◇ AI meets your data — safely ◇

AI uses your data.Conarium watches its every move.

Conarium is the governance layer between enterprise AI and sensitive data. We enforce policy, mask data, and record every action — in real time.

Break it if you can — every attempt lands in the audit log.

Conarium governance eye — incoming systems flow through the eye and exit as governed outputs
Incoming systems
Governed outputs
AI Agent
Analytics Tool
App / Service
Data Pipeline
Third-party AI
BI Dashboard
Masked Data
Filtered Rows
Allowed Fields
Safe Context
Policy Applied
Audit Recorded
Governance · Active
◑ PII Masking
⊘ Deny by Default
≣ Row & Field Controls
⌖ Immutable Audit Logs
◈ Policy Enforcement
View live policy status →
0
0
0
Self-hostedData stays in your perimeter
Zero data egressNothing leaves your network
KVKK / GDPR audit trailAudit without raw PII
Works with your stack ·PostgreSQLDocs & MarkdownOpenAPISlackJiraClaudeCodexCursorCopilot
In plain English
Think of it as a checkpoint at your door.

An AI coding tool is like a brilliant new consultant you turn loose in your filing room. It works incredibly fast — but it reads everything, including what no outsider should ever see: customer names, passwords, card numbers. Conarium is the checkpoint at the door: before the consultant sees a single file, it blacks out every secret, notes down everything that was looked at, and makes sure not one original ever leaves the building.

You decide what's allowed. You keep the key.

And the clever part — the company that makes Conarium never sees your files either. It runs inside your own walls, so there's nothing for anyone to leak.

See what your AI sees
Watch your own data leak — then stop it.

Pick a sample or paste your own. See exactly what an AI assistant reads the moment you point it at real data — then flip Conarium on. Everything runs in your browser; nothing is ever uploaded.

This is a pattern-based preview. See what production masking does — and doesn't — catch →

The problem
AI sees everything.
So does the risk.

Point Cursor or Copilot at a production database and it drinks the raw stream — national IDs, IBANs, balances, live keys. One prompt can expose your most sensitive tables. Security teams simply can't allow that.

⚠ ungoverned
USER PROMPT
Show me recent account holders
AI — WITHOUT GOVERNANCE
1Ayşe DemirTR00 0000 0000 0000 0000 000112345678901+90 5xx xxx 00 01₺482,900
2Mehmet YılmazTR00 0000 0000 0000 0000 000212345678902+90 5xx xxx 00 02₺1,204,350
3Zeynep KayaTR00 0000 0000 0000 0000 000312345678903+90 5xx xxx 00 03₺76,120
RESULT: MASSIVE BREACH WAITING TO HAPPEN.
How it works
One eye between the model and your data.
AI Assistants
Claude
Codex
Cursor
Copilot
Conarium
MCP Governed Gateway
Your Sources
Postgres
Docs & ADRs
OpenAPI
Jira · Slack
Live demo
Watch it govern in real time.

No narration — the real pipeline. A request arrives, the eye decides, and the audit writes itself.

Live
1 PII Masking
2 Row Caps 100
3 Policy Deny
AI · Request
Data returned
Audit trail · live
PII masked before AI sees it Row caps enforced Policy guardrails active Immutable audit logged
Interactive Demo
Try to steal our secrets.

Act as a rogue AI or a malicious developer. Try to extract PII from our database. Watch how Conarium intercepts and masks it in milliseconds.

ATTACK VECTORS

AI TERMINAL
> Waiting for query execution...
Nice try. Nothing leaked 🛡️ AUDIT LOGGED
Try it yourself
Don't take our word for it. Point your own AI at it.

This is a live Conarium server with a governed sample database. Connect it to your own Claude in about 30 seconds and try to get the data out. You won't be able to — and you'll see exactly why.

CONNECTOR URL
https://demo.conarium.dev/t/conarium-public-demo-tryit-2026/mcp
STEP 1

In Claude, open Settings → Connectors → Add custom connector.

STEP 2

Paste the URL above, name it anything, and connect.

STEP 3

Ask it for the revenue. Then ask it for the customer list.

WHAT YOU'LL SEE
Revenue → answered

Business figures come back instantly. Governance isn't a wall; the work still gets done.

Names → [MASKED_PII]

Sales rows arrive complete, but every name, phone and email is redacted before the model reads it.

Customer table → denied

Not permitted by policy. The AI can ask; it simply never gets an answer.

Sample data is entirely synthetic — no real company, no real people. The connector is read-only and rate-limited. This is the same code you can read on GitHub and run on your own server.

