EnableYourData.nl

Private AI

Secure AI for business starts with what the model sees.

Secure AI for business mainly means knowing which data goes to an AI model, who sees which answers, what gets logged and who is allowed to use it. ENABLE sends only metadata and the question to the model, never data rows, and runs queries read-only. The model is OpenAI's, accessed via the API; ENABLE has no model of its own and no on-premise model.

Secure AI for business is AI you can use on company data without losing control over where that data goes. "Private AI" sounds like one thing, but it really comes down to four questions: which data goes to the model, who may see which answers, what gets logged and who is allowed to use it?

ENABLE answers those questions with data minimisation. The AI only receives the structure of your data warehouse (tables, columns, relationships) and the user's question. The figures themselves stay in your database. Whatever the AI suggests is validated and only used once someone confirms it.

To be clear: ENABLE uses the OpenAI API. It is not a proprietary, EU-hosted or on-premise model. You decide per role who may use the SQL Explorer with AI, and you determine what the AI can see through the permissions of ENABLE's database user.

Key points

Secure AI for business at a glance

Only metadata to the model

The AI sees table and column names, data types, relationships and a rough estimate of the number of rows per table. That is enough to write a query.

No rows, no passwords

Query results, connection details and passwords never go to the AI. Secrets in ENABLE are encrypted with AES-256-GCM.

Read-only execution

Queries run in a read-only transaction with a 45-second timeout. Writing or deleting is not possible.

A person decides

AI output is validated and only used after a user action: in the SQL Explorer you run the query yourself; in the Dashboard Builder you choose "Apply proposal" or "Discard".

Access per role and profile

Roles and access profiles determine who can use the AI features. Signing in requires a password of at least 12 characters and two-step verification by email.

Audit log

Executed queries and published API endpoints are recorded in the activity log, so you can see afterwards who did what.

Limits who uses AI

The SQL Explorer with AI is available only to customer admins by default. For regular users it is only switched on if that has been configured for your organisation.

What is private AI, and what is secure AI for business?

"Private AI" is used for very different set-ups: from a business account with a well-known chatbot to a proprietary model on your own servers. "Sovereign AI" and "European AI hosting" are also mainly about one question: where does the model run, and which jurisdiction applies to the data it processes?

For a secure AI environment, a better question is: which data does the model actually need to see? For questions about figures, the answer is often: not a single row. The model only needs to be able to write a query; your own database does the calculating. That is the choice ENABLE makes.

Four questions to test AI privacy in your business

Use these questions for any AI solution, including outside ENABLE.

  • Which data goes to the model? With ENABLE, metadata and the question; when explaining or fixing a query, also that query and the error message.
  • Who sees which answers? With ENABLE, roles, access profiles and row-level security determine who sees what.
  • What gets logged? With ENABLE, executed queries and publications are recorded in the activity log.
  • Who may use it? With ENABLE, the SQL Explorer with AI is for customer admins only by default.

Three ways to use AI securely

There is no single right choice. There is, however, a trade-off between what the model sees, who manages the environment and how verifiable the outcome is.

ChatGPT with an exportAI on metadata in ENABLEOwn model on-premise
What goes to the modelThe exported rowsTable and column names and the questionAnything; the model runs on your premises
Where the model runsAt the AI providerAt OpenAI, via the APIIn your own environment
Who calculatesThe language modelYour own database (SQL)Depends on the set-up
VerifiableDifficult: the answer is textYes: query next to the resultDepends on the set-up
Access controlPer account, separate from your dataRoles, profiles, RLS, audit logUp to you to set up
Management effortLow, but exports get passed aroundLow: managed platformHigh: hardware, updates, expertise

GDPR compliant AI: what ENABLE does and doesn't handle for you

GDPR compliance is not a property of a tool, but of how your organisation processes personal data. That involves a lawful basis, data processing agreements, arrangements with sub-processors and sometimes a DPIA (data protection impact assessment). Those remain your own responsibility, including with ENABLE.

What ENABLE does: give the AI as little as possible. Do keep two things in mind. Metadata can also reveal something; a column such as "sick_leave_reason" says something about your organisation. Through the permissions of the database user, you decide which tables ENABLE, and therefore the AI, can see. And the question itself goes to the model, so don't type personal data or passwords into a question.

European AI hosting and sovereign AI: what runs where?

With ENABLE, three locations matter. If you are looking for a solution in which the AI model also runs in the EU or in your own environment, ENABLE does not offer that today.

ComponentWhere
ENABLE portalVercel, Frankfurt region (fra1)
Your data warehouseWherever your organisation hosts it; this varies by customer
AI modelOpenAI, via the API
What the model receivesMetadata and the question, no rows

In ENABLE

How to set up secure AI in ENABLE

  1. 01

    Decide what ENABLE sees

    Give ENABLE's database user read-only permissions on the schemas and tables you want to expose. What ENABLE can't see, the AI can't see either.

  2. 02

    Decide who uses AI

    The SQL Explorer is for customer admins by default and can be switched on for users per organisation. Access profiles control dashboards and apps.

  3. 03

    Check every outcome

    The query sits next to the result, and you only use AI suggestions after confirming them.

  4. 04

    Monitor and adjust

    Review the audit log: it lists every executed, blocked or failed query, with user and time.

FAQ

Frequently asked questions

What is secure AI for business?

Secure AI for business is AI where you know which data goes to the model, who sees which answers, what gets logged and who is allowed to use it. In ENABLE, the AI only receives metadata and the question, never data rows.

Is ENABLE a private AI platform?

That depends on your definition. ENABLE uses the OpenAI API and no model of its own, but it only sends metadata and the question to that API. Your data stays in your own data warehouse and queries run read-only.

Is the AI in ENABLE GDPR compliant?

GDPR compliance is not a property of a tool, but of how your organisation processes data. ENABLE helps by giving the AI only metadata and no data rows. Data processing agreements, lawful bases and any DPIA remain your own responsibility.

Where is ENABLE hosted?

The ENABLE portal runs on Vercel in the Frankfurt region (fra1). Where your data warehouse is located varies by customer. The AI model is OpenAI's, accessed via the API.

Can ENABLE work with an on-premise or European AI model?

No, not today. ENABLE uses the OpenAI API and only sends metadata and the question to it, never data rows.

Who can use AI in ENABLE?

The SQL Explorer with AI is available only to customer admins by default. For regular users it is only switched on if that has been configured for your organisation. The AI in the Dashboard Builder only works where that pilot module has been switched on.

Share securely, live fast, no headache

In an online demo we show you the portal: dashboards per role, row-level security, plain-language questions and how we set it up and manage it for you.