START WITH A PROBLEM

AI over private business data, without exposing it

The team wants to ask ChatGPT or Claude about the numbers. IT wants the data to stay where it is. Both are right.

Leadership PROBLEM 3 min read
Today YOUR INFRASTRUCTUREDATABASESPREADSHEETSChat toolOUTSIDEEXPORTS OUT · "JUST GIVE IT ACCESS?"
With an indexed layer inside YOUR INFRASTRUCTUREAI AssistantMCP ServerLLMYOUR KEYAI clientYOUR KEYSONLY ASK → · ← ANSWERS CROSS · REVOCABLE KEYS
Nothing exported. Only the question and the answer cross.

The symptom

Spreadsheets pasted into chat tools, because that is the fastest way anyone has found to ask a question about last month's orders. A request from the team that goes "can we just give it database access?" And a policy from IT that says no to all of it, which is reasonable, and which means the questions get asked anyway, through exports nobody tracks.

Both sides are right. The team is right that asking in plain language is faster than building a report. IT is right that an export in a chat window is data that has left the building, with no record of what went, and that a model with a production login is a model with too much.

Why it happens

AI tools need structured access with a boundary and keys. An export has neither: it is a copy, it is stale the moment it is made, and it goes wherever the chat tool goes. Direct database access is the opposite failure: it gives the model every table, every row and every join, with the production database carrying the load of whatever query the model decides to write, and gives the business no control over what is asked or what comes back.

What is missing is the middle: a place where the data is already organized for questions, that sits inside your infrastructure, that answers through a controlled endpoint, and that sends out only what a given question needs.

What changes with an indexed layer

The indexed layer runs inside your infrastructure, as a copy of the collections people ask about - orders, customers, products, invoices. An AI assistant answers inside it: the question is mapped to fields, filters and facets, the index does the searching and counting, and the model writes up the result. For the AI tools your team already uses - ChatGPT, Claude, Cursor - an MCP (Model Context Protocol) endpoint with revocable access keys lets them ask the same data the same questions, with no export and no database login. The production database is never on the path.

Something does cross the boundary, and it should be said plainly. When the assistant answers, the question and the information required for that request go to the LLM provider you chose, under your own account and key. When an AI client asks through MCP, the requested results go to that client and are handled under your agreement with its AI provider. What does not cross: the database, the index, the keys, and anything the question did not need. That is a boundary a security review can look at, which is the difference between this and a spreadsheet in a chat window.

See it on real data.

The demo instance runs dashboards, data grids and the AI Assistant on real business data. No sign-up.