Database access, governed

Many paths.
One trusted centre.

Your engineers need production data. QMELA gives them one place to connect, query and run data operations across every database you own — entitled before it runs, recorded after it does.

QQuery
MMediate
EEntitle
LLedger
AAudit

The state of things

Production access is handed out, then forgotten.

Most teams solve database access once, informally, and live with it for years. The cost shows up later — in an incident review, or an audit.

Shared credentials

One admin account, one password in a spreadsheet, used by everyone across every tenant. Nothing traces back to a person.

Access that never expires

The grant made for a migration two years ago is still live. So is the contractor's login. Nobody has a list.

No record of what ran

When something changes 40,000 rows at 2am, the answer to "who ran that, and why" takes days to reconstruct — if it can be.

The platform

Five parts. The name is the map.

Each letter is a service you can point at on an architecture diagram, not a marketing word.

Q
Query

Execution gateway

A SQL workspace your engineers actually want to use — editor, saved queries, history, result export, and one dialect-aware surface over MySQL, PostgreSQL, SQL Server, Mongo and more. Long-running data operations run as tracked jobs, not abandoned sessions.

M
Mediate

Connection broker

Nobody holds a live credential. QMELA vaults them and brokers every connection: columns masked on the way out, statements rewritten or refused on the way in, timeouts and row caps enforced, runaway queries killed. Blast radius becomes a setting, not a hope.

E
Entitle

Entitlement engine

ACLs down to the column and the row, bound to roles rather than people. Time-boxed elevation with an approver, automatic expiry, and break-glass that pages someone. Access you granted for an afternoon ends that afternoon.

L
Ledger

Append-only record

Every connection, statement, result fingerprint and grant change written once to a tamper-evident log. Nothing edits it, including QMELA. This is the write side — the thing that makes the audit side possible.

A
Audit

Evidence layer

The read side of the ledger. Ask who touched customer PII last quarter and get an answer in seconds. Flag the unusual — bulk reads, off-hours DDL, first-time table access. Export evidence packs your auditors accept as-is.

How it works

One statement, end to end.

The order matters here — each stage can stop the one after it.

  1. Engineer opens a session

    They authenticate to QMELA with your existing SSO. They never see a hostname, port or password.

  2. Entitlement is checked

    Role, target, table, columns, time window. Anything outside the grant is refused before a connection exists.

  3. The broker mediates

    QMELA opens the connection with vaulted credentials, applies masking and limits, and rewrites or blocks unsafe statements.

  4. The statement runs

    Results come back through the platform, capped and masked. Heavy jobs queue instead of pinning a production primary.

  5. The ledger records it

    Who, what, where, when, how many rows — written once, immutably, whether the statement succeeded or failed.

  6. Audit answers questions

    Search it, alert on it, export it. The evidence already exists when someone asks.

// session · anand@platform · role: support-l2 ENTITLE billing.invoices allow expires 17:30 ENTITLE billing.customers.pan mask ENTITLE billing.payouts deny MEDIATE row_limit=5000 timeout=30s MEDIATE ddl=blocked dml=approval > SELECT id, name, pan, amount > FROM billing.invoices WHERE id = 88214; id name pan amount 88214 Meera Rao XXXXX1234X 12,400.00 LEDGER #4f21a0 1 row 114ms recorded

Who it's for

Fewer tickets. Better answers.

For engineering

  • Query every database from one place, without chasing credentials
  • Access requests approved in minutes, not sprint cycles
  • Guardrails that stop the accidental full-table update
  • Shared queries and history the whole team can search
  • Data operations and migrations run as tracked, resumable jobs

For security and compliance

  • Least-privilege enforced by default, expiry included
  • Every statement attributable to a named human
  • Tamper-evident ledger built for evidence, not for debugging
  • PII masked at the boundary, not by convention
  • Reports for SOC 2, ISO 27001, HIPAA and RBI reviews

Early access

Bring your databases under one centre.

We're onboarding a small number of teams running heterogeneous fleets.