Database access, governed
Your engineers need production data. QMELA gives them one place to connect, query and run data operations across every database you own — entitled before it runs, recorded after it does.
The state of things
Most teams solve database access once, informally, and live with it for years. The cost shows up later — in an incident review, or an audit.
One admin account, one password in a spreadsheet, used by everyone across every tenant. Nothing traces back to a person.
The grant made for a migration two years ago is still live. So is the contractor's login. Nobody has a list.
When something changes 40,000 rows at 2am, the answer to "who ran that, and why" takes days to reconstruct — if it can be.
The platform
Each letter is a service you can point at on an architecture diagram, not a marketing word.
A SQL workspace your engineers actually want to use — editor, saved queries, history, result export, and one dialect-aware surface over MySQL, PostgreSQL, SQL Server, Mongo and more. Long-running data operations run as tracked jobs, not abandoned sessions.
Nobody holds a live credential. QMELA vaults them and brokers every connection: columns masked on the way out, statements rewritten or refused on the way in, timeouts and row caps enforced, runaway queries killed. Blast radius becomes a setting, not a hope.
ACLs down to the column and the row, bound to roles rather than people. Time-boxed elevation with an approver, automatic expiry, and break-glass that pages someone. Access you granted for an afternoon ends that afternoon.
Every connection, statement, result fingerprint and grant change written once to a tamper-evident log. Nothing edits it, including QMELA. This is the write side — the thing that makes the audit side possible.
The read side of the ledger. Ask who touched customer PII last quarter and get an answer in seconds. Flag the unusual — bulk reads, off-hours DDL, first-time table access. Export evidence packs your auditors accept as-is.
How it works
The order matters here — each stage can stop the one after it.
They authenticate to QMELA with your existing SSO. They never see a hostname, port or password.
Role, target, table, columns, time window. Anything outside the grant is refused before a connection exists.
QMELA opens the connection with vaulted credentials, applies masking and limits, and rewrites or blocks unsafe statements.
Results come back through the platform, capped and masked. Heavy jobs queue instead of pinning a production primary.
Who, what, where, when, how many rows — written once, immutably, whether the statement succeeded or failed.
Search it, alert on it, export it. The evidence already exists when someone asks.
Who it's for
Early access
We're onboarding a small number of teams running heterogeneous fleets.