Security

The security model, in plain words

bzora is a tool you point at production. Here is exactly what it does to keep that safe, what it never does, and where its limits are.

What never happens

Secrets

Database passwords, SSH passwords, key passphrases and AI API keys are stored in the operating system's keychain: macOS Keychain, Windows Credential Manager or the Linux secret service. The connections file on disk contains none. A password found in a pasted URL is moved to the keychain before anything is saved, and error messages from a failed connection are scrubbed of the secret.

The network

Edits and structure changes

The review covers grid edits and structure changes. SQL you type in the editor runs when you run it.

Read-only

Mark a connection read-only and bzora opens it so the database refuses writes.

EngineHow read-only is enforced
PostgreSQLThe session starts with default_transaction_read_only on, and the simple query protocol (which can chain statements) is never used.
MySQL and MariaDBThe session is read-only, and multi-statement mode is off.
SQLiteThe file is opened read-only. ATTACH and VACUUM are refused, since they can write other files.
SQL ServerSQL Server has no read-only session, so bzora itself blocks writes. This guards against mistakes, not against a determined user.

The window also hides every editing, import, restore and structure control on a read-only connection.

The honest limit. A read-only connection protects you from mistakes. It is not a permission system. A user who can run SET default_transaction_read_only = off on PostgreSQL can undo it. The guarantee is a database user that has only read rights. bzora makes the safe setup easy. It does not replace it.

AI and MCP

The assistant writes SQL and never runs it. It is off until you configure it. What it sends: your question, the dialect, the current database name, and the names, types and keys of your tables. It never sends rows. A local model means nothing leaves your machine. API keys stay in the keychain. More on the assistant.

MCP. bzora --mcp lets Claude Desktop, Cursor or another MCP client query a connection you have chosen.

The limit. The database user bzora connects with still has its own rights. A privileged user can read more than you might expect, even in a read-only session. Give MCP a read-only database user.

What leaves your computer

WhatWhenWhere to
License checkOn activation, and in the backgroundLemon Squeezy
Update checkAt startdl.bzora.io (a small version file)
Database trafficOnly to the databases you configureYour own servers
AI requestsOnly if you enable the assistantYour local model, or the provider you chose. Names only.

That is all. No crash reports, no usage statistics.

What is kept on disk

Stored in your user config folder, readable only by you:

Query text and history are plain files. Anyone who can read your user folder can read them. If that matters, use full-disk encryption.

Reporting a problem

Send security reports to [email protected]. We read every one.