Surgical access
to production data.
Zero exposure.
Scalple replaces shared database credentials with structured, audited access. Every query is scoped, logged, and structurally immutable. Built for teams operating under GDPR, HIPAA, and strict data sovereignty requirements.
Security that ships
as infrastructure.
Scalple is not a policy layer on top of your existing access patterns. It replaces the access model entirely — from credentials to queries to compliance reporting.
Access model replacementZero credential exposure
No SSH tunnels. No shared .env files. No credentials in Slack messages. Developers request scoped access through a policy engine — credentials never leave Scalple's control plane.
INSERT-only audit trail
Every query, every access request, every denied operation is appended to an immutable log. The schema enforces INSERT-only writes — no UPDATE, no DELETE, no backfilling possible.
EU-only cloud
AWS is excluded — CLOUD Act jurisdiction creates legal risk for EU data subjects. Scalple runs on EU-domiciled providers: Hetzner, OVH, Exoscale.
Sandboxed TypeScript
Queries run as typed TypeScript functions inside V8 Isolates with hard limits on memory, CPU, and network. No arbitrary code execution risk.
GDPR engine
DSR workflows, RoPA, and breach notifications are structural — not procedural. Built into the access model, not bolted on afterward.
Access control built in.
Not bolted on.
A complete platform for controlled production database access — from query execution and schema browsing to compliance export and script automation.
Multi-database browsing, without credentials.
Connect PostgreSQL, MySQL, MongoDB, and Redis. Browse table schemas, run queries, and paginate results — all through Scalple's policy engine. Credentials stay in the vault.
- Expandable tree view — tables, collections, key views
- Query execution with filter, sort, and pagination
- Schema viewer with column types and nullability
- Connection status with real-time health checks
| # | ID | FIRST_NAME | LAST_NAME | CTR | SEGMENT |
|---|
Field- and record-level permissions.
CASL-based enforcement on every query. Roles map to your IdP groups — Entra ID, Google Workspace, or any OIDC provider. Edit permissions in the UI, not config files.
- Per-column field selection and per-row conditions on every query
- Role hierarchy with IdP group synchronization
- Entra ID, Google Workspace, and custom OIDC providers
- Permission editor UI — no config files to manage
Real-time audit log. INSERT-only, always.
Every access attempt is logged with actor attribution, query content, and result status. The schema enforces immutability — no UPDATE or DELETE path exists, even for database administrators.
- Real-time viewer with actor and query attribution
- WORM cold archive — nightly export to immutable storage
- Export as signed, timestamped PDF for auditors and regulators
- Cryptographic chain — tampering is structurally detectable
| TIME | USER | ACTION | TARGET | DURATION |
|---|
TypeScript scripts, sandboxed execution.
Write automation and reporting scripts in the Monaco editor with full TypeScript IntelliSense. Each script runs in a V8 Isolate with hard resource limits. Output files get signed download URLs.
- Monaco editor with TypeScript IntelliSense
- V8 Isolate sandbox — configurable memory and CPU limits
- Real-time log streaming as scripts execute
- Output file management with signed download URLs
Every query.
Immutably logged.
The audit log is not a feature that can be disabled. It is the only write path into the access record. The schema enforces INSERT-only semantics — there is no UPDATE permission, no DELETE permission, even for database administrators.
From credentials to controlled access in four steps.
Connect your database
Point Scalple at your PostgreSQL, MySQL, or MongoDB instance. Credentials stay in Scalple's encrypted vault — they are never exposed to developers.
Define access policies
Write policies in TypeScript. Specify which roles can query which tables, under what conditions, with what column-level redactions.
Developers request access
Engineers request scoped, time-limited sessions with a business justification. Approval workflows are optional but audited regardless.
Every query is logged
The developer receives query results. Simultaneously, the full operation — actor, query text, result count — is appended to the immutable audit log. No log entry means no query execution.
Start free. Scale when compliance demands it.
Annual licences paid upfront — aligned with EU enterprise budget cycles. All plans include self-hosted deployment. No per-seat pricing, no usage-based surprise invoices.
Full self-hosted deployment with core audit log and access controls. No usage limits on core features.
Early-stage startups, developers, and technical founders evaluating Scalple risk-free. Ideal for teams under 15 people.
- Full self-hosted deployment
- Core audit log — not gated
- Database access control
- GDPR-aware access trail
- Community support
- No usage limits on core features
Full compliance evidence, automated DSR processing, and priority support. Pass security reviews and satisfy auditors.
Series A scale-ups with 15–50 employees in fintech, healthtech, or SaaS that need to pass security reviews and respond to DSRs.
- Everything in Community
- Full audit log with compliance export
- Automated DSR processing
- Role-based access and privilege management
- GDPR & NIS2 compliance reporting
- Priority email support
- Onboarding assistance
- Optional 2-year discount — 10% off
DORA & NIS2 compliance module, air-gapped deployment, and a dedicated support SLA.
Series B/C fintechs and healthtech firms with 50–150 employees facing regulator scrutiny or enterprise procurement requirements.
- Everything in Professional
- DORA & NIS2 compliance module
- Air-gapped / on-premise deployment
- Dedicated support with SLA
- Privilege escalation detection and alerting
- Multi-team / multi-environment access management
- Quarterly security review calls
- Custom contract and invoicing
- Multi-year discount — 10% off 2-year
All prices are annual licences paid upfront · Aligns with EU enterprise budget cycles (Q4/Q1 approval)
Compliance is not a checkbox.
It is the architecture.
Regulatory requirements are encoded into access policy, not documentation. Your DPO can export evidence at any time.
We scope the proof of concept. Your team is live in one week.
No schema migrations, no agents on your database servers. We configure policies, integrate with your IdP, and validate the audit trail — your team is writing scoped queries within days.