Encrypted credentials, five roles, one audit log.
Letting a model write SQL against a production database is a governance question before it is an accuracy question. Here is exactly what BeyondQueries holds, who can do what, and what gets recorded.
Nothing sensitive is stored as plain text.
Credentials encrypted at rest
Connection strings, database passwords and LLM API keys are encrypted with Fernet — AES-128 in CBC mode with HMAC authentication. None of them is ever stored as plain text, and none is returned to the browser after it is saved.
Token sessions, not long-lived cookies
Authentication runs on short-lived JWTs with separate refresh tokens, so a stolen access token expires on its own rather than lasting until someone notices.
An append-only audit log
Sensitive operations are recorded with the actor, the action, the resource, the IP address and the timestamp. The table is written to, never updated — a record cannot be quietly edited after the fact.
Your database stays yours
BeyondQueries connects to a database you already run and own. There is no copy of your tables to lose, and you can revoke the connection by rotating one credential.
Five roles, granted per database instance.
Roles are scoped to an instance rather than to the whole account, so someone can be an admin on the analytics warehouse and a plain user on production. The permission set for each role is fixed and enforced server-side on every request.
Everything, including deleting the instance and managing billing.
Manage users and roles, edit the database connection, choose which tables and columns are visible, review flagged queries, and see all queries and analytics.
Write table and column instructions, use the production and sandbox chatbots, flag any query, and see all analytics — but not manage people or the connection.
Use the production chatbot, see their own queries and analytics, and flag their own queries.
Ask questions and see their own query history. Nothing else.
Two permissions worth calling out: only owners and admins can promote a sandbox configuration to production, and only they can review the flagged queries that feed the correction loop. An analyst can say an answer was wrong; an analyst cannot decide what the system learns from it.
No certification we have not been through.
BeyondQueries is not currently SOC 2 or ISO 27001 certified, and this page will say so until it is. If your procurement process needs a specific control documented, ask Irevex and you will get a straight answer rather than a badge.
Invite one colleague as a plain user and see the difference.
Roles are set at invitation time, so the narrow case is the default rather than something to remember to lock down later.