$fastcrud
~ SQL Server / Oracle / PostgreSQL / MySQL / MongoDB

Audit-ready APIs for the SQL_Server_ databases enterprises actually run on.

FastCRUD puts a modern, audited REST and GraphQL API on top of the SQL Server, Oracle, PostgreSQL, and MySQL databases your business already runs on — without rebuilding the database, replacing the team, or ripping out the auth your auditors already approved.

Built for engineering teams at fintech, healthcare, insurance, logistics, and any company that lives on legacy SQL and has to answer to compliance. Every call is logged, every key is scoped, every credential is KMS-encrypted.

#who this is for

FastCRUD is narrow on purpose. It is the data-API layer for companies that have a database they can't replace and an auditor they can't ignore.

You're a fintech, healthcare, insurance, logistics, or manufacturing team. Your business runs on SQL Server, Oracle, or a long-lived PostgreSQL with twenty years of stored procedures, denormalized tables, composite keys, and rules nobody wants to re-derive. A green- field tool wants you to migrate to its database. You can't, and you shouldn't have to.

FastCRUD connects to the database you already have, introspects the schema, and gives you a documented REST and GraphQL API in about a minute — with audit logging, row-level access policies, IP allowlists, and KMS-encrypted credentials wired in by default, not as a Pro-tier upsell.

you'd buy this if

You're putting an external-facing API on top of an internal SQL Server or Oracle database, and Legal wants receipts for every read and write before you ship.

you wouldn't buy this if

You're building a side project on a fresh Postgres instance with no compliance requirements. A free Postgres-first generator will probably make you happier.

what your team gets

A managed REST + GraphQL endpoint, an admin dashboard with audit views, exportable access reports, per-key scopes, encryption, and an SLA on Business and above.

how it's delivered

SaaS on EU or US infrastructure (Business), or BYO-VPC / on-prem with a BAA and DPA on the table (Enterprise). No download, no install, nothing to host yourself.

#what it does

The pieces a generic auto-API tool ships in five minutes are fine. The pieces it punts on — the ones that get a project killed in security review — are why FastCRUD exists.

01

SQL Server & Oracle, treated as first-class

Most auto-API tools are Postgres-first and ship MSSQL/Oracle as an afterthought. FastCRUD is built around the databases that actually run inside banks, hospitals, insurers, and 20-year-old enterprises — and runs PostgreSQL, MySQL, and MongoDB just as well.

02

Audit log on every call

Every request is recorded with the access key, source IP, table, operation, and response code. Exportable for SOC 2 evidence collection, internal audits, and incident response — no extra service to bolt on.

03

Per-key row-level access policies

Restrict an access key to specific tables, columns, or row filters (e.g. tenant_id = X). Multi-tenant isolation without rewriting your schema or your auth system.

04

Stored procedures, exposed safely

Legacy databases live in stored procedures. FastCRUD lets you publish a procedure as a typed REST or GraphQL endpoint, with parameter validation and the same audit trail as everything else.

05

Encrypted credentials, IP allowlists, KMS-backed

Connection strings are encrypted with AES-GCM via AWS KMS and stored in AWS Secrets Manager. Per-project IP allowlists block traffic from anywhere it shouldn't be. Credentials never appear in logs.

06

No backend code, no schema files

Point FastCRUD at your existing database. The schema is introspected, validated, and cached. You get a working, documented REST and GraphQL API in about a minute — without rebuilding the database your business already depends on.

#compliance, not a checkbox

The audit log is the product. Every customer plan ships with full request-level logging — what was queried, by whom, from where, when, and with what outcome — surfaced in the dashboard and exportable for evidence.

audit log

Every read, write, and procedure call is recorded with actor, IP, query, latency, and outcome. Exportable for SOC 2, ISO 27001, and HIPAA evidence collection.

access control

Per-key scopes, table/column allowlists, row-level filters, and IP restrictions. Revoke a key in one click — every downstream caller is cut off immediately.

encryption

Database credentials encrypted with AES-GCM via AWS KMS. Secrets live in AWS Secrets Manager. Credentials never appear in application logs.

data residency

France today. Additional regions (other EU, US, APAC) provisioned per Enterprise customer request — we do not pre-spin infrastructure we don't have a customer for.

Controls aligned with SOC 2 Type II and HIPAA expectations. SOC 2 attestation in progress. BAA and DPA available on Business and Enterprise plans.

