AES-256-GCM encryption at rest
LiveEvery API key and database credential is encrypted before it touches disk. The encryption key lives in env, never in the database. Key rotation runbook documented for compliance reviews.
Every Excel uploaded. Every AI prompt. Every dashboard. Every cost. In one place. Encrypted, auditable, governed by you. The full picture of what governance + observability look like in zenital selfBI today.
Every Excel upload, every AI call, every dashboard. Filter by team, user, period. Spot the columns your warehouse should have, straight from how people actually work. Live in /admin today.
cancellation_reason not in any modelchurn_status not in any modelnps_response not in any modelEvery Excel uploaded is logged with its columns, who uploaded it, and which topics it covers. When three teams upload files with a column called `customer_health_score`, you know what to add to the warehouse next sprint. Live in /admin/files today.
23 files · 3 with columns not in your warehouse
| File | Uploaded by | Size | Topics | Signal |
|---|---|---|---|---|
Q2_sales_export.csv | maria.gomez | 12 cols · 8.4k rows | — | |
churn_score_weekly.xlsx | david.ruiz | 7 cols · 2.1k rows | +2 new cols | |
NPS_responses_apr.csv | lucia.fdz | 9 cols · 1.3k rows | +1 new col | |
invoices_jan_apr.csv | lucia.fdz | 18 cols · 14k rows | — | |
team_workload.csv | pablo.lara | 5 cols · 340 rows | — |
Test, introspect, and connect any production database in under a minute. Cryptic columns get AI-suggested aliases automatically. Credentials are AES-256-GCM encrypted before they touch disk.
IT connects a data source once at the organization level. Then a visibility matrix says which workspaces (Finance, Sales, Operations…) can use it. The Cube query layer enforces the matrix server-side, no one can query a source they aren't enabled for, even by guessing the cube name.
| Data source | Type | Tables | Finance | Sales | Operations | Marketing | Customer Support |
|---|---|---|---|---|---|---|---|
CRM (production) | PostgreSQL | 47 | |||||
ERP, billing | MSSQL | 28 | |||||
Warehouse, sales | BigQuery | 14 | |||||
Field operations | PostgreSQL | 22 | |||||
Analytics, Redshift | Redshift | 18 |
Every API key and database credential is encrypted before it touches disk. The encryption key lives in env, never in the database. Key rotation runbook documented for compliance reviews.
Cube enforces workspace_id filtering on every query through queryRewrite. A user from workspace A literally cannot query data from workspace B, even if they know the cube name.
Org admin picks: full telemetry (default, log every prompt, file, dashboard) or metadata-only (cost and usage stay, prompt content stripped). Every employee knows what is logged.
A unified events table captures every AI call, file upload, dashboard action, and admin change. Queryable from /admin. Five indexes for sub-second range queries.
Choose one company-wide key, per-workspace keys, or each user brings their own. Matches how the company actually buys AI. UI surfaces only the relevant config based on org mode.
On roadmap for the first regulated enterprise client. Until then: encryption + RLS + audit log cover the substance of what SOC 2 asks for, just not the audit certificate itself.
No raw SQL ever touches the LLM. Every chart goes through a validated semantic layer that prevents hallucinations.
The other half of zenital selfBI is the wizard managers use every day. Charts in plain English, no SQL, no IT ticket. Same data layer. Same governance you control.
or write to the contact form