Security and compliance posture.
If you're reviewing iDBQuery for IT or procurement, this is your reference: encryption, access control, data residency, and three deployment modes — cloud, your own VPC, or fully air-gapped — with a downloadable one-pager. The Desktop app and Embedded SDK keep data local, so nothing has to leave your walls.
Compliance at a glance
| Standard | Status |
|---|---|
| GDPR | Aligned by design |
| PIPEDA | Aligned for Canadian customers |
| Data-stays-local deployment | Desktop app and air-gapped mode keep data in your environment |
| Annual penetration test | Yes |
Authentication
JWT on every request. Email and password with verification. Google OAuth. SAML and OIDC for enterprise SSO. Per-visitor JWT for embedded surfaces.
Authorization
Workspace-level RBAC (Owner, Admin, Editor, Viewer). A query-level scope rewriter injects per-tenant filters into every query before it runs. Three-layer defense: workspace middleware, source-level allowlist, and a SQL-level rewriter that locks each query to the data the user is allowed to see. An AI mistake, an injection attempt, or a rule misconfiguration each get caught by another layer.
Encryption
Symmetric encryption for credentials at rest. TLS 1.2+ in transit. JWT secrets encrypted at rest. Master key in environment variable, managed via cloud KMS.
Deployment and data residency
- Cloud SaaS: AWS Canada Central, Montréal, or the EU
- Customer-VPC deployment to AWS or Azure for those who require it
- Fully air-gapped on-premises for classified and regulated environments
- Desktop app and Embedded SDK keep data local — nothing leaves your walls
Logging and audit
Every executed query recorded with user, workspace, query hash, latency, status, and token usage. Every writeback journalled with full request and response bodies. Workspace audit log of every membership change, source addition, and conversation created. Auditor read-only share links available for compliance reviews.
Retention
Active customer data retained while the contract is active. Departed customer data: 90 days then hard delete. Audit logs: 7 years. Backups: 30 days.
Trust center
A one-page security overview is available as a downloadable PDF.
Download the security overview (PDF) →Reviewing iDBQuery for procurement?
Request our completed security questionnaire response. A senior team member sends it within one business day.