Governed MCP access to your databases.
Warplock turns the tables, views and procedures you choose into an MCP surface that AI assistants can call. Every hop between the assistant and the database is named and enforced, and every authenticated call is audited. What you did not expose stays dark.
Illustrative entity. Filled cells are exposed columns.
Every pane, listed.
Seven groups, forty-odd features, one vocabulary. The names here are the names in the control plane and the documentation, so nothing needs translating between a sales conversation and a runbook.
Read the full feature listWhere exposure is decided.
The signed-in application: change spine, every area of the Web UI, roles and permissions.
Read about the control plane →
Query and response content can be set to never be stored.
Down to a single entity. Operational metadata is still kept, so you can see who asked what, without keeping what came back.
How audit and retention work →
Runtime surface
Decide what exists. Only entities an operator deliberately exposes become MCP tools.
SQL Connections · DAB Instances · Exposed Entities · Column Exposure · Column Redaction · TFN Redaction · Row Filter Presets · Procedure Contracts · SQL Capability checks · Schema Drift · Schema analysis · Exposed Entity Templates
Change control
No runtime-affecting DAB configuration reaches an environment without preview, validation, approval and an immutable version.
Draft Changes · Preview · Policy Governance · Promotion · Effective Config Versions · Deployment Jobs · Advanced overrides
Gateway and access
Who may call, from where, how often, and which tools they can see.
MCP Gateways · MCP Access Tokens · Restrict, rotate, revoke · Discovery filtering · Gateway-owned MCP Resources · Source Allowlist Policy · Rate limits · Registered Runtimes · Public ingress metadata
Microsoft 365 and Copilot
Hand a Gateway route to a Microsoft 365 tenant without embedding a secret in the package.
M365 App Package · OAuth clients · Dynamic Client Registration · Copilot Studio compatibility · Service-tag allowlists
Query Audit and retention
Every authenticated call is a record. What the record contains is a policy you set, down to a single entity.
Query Audit · Payload Policy · Zero Data Retention · Payload Viewer · Partner Payload Access · Audit Delivery Policy · Export · Retention cleanup
Operations
Placement and execution authority are separate. The worker applies only where both agree.
Runtime host inventory · Host Execution Credentials · Plan-only or Apply · Worker jobs · Runtime lifecycle · Operational Events · Notification Endpoints · Outbound Target Policies · Lifecycle Controls · Blank-Slate Reset
Identity and roles
Built-in accounts with the boring, verifiable defaults.
Argon2id passwords · TOTP MFA · Session versioning · Partner roles · Client roles · Active Client Context
Your databases. Their assistants.
Warplock runs on Microsoft Data API builder, so any source DAB supports can sit behind the same bars, and each entity can be served over MCP, REST or GraphQL.
- Microsoft SQL ServerOn-premises or hosted
- Azure SQLDatabase and Managed Instance
- PostgreSQL
- MySQL
- Azure Cosmos DBfor NoSQL
MCP · REST · GraphQL
- Streamable HTTP through the MCP Gateway
- DAB stdio for local development, outside the Gateway
- Microsoft 365 Copilot
- Copilot Studio
- Claude
- Cursor and VS Code
- Any MCP client over Streamable HTTP
What Warplock does not do
- It does not replace database permissions. SQL Server authentication, row-level security and grants remain the strongest boundary; Warplock narrows on top of them.
- It does not reach into your network beyond the backhaul you agreed. Your firewall, DNS and SQL Server stay yours; Warplock connects to the SQL host and port you nominated, from egress addresses you can allowlist.
- It does not keep recoverable token secrets. Tokens are one-way hashes shown once. SQL credentials are encrypted per Client and unwrapped on two audited paths only: a worker rendering a runtime's secrets file, which is then handled as a deployment secret, and an explicit encrypted Registered Runtime bundle.
- It does not let the model see what you did not expose. Withheld entities have no tool, no resource and no description.
Put your data behind the bars.
Bring a database and the questions your people keep asking it. Your partner will walk the thread with you from the WAF to the row.