Key features
Built for security. Designed for engineers.

PII Masking

Emails, IDs, cards and secrets redacted in the response stream — before the model sees a character.

Allow / Deny

Whitelist what AI can access. Your secrets table stays invisible; unauthorized access throws PolicyError.

Row Caps

Hard per-query limits. No silent exfiltration of millions of rows. You stay in control.

Immutable Audit

Every access logged — who, what, when, rows, decision — in a hash-chained, tamper-evident ledger. Alter one entry and the chain shatters. Built for KVKK / GDPR evidence, no raw PII.

Verifiable Receipts

Every governed access can emit a portable receipt — Ed25519-signed, carrying the fields EU AI Act Article 12 / 19 asks for, with chain heads anchored to OpenTimestamps. An auditor checks it offline using conarium-verify: no Conarium install, no call back to us. It proves records were not altered, deleted, reordered or backdated after they were created — it does not claim they were correct when written.

Read-Only Write-Guard

DELETE, DROP, UPDATE, INSERT — blocked at the door. Even smuggled inside comments or stacked queries. The assistant can read; it can never wreck.

Beyond-the-Column Masking

PII slipped past as base64 or hidden behind an alias (email AS contact)? Still caught. Masking follows the data, not just the column name.

Every Source, One Layer

Postgres, internal docs, OpenAPI specs, Jira and Slack — a single governed layer over all your scattered knowledge, spoken in MCP to every assistant.

Self-Hosted

Runs entirely on your infrastructure. Your data never crosses your perimeter. Not ours. Yours.

Tool-Agnostic

Claude, Codex, Cursor, Copilot. Bring whatever assistant your team already loves.

Proven, not promised
Attacked on purpose. By our own red-team.

Most tools are merely configured to be safe. Conarium is attacked by an adversarial red-team that tries to break every policy — write-smuggling, unauthorized access, PII slipped past the mask. Whatever it bypasses, we harden — then it attacks again to verify the fix. We don't claim secure. We prove it, and re-prove it.

Red-team attacks the policy
Bypasses get hardened
Fix re-verified by attack
Live in production
121,366 identities protected. Zero intelligence lost.

A production AI assistant runs a real company's ERP — its customers, suppliers and staff. Every one of the 121,366 real identities is pseudonymized before it ever reaches the model. The AI reasons on opaque tokens; the operator sees the real names on the way back. Raw contact data — phone, email, tax IDs — never crosses the boundary at all.

What the model receives
Top customer: Record #12 — ₺1.7M
Salesperson: Record #47
Phone: [redacted]
What the operator sees
Top customer: ▓▓▓▓▓ ▓▓▓▓ — ₺1.7M
Salesperson: ▓▓▓▓ ▓▓▓
Phone: on screen only
[CONARIUM-AUDIT] { pseudonymized: 121366, leaked_to_model: 0 }

Read Governance Report 001 - what it proves, what it does not, and the measurement error we made →

"Your most valuable customer is also your single biggest concentration risk — when did anyone last speak to them?"
— the assistant, reasoning on tokens it cannot de-anonymize
Architecture
Zero Egress. Total Control.

Conarium is designed from the ground up for zero-trust environments. It runs inside your VPC, acts as a local MCP server, and ensures your raw data never leaves your perimeter.

DEVELOPER MACHINE
IDE (Cursor / Copilot)
AI Assistant
YOUR SECURE VPC
Conarium
GOVERNANCE LAYER
Postgres / MySQL
Internal APIs
MCP over stdio
No Inbound Ports
No External APIs
For Security Leaders
CISO F.A.Q.

Does Conarium store our data?

No. Conarium is a stateless gateway. It processes data in memory to apply masking and row caps, then streams it directly to the local MCP client. The only thing written to disk is your PII-safe audit log.

Are we training AI on our data?

Conarium intercepts PII and secrets before they reach the LLM; and because it runs self-hosted, you choose which model to use — including zero-retention endpoints — so the end-to-end data flow stays under your control.

How does it help with KVKK / GDPR?

Conarium provides an immutable, append-only JSONL audit log of every database query made by AI, including the rows returned and the policies applied. This supports access-monitoring and data-governance controls.

How is Conarium deployed?

As a standalone Node.js binary or Docker container within your VPC. It communicates with developer machines entirely over standard I/O (stdio) via the Model Context Protocol, meaning absolutely no open inbound ports.

Quickstart
From zero to governed in minutes.

Deploy Conarium locally or in your VPC, configure your policy, and attach it to your IDE.

