
- Sensitive data is masked before Claude Code sees it. PII, credentials, and secrets in query results are redacted in real time. The model works with the schema and structure, not the raw values.
- Credentials are never handed to the model. Claude Code authenticates through hoop.dev’s SSO integration. Database credentials are retrieved just-in-time and never exposed to the model or its context window.
- Every query is logged at the command level. More granular than session-level access records, with hoop.dev every individual query is logged, with full context, in a structured and searchable audit trail.
- Guardrails can block or gate actions outside approved patterns. Queries or commands that fall outside policy can be blocked outright or routed through an approval workflow, without changing how Claude Code is invoked.
Before you start
To get the most out of this guide, you will need to:- Either create an account in our managed instance or deploy your own hoop.dev instance
- You must be your account administrator to perform the following commands
Features
The table below outlines the features available for this type of connection.- Native - Accessible via a native connection using hoop as proxy protocol to the resource.
- One Off - This term refers to accessing the resource from Hoop Web Console.
| Feature | Native | One Off | Description |
|---|---|---|---|
| TLS Termination Proxy | The local proxy terminates the connection with TLS, enabling the connection with the remote server to be TLS encrypted. | ||
| Audit | The gateway stores and audits the queries being issued by the client. | ||
| Data Masking (Google DLP) | A policy can be enabled to mask sensitive fields dynamically when performing queries in the database. | ||
| Data Masking (MS Presidio) | A policy can be enabled to mask sensitive fields dynamically when performing queries in the database. | ||
| Guardrails | An intelligent layer of protection with smart access controls and monitoring mechanisms. | ||
| Credentials Offload | The user authenticates via SSO instead of using database credentials. | ||
| Interactive Access | Interactive access is available when using an IDE or connecting via a terminal to perform analysis exploration. |