Read-only (SELECT-only)
Only SELECT queries are generated; write and delete operations are technically blocked. PerSight cannot make any change to your data.
SECURITY & DATA FLOW
We've put PerSight's data flow, permission model and privacy posture on one page. You can share this page with your security or IT lead.
STAYS ON YOUR MACHINE
SENT TO THE CLOUD
Only SELECT queries are generated; write and delete operations are technically blocked. PerSight cannot make any change to your data.
Every generated query is shown on screen and explained in plain language before it runs; the operator can edit and approve it. No black box.
The content sent to the cloud (schema + question) is shown verbatim inside the app. We don't just say it, we show it.
You define the connection with a read-only database user; credentials are stored encrypted on the device (DPAPI on Windows, ASP.NET Data Protection on macOS).
The text of your question is never written to server logs; only numeric telemetry such as duration, status and counters is kept. Generated queries are stored in a cache cryptographically isolated per organization and never leave your organization.
For each question, only the NAMES of the tables and columns relevant to that question leave your machine — in a database with hundreds of tables that is typically just a handful. The in-app transparency panel shows which tables were sent and how many were considered. Row data is never sent.
Because real row data is never sent to the cloud for processing, the personal data transferred to third parties is minimized. This supports your data-protection posture; final compliance depends on your entire data pipeline and processes.
All of this information and the encryption keys stay on your device — they're stored encrypted using your operating system's protection layer (DPAPI on Windows, ASP.NET Data Protection on macOS) and are never sent to the cloud.
Write to us for a corporate security review or custom setup.