Hermes connects through a least-privilege role that can only run SELECT queries. It can answer questions and build dashboards, but it can never write to or alter your data.
Handing an AI tool access to production data is a legitimate fear. Hermes is built to remove it: it connects through a dedicated least-privilege role that can only SELECT, so no matter what question is asked, it can look but never touch your data.
Connects through a least-privilege role that can only SELECT.
Cannot write to, update or delete your data.
A restricted query mode reinforces the read-only boundary.
Safe for anyone to ask questions against production data.
Self-hosted, so the access boundary stays under your control.
No. It connects through a least-privilege role that can only run SELECT queries — it can read but never write.
Yes. Because access is strictly read-only, anyone can ask questions without risk to the data.
You do. Hermes is self-hosted, so the read-only role and boundary live in your own environment.
Turns plain-language questions into SQL and shows the exact query it ran.
Business intelligence you can talk to — ask questions instead of building reports.
KPI cards, breakdowns and detail tables built directly on your own database.
The whole stack drops onto any Docker host and reads your data in place.
See the complete product: problem, features, how it works and deployment.
Book a demo and see Hermes answer questions against your own data — plain-language questions, live dashboards and the exact SQL it ran.