#the hard 20%

Generic auto-API tools handle the easy 80% — single-table CRUD on a clean Postgres schema. These are the cases they punt on, and the ones FastCRUD is built around.

stored procedures

Expose existing procedures as typed endpoints with parameter validation. The legacy logic stays inside the database, where the DBAs want it.

ugly schemas

Composite keys, denormalized tables, mixed-case column names, decade-old conventions — handled. No requirement to refactor your schema before shipping.

multi-tenant isolation

Bind an access key to a tenant filter. Even if a key leaks, it can only see one tenant's rows. No new tables, no rewrite.

computed fields

Expose derived columns and view-backed reads as first-class API resources, without committing them back into the production schema.

#first secure endpoint in under a minute

Connect a database, get a working, audited API. Four steps, one dashboard, no config file, no schema migration.

01

Connect a database

Add a connection in the dashboard — SQL Server, Oracle, PostgreSQL, MySQL, or MongoDB. Credentials are encrypted with KMS the moment they hit our infrastructure.

# dashboard → new connection

type   SQL Server
host   erp-prod.corp.internal
port   1433
db     FinanceLedger
role   fc_readonly
02

Schema is introspected

FastCRUD walks the schema, catalogs tables, columns, and types, and caches the result. Nothing in your database changes.

# schema introspected

✓ 412 tables catalogued
✓ 38 stored procedures discovered
✓ REST + GraphQL endpoints ready
03

Issue scoped access keys

Generate access keys with row-level filters, IP allowlists, and table/column scopes. Every key's activity is independently audited.

# dashboard → new access key

scope        read invoices, orders
row filter   tenant_id.eq.acme
ip allowlist 10.0.0.0/8
key          key_01JABC...
04

Ship secure APIs

Hit /crud over REST or POST /graphql. Filter, paginate, join, insert, update, and call stored procedures — with the audit trail your security team is going to ask for anyway.

GET /crud/invoices?filter=status.eq.unpaid&limit=20
Authorization: Bearer eyJhbGci...

→ logged: actor, IP, query, ms
[{ "id": 7741, "tenant_id": "acme", "total": "199.00" }, ...]

#two APIs, one connection

REST and GraphQL from the same project. Tenant filters and row-level policies enforced server-side on both.

REST API
HTTP
# Read with filter, scoped to a tenant
GET /crud/invoices?filter=status.eq.unpaid%20AND%20tenant_id.eq.acme&limit=20
Authorization: Bearer <token>

# Call a stored procedure
POST /rpc/sp_close_month
Content-Type: application/json

{ "period": "2026-04", "actor_id": "u_193" }

# Insert with audit metadata captured automatically
POST /crud/orders
{ "user_id": "42", "total": "99.99", "status": "pending" }

# Update with a filter — every change is logged
PUT /crud/orders?filter=id.eq.7
{ "status": "shipped" }
GraphQL
POST /graphql
# Joined read across legacy tables
{
  join(
    from: "orders"
    joins: [{ table: "users", on: "orders.user_id.eq.users.id" }]
    columns: ["orders.id", "orders.total", "users.name"]
    filter: "orders.total.gt.50 AND orders.tenant_id.eq.acme"
  )
}

# Mutation with row-level policy enforced server-side
mutation {
  insertOrders(rows: [{ user_id: "42", total: "99.99" }]) {
    rowsInserted
  }
}

#pricing

Annual contracts available on Business and Enterprise. Pay monthly via Stripe on Free Trial and Team. Upgrade, downgrade, or cancel anytime from the billing dashboard — access continues until the end of the paid period.

Every plan includes the full audit log, REST + GraphQL, KMS-encrypted credentials, and IP allowlists. Higher tiers add SSO, data residency, row-level policies, and an SLA.

free trial

$014 days
  • 1 database connection
  • 100k requests / month
  • REST + GraphQL
  • Audit log preview
  • Community support
start trial

team

$299/ month
  • 5 database connections
  • 5M requests / month
  • Full audit log + export
  • IP allowlists + scoped keys
  • REST + GraphQL + joins
  • Email support, 1 business day
start with team

business

$999/ month
  • 25 database connections
  • 50M requests / month
  • SSO — SAML / OIDC
  • Data residency (France today, more on request)
  • Row-level access policies
  • Configurable log retention
  • SLA + priority support
contact us

enterprise

Contact
  • Unlimited connections + requests
  • BYO-VPC or on-prem
  • Dedicated infrastructure
  • BAA / DPA / custom MSA
  • Custom SLA + named CSM
  • Procurement-friendly billing
talk to sales →

Self-serve checkout via Stripe on Free Trial and Team. Business and Enterprise billed via invoice. All prices USD.

Annual contracts available. Cancel anytime.

$ ship an audit-ready API this week.

Twenty-minute call. We'll demo against your schema or a representative one, walk through the audit log and access model, and give you a deployment plan tailored to your compliance posture.