Skip to content
Warplock

Governed MCP access to your databases.

Warplock turns the tables, views and procedures you choose into an MCP surface that AI assistants can call. Every hop between the assistant and the database is named and enforced, and every authenticated call is audited. What you did not expose stays dark.

Exposed entity
dbo.Orders
read · 9 of 14 columns · TFN redaction on

Illustrative entity. Filled cells are exposed columns.

Withheld
dbo.Payroll
Not an Exposed Entity. No tool exists.
Withheld
dbo.Users
Not an Exposed Entity. No tool exists.

Seven bars. One thread.

A request is a single warp thread. Each stage lifts it, checks it, and passes it on. Nothing reaches the database that was not lifted at every bar.

Six bars are the Warplock service: a sovereign cloud edge, Warplock compute, and a private backhaul into your environment. The last one is yours. Each owner is named so there is no gap where responsibility is assumed.

Drawdown · exposed entities

Illustrative. Filled cells are exposed; empty cells never become tools.

Follow the thread there and back →
  1. 01 · Cloud edge

    WAF

    Barracuda CloudGen WAF

    The thread enters at the edge and is inspected before anything answers it. TLS inspection, intrusion detection and prevention, and a source allowlist decide whether it reaches the next bar at all.

    • TLS inspection of inbound traffic
    • Intrusion detection (IDS) on every session
    • Intrusion prevention (IPS) that drops matched traffic before it is routed
    • Source allowlists rendered from Microsoft service tags and manual CIDRs
    • Firewall-ready CIDR artifacts generated from the Gateway's Source Allowlist Policy

    Passes on Traffic from an allowed source network.

  2. 02 · Cloud edge

    Load balancer

    High-availability load balancer

    Public hostname, DNS and TLS. Many MCP Gateways share port 443 through distinct hostnames, and traffic is steered to a healthy Gateway service.

    • TLS termination and certificate lifecycle
    • Per-Gateway public HTTPS hostname from ingress metadata
    • Routing to the upstream Gateway service and port
    • Health-aware steering across Gateway services

    Passes on An HTTPS request bound for one opaque /mcp/:id route.

  3. 03 · Warplock · Sovereign cloud

    MCP Gateway

    Gateway service

    The bar that knows who is asking. The MCP Access Token is validated, scoped and never forwarded upstream.

    • Token hash lookup, expiry and revocation on every request
    • tools/list and resources filtered to the token's allowed Exposed Entities
    • Disallowed tools/call rejected before proxying (HTTP 403)
    • Source Allowlist Policy enforced in-process after auth and before the body is read, when the policy is in enforcing mode
    • Rate limits at Client, DAB Instance, Environment, token and entity scope
    • Metadata-only Query Audit written for every authenticated request

    Passes on A scoped JSON-RPC call with internal scope headers, no bearer token.

  4. 04 · Warplock · Sovereign cloud

    Policy pipe

    Gateway transforms + promoted policy

    What the model is allowed to see, and how it is described. Part of it runs in the Gateway on every request; part of it is policy Warplock stages and DAB enforces.

    • Column Redaction rules rewrite JSON and event-stream responses in the Gateway
    • TFN Redaction by DAB Instance default or entity override, before anything leaves the Gateway
    • Row Filter Presets, staged in Warplock and enforced by DAB as database policies after promotion
    • Retained payload capture, redaction and digest per Query Audit Payload Policy
    • Gateway-owned MCP Resources carry entity and column descriptions to the model
    • Control-plane schema analysis prefills keys, grain and descriptions so those resources are worth reading

    Passes on A request DAB is allowed to execute; a response the token is allowed to read.

  5. 05 · Warplock · Sovereign cloud

    DAB

    Microsoft Azure Data API builder

    Microsoft certified runtime, secured by Warplock. It executes only the entities Warplock promoted. Generated config, pinned image, no secrets in config.

    • Entity mapping and permission evaluation
    • MCP tool schema generation per Exposed Entity
    • REST and GraphQL endpoints enabled per entity when required
    • Immutable Effective Config Version per DEV, STAGING and PROD

    Passes on A query against the SQL principal the Client provided.

  6. 06 · Backhaul

    Backhaul

    Private Ethernet/Fibre · Tunnel · VPN · SD-WAN · SSH bastion

    The thread leaves the sovereign cloud on a private path agreed with you, never across the open internet to your database.

    • Private Ethernet or fibre where the sovereign cloud and your environment share a facility
    • Site-to-site VPN or SD-WAN into your network
    • Encrypted tunnel or SSH bastion for a single host
    • Fixed egress addresses you can allowlist on your own firewall
    • Only the SQL host and port you nominated are reachable; loopback, link-local and reserved targets fail closed

    Passes on A SQL session to the host and port you nominated.

