frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

We built a guardrail layer to keep LLMs from breaking production databases

3•tcodeking•2h ago
Over the last few months I’ve been building something we originally created for internal use, but eventually realized others were running into the same problem.

Once you let LLMs generate SQL against real databases, traditional safeguards (read-only users, RBAC, views) start to break down in subtle ways:

• LLMs can infer sensitive data via aggregates and joins

• “Read-only” doesn’t prevent data exfiltration

• Regex masking fails without context

• It’s hard to audit why a query was run once it happens

We ended up building a guardrail layer that sits between the LLM and the database. Every query goes through:

• role-aware column redaction

• organization-scoped isolation

• query validation and policy enforcement

• full audit logging and telemetry

It supports multiple databases and works with both self-hosted and managed setups. The hosted version just went live, but the core design was driven by real production failures we hit along the way.

I’d love feedback from folks who’ve dealt with LLMs touching production data — especially what broke for you, or what you’d want enforced differently.

Happy to answer technical questions.

https://guardraillayer.com/

The Bruising Reality of Searching for a Job at 65

https://www.wsj.com/lifestyle/careers/the-bruising-reality-of-searching-for-a-job-at-65-eed94709
1•pauljonas•15s ago•0 comments

Show HN: Write Notes on Images

https://notesonimages.web.app/
1•sailorganymede•18s ago•0 comments

Critical (CVSS 10) tagged CVE-2025-52691 affecting SmarterMail software

https://github.com/rxerium/CVE-2025-52691
1•runtimepanic•4m ago•1 comments

Rx Inspector – Look Up Where Your Generic Prescription Drugs Were Made

https://projects.propublica.org/rx-inspector/
1•zdw•5m ago•0 comments

The Truth about Affordability

https://www.economist.com/leaders/2025/12/30/the-truth-about-affordability
1•andsoitis•6m ago•0 comments

It's time to let AI handle financial charts in dialog

https://github.com/0xhappyboy/candleview/blob/main/assets/ai-dialog.gif
1•happyboy_•6m ago•0 comments

Show HN: SU_N an Adaptive Mesh Refinement Engine

https://github.com/colinstanfordjones/SU_N
1•RAMJAC•6m ago•0 comments

Learning from Our Mistakes: Epistemology for the Real World

https://global.oup.com/academic/product/learning-from-our-mistakes-9780197567654
1•egghack•7m ago•0 comments

Securing AI coding agents: What IDEsaster vulnerabilities should you know

https://tigran.tech/securing-ai-coding-agents-idesaster-vulnerabilities
1•tigranbs•9m ago•2 comments

Mitigation needed to avoid unprecedented multi-decade North Atlantic Oscillation

https://www.nature.com/articles/s41558-025-02277-2
1•bryanrasmussen•13m ago•1 comments

10 Most Popular Articles of the Year

https://www.honest-broker.com/p/the-10-most-popular-articles-of-the
1•paulpauper•14m ago•0 comments

Reverse Engineering Bluetooth on Amazon Kindle EReaders

https://sighery.com/posts/reverse-engineering-bluetooth-on-kindle-ereaders/
2•mattmar96•16m ago•2 comments

Frontier Models are Capable of In-context Scheming

https://arxiv.org/abs/2412.04984
1•william-evans•16m ago•1 comments

The Golden Rule of Driving

https://leroy.works/articles/the-golden-rule-of-driving/
1•leroy-is-here•16m ago•0 comments

Where Are the Beautiful Cities?

https://twitter.com/david_perell/status/2005730447897055414
3•lleims•18m ago•0 comments

Google Home Users Are Trying to Hack Their Way to a Better Voice Assistant

https://gizmodo.com/google-home-users-are-trying-to-hack-their-way-to-a-better-voice-assistant-20...
2•gnabgib•19m ago•1 comments

Cyberattack disrupts France's postal service and banking during Christmas rush

https://apnews.com/article/france-postal-service-cyberattack-4ea0c3e3bcb8a87341de8aebc1dfc916
3•gnabgib•22m ago•0 comments

Sprites: Persistent, suspendable, Linux environments as a Service

https://sprites.dev
1•nateb2022•25m ago•1 comments

The former Chinese police officer bringing bubble tea to wartorn Ukraine

https://www.theguardian.com/world/2025/dec/30/former-chinese-police-officer-bringing-bubble-tea-t...
1•mykowebhn•26m ago•0 comments

Enterprises Can Navigate Geolocation, Storage, and Privacy Compliance

https://guptadeepak.com/the-global-data-residency-crisis-how-enterprises-can-navigate-geolocation...
1•guptadeepak•28m ago•1 comments

India has surpassed Japan to become the fourth-largest economy

https://www.dw.com/en/india-overtakes-japan-as-4th-largest-economy-report-says/a-75341063
8•guptadeepak•30m ago•1 comments

ESPectre Sensor: open-source motion detection system for ESP32

https://espectre.dev/
3•882542F3884314B•31m ago•1 comments

Tatiana Schlossberg Has Died

https://www.nytimes.com/2025/12/30/us/politics/tatiana-schlossberg-dead.html
1•HR01•33m ago•0 comments

Painting with light in WebGL: terrain builder in the browser

https://medium.com/@bartoszu/painting-with-light-building-a-3d-island-in-the-browser-with-three-j...
2•bartoszu_•33m ago•0 comments

New brain implant restores lost senses using light

https://newatlas.com/medical-devices/neuro-key-implant-restore-lost-senses/
2•thunderbong•34m ago•0 comments

Show HN: Line Weaver – Image to G-Code Conversion for Pen Plotters

https://github.com/straczowski/line-weaver
1•rstraczowski•35m ago•0 comments

Junkyard Nissan V8 Lays Down Nearly 700 WHP with a Turbo and Little Else

https://www.thedrive.com/news/junkyard-nissan-v8-lays-down-nearly-700-whp-with-a-turbo-and-little...
1•PaulHoule•35m ago•0 comments

Prof. Software Developers Don't Vibe, They Control: AI Agent Coding Use in 2025

https://arxiv.org/abs/2512.14012
18•dpflan•36m ago•5 comments

Everything as Code: How We Manage Our Company in One Monorepo

https://www.kasava.dev/blog/everything-as-code-monorepo
34•benbeingbin•37m ago•11 comments

Show HN: Git-aware File tree viewer for Jupyter [video]

https://www.youtube.com/watch?v=zaK-EZd0GCY
1•loa_observer•38m ago•0 comments