Security

Security & data handling

ThinAir Data is designed so you can point AI at production databases without giving up control. It's read-only by default, encrypted at rest, and we never store query results.

What we store

Connection strings are encrypted at rest with AES-GCM and never logged. We store anonymized metrics (query counts, latency, error rates) to keep the service healthy and bill correctly. We do not store query result rows, table data, or schema definitions.

What we don't store

No query result data
No table or row contents
No plaintext connection strings
No MCP bearer tokens beyond their short-lived window

Read-only by design

Writes are blocked before they ever reach your database. Only SELECT, WITH, and EXPLAIN are permitted; INSERT, UPDATE, DELETE, DROP, ALTER, TRUNCATE, writes to pg_* / information_schema, xp_cmdshell, and COPY FROM are rejected by a static SQL firewall. Where the engine supports it, every connection sets a read-only transaction at the wire protocol level as a second guardrail.

Encryption in transit & at rest

Connection strings are encrypted at rest and never logged. Every connection is encrypted in transit — from your browser to ThinAir, and from ThinAir to your database. There is no connection-string parameter that disables it: a DSN that tries is refused when you register it. SQL Server uses TDS 8.0 strict mode, so it requires SQL Server 2022+ or Azure SQL. A database that cannot do TLS is reachable only through a private connector, which terminates TLS inside your own network.

Audit & control

Every query is logged with timing and row count and can be exported from the audit log. Sessions are tenant-scoped; you can revoke access at any time from the Connect page. Enterprise deployments add private networking, dedicated connection pools, and bring-your-own-encryption-key.

Connect a database → Getting started