Secure and audit-ready,
by design
QueryWell is built for the people who have to answer to auditors and regulators. Your data stays on the device, secrets stay in the OS keychain, and every run and export leaves a tamper-evident trail.
No QueryWell reporting cloud
Studio results, history and exports remain on the device. QueryWell has no hosted reporting warehouse or cloud sync, and Elaman does not receive your query output.
Secrets in the OS keychain
Credentials live in OS-native secret storage — never in plaintext and never in the app's local database. Basic auth is clearly labelled dev/fallback and only allowed over HTTPS.
Reporting-only by default
Destructive operations are blocked, and QueryWell respects all Fusion roles, privileges and data security. It connects through Oracle's supported APIs only — no JDBC, SQL*Net, or backend SQL.
Your data stays in-country
There's no warehouse to breach and no cross-border copy to explain to a regulator. Bank of Ghana's CISD-2026 data-residency rule becomes a checkbox instead of a headache.
Masked audit logs
Every run and export is logged. Sensitive parameter names — token, key, IBAN, account and the like — are masked in the log automatically.
Tamper-evident exports
Every export is SHA-256 hashed and recorded in the export log — evidence you can hand straight to auditors and examiners.
Security & governance at a glance
- Reporting-only by default — destructive operations blocked
- Respects all Fusion roles, privileges and data security
- OS-native secret storage; no secrets in the local database
- Sensitive parameters (token, key, IBAN, account…) masked in logs
- Content Security Policy enforced in production builds
- No product telemetry or cloud sync; update checks send limited version, platform, licence and random-install identifiers
- Connects through Oracle's supported APIs only — no JDBC / SQL*Net / backend SQL
- Cryptographically signed updates; signed & notarised macOS build and verified-publisher Windows installer
Where your data lives
QueryWell stores connection metadata, history, audit logs and saved queries in local SQLite on your device. Query results and report output are yours alone — they're never copied to a vendor cloud or warehouse.
Not a bulk extractor. For very large one-off outbound extracts, QueryWell points you to Oracle's supported BICC / scheduled channels — keeping you within Oracle's guidance rather than pulling mass data through an interactive tool.
Data Loader — governed by design
When you mirror Fusion tables, the copy lands in your Oracle Autonomous Database — not ours. Every load is subject to a governance registry stored in your own BI Catalog, and written to an audit ledger you can export.
Data Loader governance controls
- Open or restricted modes — allow all targets, or only approved ones
- Per-table row caps and deny lists
- Single-copy-per-table enforcement to prevent stray duplicates
- A pod-stored audit ledger of every write, with per-user folders
- Local CSV export of the ledger for offline audit
- LOB/RAW/XMLTYPE columns excluded with explicit warnings
Reporting your auditors will trust
Own it outright, keep your data in-country, and hand over tamper-evident evidence on demand.