PLATFORM
Detect, explain, decide, act, govern
What xFalcon ships today, chapter by chapter - from a read-only connection to your warehouse to an append-only audit log.
DETECT
Go looking, on your own data
You launch the investigation. xFalcon plans it, tests its own hypotheses, and checks its work before it reports back.
AutoExplore
A deep investigation you launch - it presents the plan and waits for your go-ahead. Then 20-30 iterations of hypothesis and test, with two confirming queries from different angles before anything counts as a finding, and a disproven hypothesis reported as a finding in its own right. A fact-check pass runs over its own report before you see it.
Ask in plain English
Questions answered straight from your warehouse, read-only. xFalcon estimates the row count first, so a 500-row cap never quietly becomes a wrong total.
Works on your warehouse
Read-only connections to the databases you already run - no migration, no data movement.
- Snowflake
- Databricks
- Postgres
- SQL Server
Governed catalog
xFalcon sees only the tables your data stewards register - read-only, row-limited, and authorized per tool before every call.
File-upload analytics
NewUpload CSV and Excel files - gigabyte scale - and query them in plain English. Each upload catalog is private to the person who loaded it.
EXPLAIN
Every number traces back
Open any answer and the query, the tables, and the guardrails that applied are all still attached to it.
Data models built from evidence
The join graph comes from five sources - declared foreign keys, your own query history, schema-pack matching, SQL scanning, column heuristics - and every edge carries a confidence score. Only declared keys are auto-confirmed; the rest stay suggestions until a human accepts them.
Every answer has a query ID
That ID resolves to the exact SQL, the tables and columns it touched, and the question that produced it. Feedback on the answer lands on the same record.
Checked before and after it runs
Before a query runs, xFalcon assembles the annotations and past corrections that apply to those tables - and when a critical annotation overrides a conflicting memory, the override is reported rather than hidden. After it runs, it flags truncation, empty results, and aggregates computed over partial data.
DECIDE
Work you can put in front of the board
Dashboards, briefings, decks and workbooks - generated when you ask for them, from live warehouse numbers.
One-prompt dashboards
A branded, governed portal from a single prompt - live the same afternoon, not after a 12-week BI backlog.
xFalcon News
A briefing built from your data, not a template - ranked priorities with every claim tied to a live warehouse number. Ask for it and it is assembled on the spot.
Saved reports that re-run live
NewSave a dashboard as a report. Re-opening it re-runs the query against live data and re-renders the captured format - deterministically, with no model call.
QBR decks
Board-ready QBR decks with the narrative already written. Minutes, not weeks.
Excel Edition
Board-ready workbooks from one request, built from the same governed queries as the dashboard they came from.
ACT
Your connected tools are the action surface
xFalcon governs the call; the systems you connect carry it out. It never writes to your warehouse.
Your agents call xFalcon
xFalcon hosts an MCP server: 15 governed tools over your data, OAuth 2.1 with RFC 9728 and RFC 8414 discovery rather than a bespoke handshake. Point Claude Desktop, Claude.ai Connectors or any MCP client at your tenant - or use a scoped, revocable API key.
xFalcon calls your MCP servers
Connect any third-party MCP server over HTTP, SSE or stdio with API-key, bearer or OAuth auth - tokens encrypted at rest. The tools you connect take the action; xFalcon governs whether the call runs.
Read-only by construction
INSERT, UPDATE, DELETE, DROP and ten other write patterns are rejected before a query reaches your database - on Postgres, Snowflake, Databricks, SQL Server and DuckDB alike.
xFalcon Chat
NewA ready-to-use chat app for teams that don't run an MCP client of their own - same governed answers, same approval gate before a tool runs.
GOVERN
The control plane, not just the answer
Ask-by-default approvals, policy that runs before the tool does, and a record of every decision either of them made.
Approvals default to ask
Every tool call can require a human decision first: xFalcon pauses the run, records who approved it and when, and does not resume without it. A standing approval is bound to the exact arguments it was granted for.
Policy as code, before execution
Write a pre-execution hook that inspects, rewrites or blocks a tool call before it runs - then read back every decision it made: passed, modified, denied or errored.
An append-only audit log
Invocations, approvals and denials land in an append-only log your admins can read. xFalcon exposes no way to edit or delete an entry once it is written. Both the allow and the deny are recorded.
Every correction is versioned
Edit a definition and xFalcon ends the old version and opens a new one, with the original wording preserved for the life of the chain. Ask what a metric meant last quarter - point-in-time reconstruction is a query parameter.
Personal until an admin promotes it
A correction stays with the person who made it until an admin promotes it org-wide, with a before/after diff and a conflict check on the way through. Corrections drafted from negative feedback arrive inactive, and only an admin can author an annotation - agents read them and suggest.
Cost and latency on the record
Cost, tokens, latency, model and provider are recorded for every answer, with cost computed by the database rather than estimated by the app. Set token budgets per tenant or per user and query usage over a rolling window.
Admin console and SSO
One console for memories, annotations, data sources and users. OIDC single sign-on with Okta, Azure AD and more, with permissions granted per tool.
Production-grade cloud
Multi-AZ on AWS with cross-region backup, per-class encryption keys, zero-downtime deploys, and authorization enforced in the database by row-level security. SOC 2 Type II controls are implemented and generating evidence; no report has been issued and we are not attested today.
On-premise and air-gapped
NewA signed installer runs the full platform inside your network - fully offline if you need it.
Get started
See it answer your own questions
A 2-4 week proof of concept on one subject area, with a working use case and ROI report. The fee is credited if you move ahead.