Data control planeAI data firewall

Agents see use
your data.

Ascent is the control plane between data and everything that asks for it — agents, applications, and people.

Your own instance in about an hour. Trials pause after 14 days; nothing is deleted.

Introduction — the problem, and the control plane that answers it

real product footage, not a mockup

Five core features, on the real product.

79 seconds · see → define → enforce → use → prove

Product overview — fleet, blast radius, permissions, refusals and response, four views, evidence

Use cases and where teams start.

Identify and stop rogue AI.

Automated, real-time action to block misbehaving agents.

Block unapproved models.

Decide which AI vendors are allowed near your data. The rest never get a look.

Vibe code with confidence.

Let coding agents build against real-looking data that isn't. Ship fast without shipping a leak.

AI on regulated data.

Put agents on health, payment and HR records without widening who or what can see them. When the auditor asks, you have the proof.

True least privilege access.

Grant access to only the view and slice of data necessary for people, application, or AI to work correctly, nothing more nothing less.

One record, every caller

Show the agent the customer. Not the card number.

Not four copies of your data — one record, and a policy that decides which representation each caller has earned.

anonymizedthe AI agent · record:get_with_anonymize

Realistic stand-ins: the shape and statistics survive, the person does not. This is how an agent works on your data without seeing it.

emailuser_8f21@example.test
phone+1 555 010 2048
ssn000-00-2048

What makes it a control plane

A database permission was never built for this.

Four differences, each with the pain it removes and where the alternatives stop.

01

The view is the permission.

Others decide whether you reach the data. Ascent decides what comes back — chosen per request by policy that scopes identity, action, object, and condition. Deny wins. Plaintext is granted, never assumed.

Where others stop

Database encryption protects data at rest, then hands your application the plaintext. Encryption that ends at the connection is not a control.

02

One policy, every door.

SQL, REST, MCP, CLI, portal — one policy engine, one set of views, one audit trail behind all of them. Your ORM doesn't know it's talking to a vault.

Where others stop

A vault API makes you rebuild your data layer around its shape. In-house builds start consistent and drift into per-service enforcement.

03

Containment, not a warning.

Every agent is its own identity, safe by default. When a permitted credential starts moving too fast, the vault freezes the container, revokes the token, and deactivates the identity — before the read that tripped the threshold returns.

Where others stop

Prompt rules advise a model that can ignore them. Output scanners tell you after the data left. Enforcement below the model is not persuadable.

04

Your cloud. Your keys. Your call.

Deployed inside your boundary, single-tenant or a database per customer. Rotate on managed keys or your own KMS keys, a key webhook, or signed updates — the platform never has to hold your master key.

Where others stop

SaaS platforms route your records through their cloud — a second copy, a second trust boundary, and a residency conversation you cannot win.

Policy and workflows

Refuse it before it lands.

Policy answers every request — allow, deny, and in which view. A workflow is what happens next: run it before the request completes and it can refuse it outright; run it after, and it reacts to what just happened.

Access is conditional, not binary

Same agent, same request — the answer changes with the circumstances.

WhoYour support agent
Mayread customer records in plaintext
Only ifon your networkin an approved countryweekdays, working hoursMFA on the sessionsanctioned credential

All of them hold

The record comes back in plaintext, and the decision is on the record.

One of them doesn’t

Refused — or answered in a safer view. That decision is on the record too.

The same grammar scopes a whole company or a single field: a tenant-wide backstop, a role for one team, or an exception on one container.

A workflow that can say no

Triggered by an action, narrowed by a filter, armed with a rate threshold.

triggerrecord:get_with_decrypt · pre · ≥30 in 60s per token
01freeze_containerseal it
02revoke_tokenkill the credential
03deactivate_entityno second token
04webhooktell your SIEM
05droprefuse the read

Order is the design: contain first, alert second — a dead alert sink costs you the alert, never the freeze. Test a workflow against sample data before you arm it, and choose whether an errored one fails open or fails closed.

The AI data firewall

Stopped in the moment. Not reported in the morning.

An over-privileged credential does nothing it isn’t allowed to do — it just does it thirty times in a minute. This is the control that catches a valid credential being abused, and it runs without a human in the loop.

t + 0s

Reads allowed

Policy permits decrypt. Nothing is violated.

threshold

Rate tripped

30 decrypting reads in 60s, one token. Signs of data exfiltration.

action

Data container frozen

Nothing more comes in or out of it.

action

Access

Agent is quarantined from accessing all data.

result

Read refused

The request that tripped it never returns.

Accessible from any source

Nothing to rewrite.

However the request arrives — and whoever sends it — the same policy decides it, the same views answer it, and the same audit log records it.

SQLapplication

Your existing code, unchanged. Native drivers for five languages speak the interface each already uses.

services · jobs · reporting

RESTapplication

One OpenAPI contract for anything that speaks HTTP — internal integrations and partners alike.

integrations · partners · webhooks

MCPAI agent

A governed gateway. Read-only and redacted until an operator grants each capability, per agent.

assistants · copilots · autonomous agents

Portal & CLIhuman

For the people who administer, investigate, and answer customers — with the same limits as everything else.

admins · support · analysts · auditors

An engineer moving an existing SQL database across brings it with one command — the sensitive columns are classified and encrypted on the way in, and both sides are verified afterwards.

Self-hosted

Runs in your infrastructure. Nothing has to leave your network boundary.

Bring your own keys

KMS keys you own, a key webhook, or signed key updates.

Every access explained

Which policies were consulted, which one decided, and why.

Try it on your own instance today. No credit card.

No credit card

Start a free trial

Open the chat and pick "I would like a trial ASAP".