Starting fresh? Begin with the Sidecar. It installs in one command, runs from a single config file, and needs no gateway, agent or database. The Gateway is where you go when you need the full platform. See Getting Started.
Gateway or Sidecar?
The two are converging: the Gateway becomes the Control Plane, and the two run in parallel through the transition.
The problems it solves
Organizations managing access to critical infrastructure run into the same five things:- Security risk from overly permissive access policies
- Productivity bottlenecks from complex approval workflows
- Compliance gaps from inadequate audit trails
- No clear answer to which identity accessed what, and when
- Sensitive data exposed during ordinary access sessions
AI Agent Enablement
AI Agent Enablement
Agents reach real data through the same gateway engineers use, with PII masked at the wire, destructive operations blocked, and every session recorded.
Improve Engineering Productivity
Improve Engineering Productivity
Provide secure, audited access to databases while masking sensitive data. Developers run queries without ever handling production credentials.
Data Masking in Production
Data Masking in Production
Make PII, PHI, PCI and credentials invisible in database responses, API payloads and terminal output, so production access does not expose sensitive data.
Compliance Evidence
Compliance Evidence
Meet regulatory requirements with session recordings, access logs and data protection features that document who accessed what and when.
Explore
Features
Live Data Masking, access requests, access control, ABAC, guardrails, runbooks, session recording, MCP server and more.
Quickstart
Connect a resource. Databases, cloud services, web applications, development environments, AI and LLMs.
Clients
The
hoop CLI, the hsh shell, and the web app.Setup & Administration
Architecture, deployment, configuration, identity providers, APIs and licensing.
Concepts
Agents and resource roles.
Integrations
Slack, Teams, Jira, SIEM, Svix, AWS and Microsoft Presidio.
Get the Gateway
Managed Service
No setup. Register and start connecting resources.
Create an account
Create an account
Self-Hosted
Deploy in your own infrastructure with Docker, Kubernetes or AWS.
Go to the deployment guide
Go to the deployment guide