Wren AI security

One governed path for your people and your AI agents.

Identity, context-layer policy, row and column controls, and audit logs sit in front of every query. Same path for people, apps, and MCP agents.

Policy point
Context layer
Every caller
UI, API, MCP
Deployment
Cloud to air-gap
Live policy gate
Request path
CALLERSONE PATHWren UIchatSlackchannelAPIembedMCPClaudeWREN CONTROL PLANEENFORCEDIDENTITYOIDC, workspace rolesCONTEXT LAYERMDL metrics, approved joinsROW AND COLUMNRLS and CLS at query timeSQL GUARDValidated, bound, inspectableNO SIDE DOORYour dataqueried in place
Identity-aware
RLS and CLS
Audited

Mechanisms

Security claims you can trace through the product.

Security architecture

The control plane runs before the query.

Every prompt resolves through identity, context-layer definitions, row and column rules, and SQL validation before a result reaches anyone.

  • OIDC + workspace roles
  • MDL context layer
  • RLS + CLS at query time
  • SQL + answer lineage logged

Agent governance

Agents get the same door as everyone else.

When Claude or Cursor calls Wren as a sub-agent over MCP, it resolves through the same path as Slack, Teams, embedded apps, and API callers: one governed MCP and API boundary. There is no side door to the warehouse.

  • One MCP + API boundary
  • Skills and memory grounded in the context layer
  • Project access inherited per request
  • Generated SQL stays inspectable

Data residency

Run it inside the boundary you trust.

Managed cloud, private cloud, self-hosted, or fully air-gapped. Wren AI connects to data where it already lives; nothing migrates into a new silo.

  • 20+ sources, queried in place
  • GCP us-east-4 by default, other regions on request
  • Bring your own LLM
  • Project isolation per tenant
  • Audit logs: who asked what

Control surface

Built for the review your data team actually runs.

Identity and access

OIDC login, workspace and project roles.

OIDCRolesProjects

Row and column controls

Filtered in the query path, before results reach anyone.

RLSCLSQuery-time

Context-layer guardrails

Approved metrics and joins, defined once in MDL.

MDLMetricsJoins

Auditability

Who asked what, and which SQL ran.

Activity logSQLLineage

Deployment control

Cloud, private cloud, self-hosted, or air-gapped.

CloudVPCAir-gap

Agent-safe APIs

One governed context for UI, API, and MCP clients.

MCPAPIEmbedded

Security walkthrough

Bring your data agent to security review.

Walk your security, platform, and data teams through the governed execution path.