Only metadata to the model
The AI sees table and column names, data types, relationships and a rough estimate of the number of rows per table. That is enough to write a query.
Private AI
Secure AI for business mainly means knowing which data goes to an AI model, who sees which answers, what gets logged and who is allowed to use it. ENABLE sends only metadata and the question to the model, never data rows, and runs queries read-only. The model is OpenAI's, accessed via the API; ENABLE has no model of its own and no on-premise model.
Which access profiles see which dashboards.
Secure AI for business is AI you can use on company data without losing control over where that data goes. "Private AI" sounds like one thing, but it really comes down to four questions: which data goes to the model, who may see which answers, what gets logged and who is allowed to use it?
ENABLE answers those questions with data minimisation. The AI only receives the structure of your data warehouse (tables, columns, relationships) and the user's question. The figures themselves stay in your database. Whatever the AI suggests is validated and only used once someone confirms it.
To be clear: ENABLE uses the OpenAI API. It is not a proprietary, EU-hosted or on-premise model. You decide per role who may use the SQL Explorer with AI, and you determine what the AI can see through the permissions of ENABLE's database user.
Key points
The AI sees table and column names, data types, relationships and a rough estimate of the number of rows per table. That is enough to write a query.
Query results, connection details and passwords never go to the AI. Secrets in ENABLE are encrypted with AES-256-GCM.
Queries run in a read-only transaction with a 45-second timeout. Writing or deleting is not possible.
AI output is validated and only used after a user action: in the SQL Explorer you run the query yourself; in the Dashboard Builder you choose "Apply proposal" or "Discard".
Roles and access profiles determine who can use the AI features. Signing in requires a password of at least 12 characters and two-step verification by email.
Executed queries and published API endpoints are recorded in the activity log, so you can see afterwards who did what.
The SQL Explorer with AI is available only to customer admins by default. For regular users it is only switched on if that has been configured for your organisation.
"Private AI" is used for very different set-ups: from a business account with a well-known chatbot to a proprietary model on your own servers. "Sovereign AI" and "European AI hosting" are also mainly about one question: where does the model run, and which jurisdiction applies to the data it processes?
For a secure AI environment, a better question is: which data does the model actually need to see? For questions about figures, the answer is often: not a single row. The model only needs to be able to write a query; your own database does the calculating. That is the choice ENABLE makes.
Use these questions for any AI solution, including outside ENABLE.
There is no single right choice. There is, however, a trade-off between what the model sees, who manages the environment and how verifiable the outcome is.
| ChatGPT with an export | AI on metadata in ENABLE | Own model on-premise | |
|---|---|---|---|
| What goes to the model | The exported rows | Table and column names and the question | Anything; the model runs on your premises |
| Where the model runs | At the AI provider | At OpenAI, via the API | In your own environment |
| Who calculates | The language model | Your own database (SQL) | Depends on the set-up |
| Verifiable | Difficult: the answer is text | Yes: query next to the result | Depends on the set-up |
| Access control | Per account, separate from your data | Roles, profiles, RLS, audit log | Up to you to set up |
| Management effort | Low, but exports get passed around | Low: managed platform | High: hardware, updates, expertise |
GDPR compliance is not a property of a tool, but of how your organisation processes personal data. That involves a lawful basis, data processing agreements, arrangements with sub-processors and sometimes a DPIA (data protection impact assessment). Those remain your own responsibility, including with ENABLE.
What ENABLE does: give the AI as little as possible. Do keep two things in mind. Metadata can also reveal something; a column such as "sick_leave_reason" says something about your organisation. Through the permissions of the database user, you decide which tables ENABLE, and therefore the AI, can see. And the question itself goes to the model, so don't type personal data or passwords into a question.
With ENABLE, three locations matter. If you are looking for a solution in which the AI model also runs in the EU or in your own environment, ENABLE does not offer that today.
| Component | Where |
|---|---|
| ENABLE portal | Vercel, Frankfurt region (fra1) |
| Your data warehouse | Wherever your organisation hosts it; this varies by customer |
| AI model | OpenAI, via the API |
| What the model receives | Metadata and the question, no rows |
In ENABLE
Give ENABLE's database user read-only permissions on the schemas and tables you want to expose. What ENABLE can't see, the AI can't see either.
The SQL Explorer is for customer admins by default and can be switched on for users per organisation. Access profiles control dashboards and apps.
The query sits next to the result, and you only use AI suggestions after confirming them.
Review the audit log: it lists every executed, blocked or failed query, with user and time.
FAQ
Secure AI for business is AI where you know which data goes to the model, who sees which answers, what gets logged and who is allowed to use it. In ENABLE, the AI only receives metadata and the question, never data rows.
That depends on your definition. ENABLE uses the OpenAI API and no model of its own, but it only sends metadata and the question to that API. Your data stays in your own data warehouse and queries run read-only.
GDPR compliance is not a property of a tool, but of how your organisation processes data. ENABLE helps by giving the AI only metadata and no data rows. Data processing agreements, lawful bases and any DPIA remain your own responsibility.
The ENABLE portal runs on Vercel in the Frankfurt region (fra1). Where your data warehouse is located varies by customer. The AI model is OpenAI's, accessed via the API.
No, not today. ENABLE uses the OpenAI API and only sends metadata and the question to it, never data rows.
The SQL Explorer with AI is available only to customer admins by default. For regular users it is only switched on if that has been configured for your organisation. The AI in the Dashboard Builder only works where that pilot module has been switched on.
In an online demo we show you the portal: dashboards per role, row-level security, plain-language questions and how we set it up and manage it for you.