/ security & access control
TextQL treats its own agent as an untrusted principal. Every query clears four gates — identity, entitlement, execution, audit — before a byte of your data moves.
Audited annually · report on request
BAAs signed · PHI never leaves your cloud
DPA available · EU data residency
A gVisor sandbox per session, destroyed when it ends. Nothing is shared between customers, or between two of your own users.
TLS 1.2+ in transit, AES-256 at rest, and your own KMS keys where you want to hold them.
Your VPC, your datacentre, or fully air-gapped with no outbound route. Same product, smaller blast radius.
Not our models, not a provider’s, with no contractual carve-out. Bring your own Bedrock, Vertex or Azure OpenAI deployment and inference never leaves your account.
Authentication, authorization, network and key management, configured to your standards rather than ours.
SAML 2.0 and OIDC against any compliant provider, IdP-initiated and SP-initiated. JIT provisioning on first login, SCIM 2.0 for lifecycle, domain claim enforcement, and MFA enforced at your IdP rather than duplicated at ours.
Roles compose from named grants and resolve per request, not at login. Row filters and column masks are evaluated by your warehouse — Snowflake row access policies, Unity Catalog column masks, BigQuery policy tags — so revoking a grant upstream takes effect on the next query.
Every run gets a gVisor-isolated sandbox, destroyed with the session. Outbound traffic passes a domain allowlist and a credential-injecting egress proxy. PrivateLink, VPC peering and static egress IPs are available on enterprise deployments.
TLS 1.2+ in transit, AES-256 at rest, and customer-managed keys through your own KMS on VPC and on-prem installs. Credentials live in a vault the agent process cannot read.
Four gates clear before an answer comes back — in code, on every request, never by policy.
We connect as the person who asked, with the role you assigned them. If that role cannot see a column in your warehouse, no prompt can talk us into returning it.
Your VPC on AWS, Azure or GCP, your datacentre, or a fully air-gapped network with no outbound route — with your model, on your hardware.

Our cloud, your VPC on AWS, Azure or GCP, your own datacentre, or a fully air-gapped network with no outbound route. The product surface is identical in all four; what changes is where the compute sits and who holds the keys. Regulated customers run a large share of their workloads on-prem.