Safe by default

It can read your data, never change it

Hermes connects through a least-privilege role that can only run SELECT queries. It can answer questions and build dashboards, but it can never write to or alter your data.

Overview

Read-only by design

Handing an AI tool access to production data is a legitimate fear. Hermes is built to remove it: it connects through a dedicated least-privilege role that can only SELECT, so no matter what question is asked, it can look but never touch your data.

What it does

Access without the risk

Connects through a least-privilege role that can only SELECT.

Cannot write to, update or delete your data.

A restricted query mode reinforces the read-only boundary.

Safe for anyone to ask questions against production data.

Self-hosted, so the access boundary stays under your control.

How it works

How the read-only boundary works

1A dedicated read-only role is provisioned
2Hermes connects only through that role
3Every query is a SELECT, run read-only
4No question can modify your data
FAQ

Common questions

Can Hermes change our data?

No. It connects through a least-privilege role that can only run SELECT queries — it can read but never write.

Is it safe for non-technical staff to use?

Yes. Because access is strictly read-only, anyone can ask questions without risk to the data.

Who controls the access?

You do. Hermes is self-hosted, so the read-only role and boundary live in your own environment.

Explore more

More of what Hermes does

Get started

See Hermes answer against your own data

Book a demo and see Hermes answer questions against your own data — plain-language questions, live dashboards and the exact SQL it ran.