards. The full list is on the sub-processors page.

### Is our data used to train AI?

No. Not by Adea, and not by Anthropic, which provides the AI model.

### Can we limit who sees what?

Yes, on Pro and Business. An administrator can hide or mask tables and columns for each role, and give a colleague only their own location. The rules are applied before a query runs.

### Can we require sign-in with Google or Microsoft?

Yes, on Business. An administrator can require everyone to sign in with Google or Microsoft. Without that rule, people can also sign in with an email link or a passkey.

### How do we delete our data?

An administrator can delete the company in Adea. Nobody can open it afterwards and every connection is cut at once. After 30 days everything is erased, and backups are gone within 35 days.

## See for yourself.

Try Adea free on your own data, or see the demo without signing up.

[Start free](https://adea.app/signup) [See the demo](https://adea.app/demo)