STEP 1

Install & Init

Clone the repository and install dependencies to get the Conarium server ready on your infrastructure.

# Clone and build Conarium
git clone https://github.com/dogrucanemek-alt/conarium.git
cd conarium
npm install
npm run build
STEP 2

Define Policy

Write a simple JSON policy to define which tables are allowed, what columns to mask, and row limits.

{
  "allowTables": ["public.accounts"],
  "denyTables": ["public.card_vault"],
  "maskColumns": ["accounts.iban", "accounts.tckn"],
  "maxRows": 50
}
STEP 3

Attach to IDE

Configure Cursor or Claude Code to use Conarium via standard I/O MCP transport.

// cursor.json or mcp.json
{
  "mcpServers": {
    "conarium": {
      "command": "node",
      "args": ["/path/to/conarium/dist/index.js"]
    }
  }
}
Why Conarium
Not a proxy. A witness.

A few big, well-funded companies touch this. Here is the honest difference.

Cloud maskers

They protect your data by first sending it to their servers. Conarium never sees it — it runs inside your walls.

Access gateways

They guard the door — who is allowed in. Conarium masks what is actually in the room.

AI firewalls

They stop hackers from tricking your AI. Conarium stops your own trusted AI from quietly walking out with your data.

We couldn't leak your data if we wanted to — we don't have it.

Capability
hoop.dev
MintMCP
Conarium
Data-content PII masking
✓ wire-level
not documented
✓ deterministic
Allow/deny + row caps
✓ row-level
Immutable, PII-safe audit
session replay
✓ hash-chained
Portable receipt, verifiable offline without us
not documented
not documented
✓ Ed25519
Reconciliation against the database's own counters
not documented
not documented
✓ conarium-reconcile
SOC 2 Type II
— we never receive your data
Self-host, platform-agnostic
— SaaS

Of the ten projects we scanned, none combines all three: enforcement before the model, a receipt you can verify without us, and reconciliation against the data source's own counters. That is the whole claim — we make no wider one.

Named comparison (one list): hoop.dev, Lasso, Bifrost, Docker MCP Gateway, MintMCP, Lunar MCPX — full table with numbers on compare.html. This grid shows two. Measured 29–31 July 2026 from each project's own docs. “Not documented” means we could not find it documented — it does not mean the product lacks it. If we got something wrong about your project, email us and we will correct it.

See the named comparison, with numbers - including five places where they beat us →

Pricing
Open core. Self-hosted by default.

Start free and fully self-hosted. Upgrade when your team needs more sources, a console, and support — your data never leaves your perimeter at any tier.

The core is MIT-licensed and free forever. Paid tiers buy support and assistance — not access to the code.

Community
Free/ self-hosted
Set it up yourself, run it yourself.
  • Core governance — PII masking, allow / deny, row caps
  • Immutable, PII-safe audit log
  • All connectors — Postgres, docs, OpenAPI, Jira, Slack
  • Governance console + per-consumer policies
  • Community support — GitHub issues
Get started free
Pro
$20/ month
Someone answers when it breaks.
  • Everything in Community
  • Email support — reply within one week
  • Advance notice before breaking changes
Get started
Business
$100/ month
Be ready the day someone says “prove it”.
  • Everything in Pro
  • Priority support — reply within three business days
  • Evidence pack generated by the tooling on your side — your logs never leave your servers
Get started
Enterprise
Custom/ contact
Procurement, regulators and an SLA.
  • Everything in Business
  • The receipt states how the identity was established — nobody is named on a shared credential
  • Signed audit export (KVKK / GDPR)
  • SLA + dedicated support
  • Contract and DPA review
Contact us
Free Risk Assessment
How exposed is your data?

Take this 30-second self-assessment to discover if your AI coding assistants are leaking sensitive PII to external models.

1. Do your engineers use AI assistants (Cursor, Copilot, etc.) that can access internal databases?

Emek Can Doğru, Founder of Conarium
From the founder

I built Conarium because I needed it myself. Our own ERP had to let AI work across 100,000+ real customer records and 10,000+ incoming messages a month — with zero chance of a leak. The governance layer that made that safe became this product.

If you're shipping AI on sensitive data and losing sleep over it, I'd like to hear from you. I answer every email personally.

Emek Can Doğru — Founder · e.dogru@conarium.dev
Design Partner Program
Give your developers the power of AI.
Without giving up control.

Self-hosted, MCP-native, governed by you alone. Be among the first teams to let AI touch production — safely.

Read the docsView source ★