Skip to content

Security

Your database stays in charge. The assistant only sees what you approve.

Edward reads your data through a read-only connection, limited to the tables and columns in a catalogue you review. The assistant never writes queries against your database. It describes a chart, and Edward's own engine turns that into SQL. This page explains exactly what moves where.

What flows where

Read from the database on the left to the assistant on the right.

Data flow: your database sends aggregated rows to the Edward query engine. The engine sends capped results to the assistant. The assistant sends back a structured chart spec, which the engine validates and compiles into read-only SQL. The assistant never connects to your database.
  1. 01

    Your database

    Your infrastructure

    Edward connects with the credentials you give it. Postgres and MySQL are attached in read-only mode.

  2. 02

    Edward query engine

    Google Cloud, europe-west1

    Turns a chart spec into a SELECT over catalogue columns only, then aggregates. Your credentials are decrypted here, in memory, at query time.

  3. 03

    Structured chart spec

    Validated against the catalogue

    Widget type, field ids, aggregation, filters. Unknown tables or columns are rejected before any query is built.

  4. 04

    Assistant (Claude)

    Anthropic API

    Sees catalogue metadata and the capped results of reads it asks for. It has no database connection of its own.

A note on warehouses.Postgres, MySQL, Iceberg and file sources are queried live, so filters and aggregations run in the source. For Redshift, Snowflake, BigQuery, SQL Server and Oracle, Edward currently loads a capped snapshot of the approved columns (100,000 rows per table by default, configurable) into an in-memory engine for that workspace. The snapshot is never written to disk or to Edward's database, and it is discarded when the catalogue or connection changes or the server instance restarts. Live pushdown for these warehouses is built and being validated.

How we protect your data

  • Read-only access

    Postgres and MySQL are attached in read-only mode. For other sources Edward only issues SELECT statements it generates itself. We still ask for a read-only database user, so the guarantee also holds on your side.

  • Catalogue allowlist

    You choose which tables and columns Edward can use. Queries project only those columns, and any request for a table or column outside the catalogue is rejected before SQL is built.

  • No raw SQL from the model

    The assistant returns a structured chart spec: widget type, field ids, aggregations and filters. Edward compiles that into SQL. The one exception is saved metrics, where the assistant proposes a single aggregate expression. Edward parses it without running it, allows only approved columns and functions, and tests it on sample rows before saving.

  • Encrypted credentials

    Database passwords and keys are encrypted with AES-256-GCM using a fresh key per secret, and that key is wrapped by Google Cloud KMS. Plaintext exists only in server memory at query time. Credentials are never sent back to the browser or to the assistant.

  • Workspace isolation

    Connectors, catalogues, dashboards and chats belong to a workspace. Every request checks membership, and each workspace gets its own query engine. Edward's app data lives in a separate database from your analytical data.

  • Hosting in the EU

    Edward runs on Google Cloud Run in europe-west1 (Belgium), with its app database on Google Cloud SQL. Server secrets are held in Google Secret Manager, not in the code or image.

What the assistant sees

It sees

  • Table and column names, types, descriptions and relationships from your catalogue
  • Your messages and the current dashboard layout
  • Results of reads it asks for: up to 200 sample rows, distinct values of a column, or up to 500 aggregated rows
  • During catalogue setup: column statistics and a few example values for low-cardinality columns

It does not see

  • Your database credentials or connection details
  • Tables and columns outside the catalogue you approved
  • A direct connection to your database. Every read goes through Edward's engine
  • Other workspaces' catalogues, dashboards or data

Questions reviewers ask

Which AI provider do you use?
Anthropic's Claude models, called through the Anthropic API. Data sent to the model is limited to what is listed above.
How do people sign in?
With email and password. Passwords are hashed with bcrypt. Single sign-on (SSO) is not available yet and is on the roadmap.
What roles are there?
Workspace members are owners, admins or members. Workspaces are created by an Edward administrator.
Is there an audit trail?
Every tool call the assistant makes is logged with its user, inputs, a truncated result, timing and errors. A full audit log of user actions is not available yet.
Can we allowlist Edward's IP address?
Yes, on request. Edward can connect from a fixed outbound IP address so you can firewall your database to it.

Responsible disclosure

If you think you have found a security issue in Edward, email us athello@edward-studio.com. Please include steps to reproduce, and give us a reasonable time to fix it before sharing details publicly.

Need a security review?

We can walk your security team through connections, credentials and data access before you connect anything.

Book a call