“What did the vendor actually see?”
GLEJT stores the values of every result page viewed — replayable step by step.
Secure DB Audit Gateway — by System Access
GLEJT is a security gateway for read-only access to production databases. SQL specialists and external vendors investigate incidents; GLEJT enforces SELECT-only, time-boxes every grant to a real ticket — and records exactly what each person saw, in an audit nobody can rewrite.
“What did the vendor actually see?”
GLEJT stores the values of every result page viewed — replayable step by step.
“Could our audit log be rewritten?”
Not undetectably: append-only WORM storage, hash-chained, verified in one click.
“Who still has access from last quarter?”
Nobody. Access is bound to a ticket and a time window — it expires by itself.
How it works
GLEJT sits as a proxy in front of your databases. No agents, no schema changes — credentials never leave the gateway.
An admin registers a database connection. Credentials are envelope-encrypted with AES-256-GCM; the master key lives outside the database.
Access exists only as an allocation: user + connection + open ticket + expiry. Tickets are validated live in Jira or ServiceNow — fail-closed.
Only SELECT statements pass — enforced by SQL parsing and again by a read-only DB session. Results are paged; every viewed page is captured with its values.
Replay any session as a timeline and export an Ed25519-signed evidence pack (PDF + JSON) that verifies offline — without trusting GLEJT, or us.
Capabilities
Not another SQL client — a control plane for the riskiest access you grant.
Read-only gateway
DDL, DML, multi-statements and procedure calls are hard-blocked — twice, independently. Every refused statement is recorded as DENIED, so an “accident” becomes evidence.
Row-level capture
Query logs tell you what was asked. GLEJT records what was answered: the exact rows of every page each user opened, bound to their session.
Access governance
Every grant is a time-boxed allocation tied to a live-validated ticket. Sensitive grants can require a second pair of eyes — and for 3 a.m. incidents there is break-glass with a mandatory morning review.
Tamper-evident audit
Audit tables are append-only and hash-chained; integrity is verified in one click. Admin actions — who granted, who changed what — live in the same tamper-evident ledger.
Data protection
Sensitive columns are masked before display and before audit — the audit trail never becomes a second copy of PII. And when data does leak, a keyed blind index answers “who saw this person's records?” in seconds.
Detection & response
SQL Sentinel scores every statement: known exfiltration patterns auto-suspend the allocation on the spot, and anomaly heuristics flag off-hours access, unusual volumes and first touches of sensitive tables.
Enterprise fit
Self-hosted proxy: your network, your keys, no agents on the databases. Identities come from your IdP, events flow to your SIEM, and tickets stay the source of truth.
The details that decide security reviews.
If the audit record can't be written, the data is not shown. There is no “seen but unrecorded”.
Envelope encryption (AES-256-GCM); the master key never sits next to the data.
Who changed which rule, when, from which IP — with before/after snapshots.
Admin, Analyst, Developer, External — enforced on the server, not in the UI.
Purge captured values per policy; the tamper-evident event ledger remains.
Request → approve → time-boxed access. One-click approvals, no standing grants.
Zero-install browser client over one HTTPS endpoint; thin Tauri desktop app.
Sensitive modules ship as compiled native code — resistant to tampering.
Tamper-evident records per user, per query, per row viewed — mapped to the frameworks you answer to.
Pricing
Start with the core gateway and switch on only the modules you need. Prices are per user, per month — estimates to size a deal.
Add-on modules
Roadmap
Built with security teams, for security teams — the next bets:
The hash-chain head published to external append-only storage, plus an open-source verifier: evidence anyone can check without trusting GLEJT — or us.
Signed webhooks to SOAR and PagerDuty, kill-session in flight, one-click playbooks: suspend, evidence pack, ticket.
A schema scanner proposes PII columns and classification tags — one definition feeding masking, Sentinel and the blind index.
Snowflake, BigQuery, Redshift and MongoDB behind the same gateway and the same proof.
Self-hosted, running against one UAT database in days. No agents, no schema changes — and your first signed evidence pack the same afternoon.
We'll get back to you within one business day to schedule your 30-minute demo.