Governed AI access to the data you already have.
The Data-Bridge is middleware that makes your existing databases queryable over REST, SQL and MCP — without moving them into a cloud warehouse or routing them through someone else's copilot. Every query is audited, and the audit log is yours.
One Docker command. No account, no clone, no build.
# Community edition — CSV source, free and open source $ export TDB_API_KEYS=$(python3 -c "import secrets; print(secrets.token_hex(32))") $ docker run -d --rm --name tdb -p 8000:8000 \ -e TDB_API_KEYS \ -v "$PWD/data:/data:ro" \ ghcr.io/tdb-project/tdb-community:latest # Ask it a question — read-only SQL, over HTTP $ curl -X POST localhost:8000/v1/query \ -H "Authorization: Bearer $TDB_API_KEYS" \ -H "Content-Type: application/json" \ -d '{"source_id":"orders","sql":"WITH t AS (SELECT * FROM data) SELECT customer FROM t"}' {"columns": ["customer"], "rows": […], "truncated": false}
How it works
One governed surface in front of the databases you already run.
Register a source once. TDB validates every statement as read-only, enforces the row ceiling, writes an audit record, and answers on whichever protocol the caller speaks — with no per-dataset API to build.
Your data
Stays where it is
- PostgreSQL
- MySQL
- SQL Server
- Snowflake
- CSV
The Data-Bridge
On your infrastructure
- read-only validation
- row ceiling + timeout
- OAuth 2.1 · RBAC
- signed audit log
Who asks
No custom integration
- Claude · Cursor · MCP
- REST / OpenAPI
- read-only SQL
- your own services
What you get
Built for the part everyone else leaves to you.
Connecting a model to a database is the easy half. The governance around it — who asked, what ran, what came back, and how you prove it later — is the half that keeps the project out of production.
Your data, where it already lives
Connect the databases you already run. No migration, no consolidating everything into one warehouse first, and nothing copied to a vendor you have to trust.
REST, SQL and MCP at once
Point Claude Desktop, Cursor or any MCP client straight at it — or call the same source over REST. Read-only is enforced before the statement reaches the engine.
An audit log you own
Every query, every result, every AI tool call — recorded on your own infrastructure in a tamper-evident hash chain. Even the free edition writes one.
Inside your perimeter
Runs in one Docker command on infrastructure you control. Your data never leaves it, and OAuth 2.1 with PKCE, RBAC and per-key rate limiting keep access governed.
The audit log
Not a checkbox. The reason this exists.
When an agent can query production data, "what did it actually do?" stops being a curiosity and becomes an audit question. TDB answers it by default, in a format you can hand to a compliance reviewer.
- Hash-chained records — a removed or edited entry breaks the chain and is detectable.
- Refusals are logged too, so a blocked write is evidence rather than silence.
- Retention by sealing, never deletion — segments stay independently verifiable.
- Incremental export to Splunk or S3, so it lands in the SIEM you already run.
{ "seq": 4127, "event": "query", "actor": "mcp:claude-desktop", "source_id": "3f1c…a90b", "sql": "SELECT region, SUM(amount) …", "rows_returned": 112, "truncated": false, "prev_hash": "9c2f…", "hash": "e70a…" } { "seq": 4128, "event": "denied", "action": "query", "reason": "Blocked keyword: DELETE" }
Editions
Evaluate it free. Upgrade when a second source shows up.
The community edition is a complete, honest version of the idea for one CSV source — enough to answer "does this work for us?" without talking to anyone.
Community
Free- One CSV data source
- REST + MCP (
query_source) - Read-only SQL, 1,000-row ceiling
- Local audit log (NDJSON)
- Auto schema detection · CLI · OpenAPI
Enterprise
Commercial- PostgreSQL, MySQL, SQL Server, Snowflake
- Unlimited sources · OAuth 2.1 + PKCE · RBAC
- Signed audit log · retention · SIEM export
- Seven MCP tools · named views · rate limiting
- Prometheus metrics · schema caching · SLA support
Try it against your own CSV in a minute.
Nothing to sign up for. If it fits, get in touch about the commercial edition and a 30-day evaluation.