Ship AI Agents Your Customers Can Trust.
The governed infrastructure layer for building and deploying agents — connectors, permissions, audit trails, and cost controls built in — for your product, or your own stack.
Free to start, no credit card · for enterprise & air-gapped
Reaches on-prem & air-gapped systems
Behind your firewall, outbound only
Scoped, revocable access
Signed tokens, rotate anytime
Free to act, never to overreach
Scoped to the sources and actions you allow
Usage you can see
Cost per user, before it surprises you
A few lines to ship
Sign a scoped token for each of your users — source allowlists, rate limits, read-only by default — then drop in the widget or call the SDK. The governance rides in the token, so there's no glue code to maintain.
// Server-side: sign a scoped token for this userconst token = cb.widgetToken(user.id, { sources: ["orders", "invoices"], limits: { daily: 50 },}); // Client-side: drop the governed widget into your appimport "@corebasehq/widget"; CorebaseWidget.init({ publicId: "proj_•••", getAuthToken: () => token,});Give your agents the data they run on
Every agent you ship reads straight from your real systems — databases, REST & GraphQL APIs, and 50+ apps. No ETL, no glue code, no integration sprint.
See all integrationsCloud & SaaS
Connect in one clickPaste a connection string or sign in — PostgreSQL, MySQL, REST & GraphQL APIs, Slack and Microsoft 365 connect directly, live and read-only.
On-prem & legacy
When a customer needs itWhen a customer's data lives behind the firewall, reach it too: the open-source CoreMCP agent runs inside their network to serve SQL Server 2000+, Firebird, and on-prem ERP / POS. It connects outward from the inside — nothing to open up, no VPN. Even works fully offline.
Everything you need to ship on real data
Guardrails, attack screening, per-user isolation — the governance you'd otherwise build yourself, already here. Batteries included, self-host optional.
Agents that stay on the rails
Draw the steps your assistant works through — what data each step can touch, what it may do, when it must ask for approval. It reasons freely inside; the rails are enforced, not suggested.
Every visitor connects their own
Gmail, Jira, or any of 50+ apps — each visitor links their own account, and the assistant acts on it alone. Isolation is the OAuth grant itself, not a filter that could slip.
Bring your own model
Use the built-in AI, or plug in your own keys — Claude, GPT, Gemini and more. Switch anytime.
Private by design
Read-only by default, isolated per customer, encrypted in transit and at rest — and every action is logged.
Screened at the door
Every message is checked for prompt injection, jailbreaks and abuse before it reaches the model — on chat, widget, voice and API alike.
It learns your schema
Query Memory remembers the queries that worked and what your tables mean — so natural-language → SQL gets sharper the more you run it.
Ask across every system — answers from live data
One query can hit your database, your CRM, and your inbox at once — read straight from the source, never a stale copy.
One question, every source
CoreBase fans your question out across the systems you have connected and assembles a single answer — with every step logged.
Real numbers, straight from the source
Answers come back as figures and tables computed from live data — not summaries of a stale copy.
Always current
Every answer is computed at ask time, straight from the live system.
Only their own rows
Each question runs as the person asking it, so one customer can never be answered with another’s data.
Asks before it changes
Nothing is written until someone says so — the customer for their own data, your team for anything you gated.
Full audit trail
Every question, query, and action is recorded — nothing happens off the record.
Room to think, rails that hold
Draw the steps your agent works through — the data each step can reach, the actions it may take, when it must ask first. It reasons freely inside; the rails are enforced in code, never just suggested in a prompt. Watch one hold:
Enforced, not suggested
A blocked action is never called; a required approval is never skipped. Your rules compile to real gates — not a line in a prompt the model can talk itself out of.
Scoped, step by step
Each step grants only the data and actions it needs. The agent physically can’t reach a source you didn’t hand it there — even if it tries.
Approval gates & full audit
Hold an action for a human OK before it runs — and every query, step, and block it hits lands in the audit trail.
Open source
CoreMCP — the open-source bridge.
The agent that reaches behind the firewall is open source. Audit it, run it yourself, or keep it fully offline. The managed platform is built on the same code your team can read line by line.
Start free. Scale when you're ready.
Every plan includes AI usage on built-in models — no key required to start. Bring your own LLM key any time and pay your provider directly instead.
Save 25% on annual billing
Free
Build against one source, free.
Free forever
- 1 data source
- $1 one-time model credit — built-in models, no key needed
- BYOK LLM keys (optional, your provider)
- Developer API + embeddable widget
- Query Memory + Unified Context (RAG)
- Per-tenant isolation at the database — every plan
- Read-only by default
- Community support
When the $1 runs out we pause model calls before any charge — top up a prepaid balance or add your own LLM key. Everything else here stays free.
GrowthMost popular
For developers wiring agents to real systems.
billed monthly
- Everything in Free, plus:
- 5 data sources · 3 projects
- $5/mo included AI usage
- REST / GraphQL + cloud DB connectors
- On-prem database access via CoreMCP
- Guardrails — enforced conversation rails
- Email support
Team
For teams that need governance and scale.
billed monthly
- Everything in Growth, plus:
- Unlimited data sources & projects
- $15/mo included AI usage
- RBAC + full audit log
- Usage & cost analytics per member
- Priority support
Enterprise
Air-gapped or regulated environments, dedicated infrastructure, and SSO.
- Air-gapped / on-prem container
- Dedicated infrastructure
- SSO / SAML
- SLA + dedicated support
Need the full breakdown across every plan?
Compare all plansFAQ
Frequently asked questions
Reach, safety, isolation, and deployment — what security and data teams ask before connecting an agent to live systems.
Can't find what you're looking for? Contact our support team
Ship your first agent today.
Connect a source, wire up an agent, and stream your first answer in minutes. Free to start — no credit card.
Need air-gapped or enterprise?