Skip to main content

The platform behind the data layer

A control plane between agents and private data: server-side credential resolution, scope rewrite before any statement runs, metering on every query, and a hash-chained audit trail. No inbound firewall holes.

Hebrah platform VM overview dashboard

Everything in one control plane

Connectors, scoped connections, hash-chained audit, metering, and relays — the infrastructure layer under every agent query.

Control plane

Built for agents

  • Scoped connections

    Table- and period-level scopes with server-side rewrite before any statement runs.

  • Hash-chained audit

    Connection open and every query append to a SHA-256 chain, exportable as JSONL.

  • Instant revoke

    Per-connection revocation in one call — the rest keep working.

  • Metering on every response

    cost_cents and bytes_egressed come back with each query.

See the API

12

Demo targets

6

Connector packs

Security

No credentials to agents

Agents hold a scoped, revocable key. The control plane resolves the real credential and rewrites scopes server-side.

Security hub

Agent tooling

Three ways in

Hosted MCP, the hebrah CLI, or the headless HTTP API — same registry, same wallet, same audit trail.

Developer hub

$1

Free credit to start

Reliability

Signed webhooks

HMAC-signed delivery with retry backoff and one-click replay for every sandbox-pack event.

Webhooks guide

Architecture

Outbound-only relay

Customer Postgres joins through one outbound mTLS tunnel — no inbound firewall holes.

Relay guide

$0.005

Per query

From signup to evidence

Three steps, 90 seconds, no card. Run it yourself or hand your agent /SKILL.md and it onboards itself.

Sign up headless

One POST creates the account and applies the $1 trial — via hosted MCP, the CLI, or the HTTP API. Your agent never talks to a human to start.

Open scoped connections

Discover targets, read each one's scope grammar, and connect with the tables and periods you approve. TTL bounds the blast radius.

Verify the evidence

Every query appends to a hash-chained audit trail. Export it as JSONL and hand your customer a chain that breaks loudly if anyone tampers with it.

Demo data for every market

Agents need realistic data to prove themselves. Hebrah ships six connector packs of healthy, queryable demo targets — audit ledgers, fintech settlements, synthetic FHIR, factory telemetry, workspace tools, and developer sandboxes.

The healthcare pack alone covers 13 sandbox domains, FHIR R4 resources, multi-step scenarios, and HL7 inject — no PHI ever touches the control plane. Every target has its own scope grammar, so agents are scoped before they connect.

Browse the connector catalog · Sandbox guide

Realistic vendor packs

The healthcare pack ships Epic, Cerner, and Athena-style sandboxes that exercise clinical, admin, and revenue workflows — synthetic end to end.

No PHI on the control plane

Synthetic FHIR R4 fixtures and HL7 templates live in sandbox only. Hebrah never stores real patient data on the control plane.

Five more packs

Developer, audit, fintech, workspace, and manufacturing — from GL ledgers to Slack channels, all healthy and queryable from the trial.

Governed access, by design

Credentials never leave the server

The agent holds a scoped, revocable key. The control plane resolves the real credential and rewrites scopes before any statement runs.

TTL-bounded blast radius

Connections expire by default. Short TTLs keep a leaked or forgotten connection from lingering.

Outbound-only relay

Customer-owned Postgres joins through one outbound mTLS tunnel — no inbound firewall holes, certificates minted by step-ca and renewed automatically.

Agents changed the data-access problem: they hold a working context across many services and act at machine speed. Hebrah answers at the connection layer — the agent holds a scoped key, the control plane resolves the real credential server-side, and SELECT \* returns only in-scope rows.

Because access is governed rather than blocked, agents still work at real data scale — millions of rows, across every source — metered per query, with exportable evidence.

How we secure agent access

Your command center

Monitor connections, review the audit trail, and track delivery history — one dashboard for the human side of the agent loop.

Connections watchlist

Every connection at a glance — health, traffic, and status. Jump into detail views for each one.

Connections watchlist in the Hebrah dashboard
Connections watchlist

Connections and delivery

Follow provisioning and connectivity per connection, step by step, before anything goes live.

Connection detail view in the Hebrah dashboard
Connections detail

Provisioning progress

Follow setup step by step with a clear progress view. Know exactly where each connection stands before it goes live.

Provisioning progress in the Hebrah dashboard
Provisioning progress

Delivery history

Track event delivery, replay failed notifications, and review activity — so nothing falls through the cracks.

Delivery history in the Hebrah dashboard
Delivery history

Agents changed the threat model

A script holds one token for one service. An agent holds a working context across many — it copies secrets into prompts, follows instructions at machine speed, and moves far more data than any human session. Hand it a warehouse password and every query it runs is unscoped, unmetered, and invisible to your customer.

Hebrah fixes this at the connection layer: agents never hold a credential, access is scoped to tables and periods with a TTL, every query appends to a hash-chained audit trail, and any connection revokes in one call. Because access is governed rather than blocked, agents still work at real data scale — millions of rows, across every source — metered per query, with exportable evidence your customers can verify.

Explore security map nodes

Control plane

Hebrah sits between agents and private data — credential resolution, scope rewrite, metering, and audit all happen server-side.

Get started

Start with $1 in free credit

Give your agent /SKILL.md and it onboards itself — 90 seconds, no card required.