the gapwhat I doworkblogbook a call rostyslab21@gmail.com
security tool · postgres · row-level security

The prompt can't guarantee tenant isolation. The database can.

An AI SQL agent over Postgres where row-level security is enforced by the connection, not the model — with every query audited and a hard token cap.

read-only by defaultRLS enforced by the connectionquery audit loghard token cap
free vs. paid

same code. one line, hardened.

The free core proves the model — the paid version is what you put in front of real tenants.

free · MIT · on GitHub

free, MIT, on GitHub

  • NL → SQL over Postgres with RLS on
  • Read-only, single tenant model
  • Query audit log + hard token cap
  • The RLS-bypass test that proves the leak

$0 · MIT license · clone it today

view on GitHub
paid · one-time

the $149 version

  • Multi-tenant isolation across many tenants/policies
  • Write queries behind an explicit confirmation flow
  • Cost dashboard (per-tenant token & query spend)
  • The full RLS-bypass test suite — every attack from the article, red-teamed on every run

$149 · one-time · same code, hardened shelf

get it when it ships
the proof

I attacked my own agent — 5 ways an LLM bypasses row-level security.

RLS scopes rows by a setting the query can change. The prompt can't stop it — the connection has to. Five real bypasses, and the fix for each — the same bypasses the $149 suite tests for, automatically, every run.

product waitlist

leave your email — get it when it ships

No spam. One email when the $149 hardened version is ready.