  7. 07 · Your data

    Database

    Public cloud · Private cloud · IaaS · On-premises

    The strongest boundary is still yours, wherever it already runs. Database permissions, row-level security and procedure behaviour are never replaced, only narrowed on top of.

    • SQL Server, Azure SQL, PostgreSQL, MySQL or Cosmos DB, in your public cloud, private cloud, IaaS or on-premises
    • Authentication and database permissions
    • Row-level security and views
    • Stored procedure behaviour under a Procedure Contract

    Passes on Rows. Then the thread climbs back through every bar it came down.

Every pane, listed.

Seven groups, forty-odd features, one vocabulary. The names here are the names in the control plane and the documentation, so nothing needs translating between a sales conversation and a runbook.

Read the full feature list
The control plane

Where exposure is decided.

The signed-in application: change spine, every area of the Web UI, roles and permissions.

Read about the control plane →

Zero Data Retention

Query and response content can be set to never be stored.

Down to a single entity. Operational metadata is still kept, so you can see who asked what, without keeping what came back.

How audit and retention work →

12 features

Runtime surface

Decide what exists. Only entities an operator deliberately exposes become MCP tools.

SQL Connections · DAB Instances · Exposed Entities · Column Exposure · Column Redaction · TFN Redaction · Row Filter Presets · Procedure Contracts · SQL Capability checks · Schema Drift · Schema analysis · Exposed Entity Templates

7 features

Change control

No runtime-affecting DAB configuration reaches an environment without preview, validation, approval and an immutable version.

Draft Changes · Preview · Policy Governance · Promotion · Effective Config Versions · Deployment Jobs · Advanced overrides

9 features

Gateway and access

Who may call, from where, how often, and which tools they can see.

MCP Gateways · MCP Access Tokens · Restrict, rotate, revoke · Discovery filtering · Gateway-owned MCP Resources · Source Allowlist Policy · Rate limits · Registered Runtimes · Public ingress metadata

5 features

Microsoft 365 and Copilot

Hand a Gateway route to a Microsoft 365 tenant without embedding a secret in the package.

M365 App Package · OAuth clients · Dynamic Client Registration · Copilot Studio compatibility · Service-tag allowlists

8 features

Query Audit and retention

Every authenticated call is a record. What the record contains is a policy you set, down to a single entity.

Query Audit · Payload Policy · Zero Data Retention · Payload Viewer · Partner Payload Access · Audit Delivery Policy · Export · Retention cleanup

10 features

Operations

Placement and execution authority are separate. The worker applies only where both agree.

Runtime host inventory · Host Execution Credentials · Plan-only or Apply · Worker jobs · Runtime lifecycle · Operational Events · Notification Endpoints · Outbound Target Policies · Lifecycle Controls · Blank-Slate Reset

6 features

Identity and roles

Built-in accounts with the boring, verifiable defaults.

Argon2id passwords · TOTP MFA · Session versioning · Partner roles · Client roles · Active Client Context

Your databases. Their assistants.

Warplock runs on Microsoft Data API builder, so any source DAB supports can sit behind the same bars, and each entity can be served over MCP, REST or GraphQL.

Databases
  • Microsoft SQL ServerOn-premises or hosted
  • Azure SQLDatabase and Managed Instance
  • PostgreSQL
  • MySQL
  • Azure Cosmos DBfor NoSQL
Protocols per entity

MCP · REST · GraphQL

Transports
  • Streamable HTTP through the MCP Gateway
  • DAB stdio for local development, outside the Gateway
MCP clients
  • Microsoft 365 Copilot
  • Copilot Studio
  • Claude
  • Cursor and VS Code
  • Any MCP client over Streamable HTTP

What Warplock does not do

  • It does not replace database permissions. SQL Server authentication, row-level security and grants remain the strongest boundary; Warplock narrows on top of them.
  • It does not reach into your network beyond the backhaul you agreed. Your firewall, DNS and SQL Server stay yours; Warplock connects to the SQL host and port you nominated, from egress addresses you can allowlist.
  • It does not keep recoverable token secrets. Tokens are one-way hashes shown once. SQL credentials are encrypted per Client and unwrapped on two audited paths only: a worker rendering a runtime's secrets file, which is then handled as a deployment secret, and an explicit encrypted Registered Runtime bundle.
  • It does not let the model see what you did not expose. Withheld entities have no tool, no resource and no description.

Put your data behind the bars.

Bring a database and the questions your people keep asking it. Your partner will walk the thread with you from the WAF to the row.