Most database MCP servers are a process on someone's laptop with a connection string in a config file. The model can reach whatever that string can reach, nothing records what it ran, and the database sees one shared user. LLM governance for data starts at the connection: which databases an LLM may touch, as which database user, with what rights, and with a record of every query.
AI access is set per connectionEnterprise
Each connection has one AI access setting, separate from what people can do in the SaturnSQL editor:
- Off. AI clients and API keys cannot see or query the connection. People still use it in the editor as usual.
- Read-only. AI clients can query it, but every call must be a single SELECT, WITH or EXPLAIN statement, even if people are allowed to write.
- Same as people. AI clients get the same rights as the person they act for. Meant for staging and scratch databases.
Only the connection's owner and company admins can change the setting, and it is enforced on SaturnSQL's servers before a query reaches your database, not by asking the model to behave.
Limit tables and columns in the database itself
A prompt cannot be trusted to stay away from the salaries table, so put the boundary where the model cannot argue with it. Create a database user that can only read the tables or views you choose, add it to SaturnSQL as its own connection, and make that the only connection with AI access. The full-rights connection stays Off for AI, and the model can never see more than that user can. See creating a read-only database user.
Every AI query has a name on it
Teammates connect Claude, ChatGPT or Cursor by signing in with their own SaturnSQL account over OAuth. There is no shared API key and no service account hiding who asked. The AI only sees the connections shared with that person, under their role, and viewers have no SQL access for an AI client to borrow. Remove someone from the workspace and their AI clients stop on the next request, because membership is checked on every call.
An audit log per connectionEnterprise
Every query is recorded, whether it came from the SaturnSQL editor, a schedule, an API key or an AI client. Each entry has the time, the person, the client or named key, the connection, the full SQL, the row count, the duration and any error. Filter to one connection to see everything AI did on that database, and export it as CSV for a compliance review.
The model never holds the credentials
Connection credentials are encrypted with AES-256 on SaturnSQL servers and never sent to the browser or the AI client. Claude sends SQL and gets rows back, capped by row limits. Your database does not need to be open to the internet either: allow the static egress IP 100.49.19.161, tunnel through an SSH bastion, and pin your own CA for TLS.
Checklist
| Control | How SaturnSQL does it |
|---|---|
| Choose which databases AI can reach | AI access set per connection: Off, Read-only or Same as people (Enterprise) |
| AI cannot change data | Read-only AI access accepts one SELECT, WITH or EXPLAIN per call |
| Limit tables and columns | A separate connection with a restricted database user, the only one open to AI |
| Credentials never reach the model | Encrypted with AES-256, kept server-side |
| Every AI query tied to a person | OAuth sign-in per person, no shared key |
| Full record per connection | Audit log with person, client, full SQL and rows, exportable as CSV (Enterprise) |
| Only owners change the rules | AI access is editable by the connection owner and admins |
| No database open to the internet | Static egress IP, SSH bastion, TLS with your own CA |
What SaturnSQL does not have
Better to read it here than find it in procurement: there is no column-level masking inside SaturnSQL (use a restricted database user), no SAML single sign-on or SCIM provisioning, no self-hosted option, and no SOC 2 or ISO 27001 report. The full picture is on the security page, and contract terms, including subprocessors, are in the data processing agreement.
Common questions
Which plan includes this? Per-connection AI access and the audit log are part of the Enterprise plan. Everything else on this page, including per-person OAuth sign-in, read-only connections, encrypted credentials and the SSH bastion, comes with Starter and up, the plans that include the MCP connector.
Do I need an MCP gateway as well? A gateway sits in front of many MCP servers and applies one policy to all of them. For database access, SaturnSQL already is that control point: it authenticates each person, applies each connection's AI access setting, and writes the audit log before a query reaches your database. A gateway still makes sense if you also run many unrelated MCP servers.
Can an admin see the exact SQL Claude ran on a connection? Yes. The audit log stores the full statement for every query, with who ran it, which AI client or API key it came through, the row count, duration and any error. Filter it to one connection to review everything AI did on that database.
Does the AI ever see our database password? No. Connection credentials are encrypted with AES-256 and stay on SaturnSQL servers. Claude, ChatGPT or Cursor sign in with the person's SaturnSQL account and only receive query results.
What happens when someone leaves the company? Remove them from the workspace. Membership is checked on every request, so their connected AI clients stop working on their next call, without waiting for a token to expire.
Can I hide specific tables or columns from the AI? Do it in the database, where it cannot be bypassed. Create a database user that can only read the tables or views you choose, add it as its own connection, set that connection to Read-only AI access and turn AI access off on the full one. The model can only ever see what that user can see.
Do you support SAML SSO or have a SOC 2 report? Not today. Sign-in is email and password or Google, with optional TOTP two-factor authentication, and we have not been through a SOC 2 or ISO 27001 audit. If either is a hard requirement, SaturnSQL does not meet it yet.
Part of SaturnSQL Enterprise. For how people get access without sharing passwords, see database access management. Setting up a client? See Claude, ChatGPT, Cursor or Claude Code, or build Claude Dashboards on your database.
Rolling out AI access across a team? Talk to us about Enterprise.
