FastCRUD puts a modern, audited REST and GraphQL API on top of the SQL Server, Oracle, PostgreSQL, and MySQL databases your business already runs on — without rebuilding the database, replacing the team, or ripping out the auth your auditors already approved.
Built for engineering teams at fintech, healthcare, insurance, logistics, and any company that lives on legacy SQL and has to answer to compliance. Every call is logged, every key is scoped, every credential is KMS-encrypted.
# connect existing SQL Server
host erp-prod.corp.internal:1433
db FinanceLedger
✓ 412 tables, 38 procs cataloged
# scoped access key for a partner
scope read invoices, orders
row filter tenant_id.eq.acme
ip allowlist 10.0.0.0/8
# query — logged with actor + IP
GET /crud/invoices?filter=status.eq.unpaid
→ 200 37 rows 41ms audit_id=ax_91…
# export evidence on demand
GET /audit/export?from=2026-04-01&to=2026-04-30FastCRUD is narrow on purpose. It is the data-API layer for companies that have a database they can't replace and an auditor they can't ignore.
You're a fintech, healthcare, insurance, logistics, or manufacturing team. Your business runs on SQL Server, Oracle, or a long-lived PostgreSQL with twenty years of stored procedures, denormalized tables, composite keys, and rules nobody wants to re-derive. A green- field tool wants you to migrate to its database. You can't, and you shouldn't have to.
FastCRUD connects to the database you already have, introspects the schema, and gives you a documented REST and GraphQL API in about a minute — with audit logging, row-level access policies, IP allowlists, and KMS-encrypted credentials wired in by default, not as a Pro-tier upsell.
you'd buy this if
You're putting an external-facing API on top of an internal SQL Server or Oracle database, and Legal wants receipts for every read and write before you ship.
you wouldn't buy this if
You're building a side project on a fresh Postgres instance with no compliance requirements. A free Postgres-first generator will probably make you happier.
what your team gets
A managed REST + GraphQL endpoint, an admin dashboard with audit views, exportable access reports, per-key scopes, encryption, and an SLA on Business and above.
how it's delivered
SaaS on EU or US infrastructure (Business), or BYO-VPC / on-prem with a BAA and DPA on the table (Enterprise). No download, no install, nothing to host yourself.
The pieces a generic auto-API tool ships in five minutes are fine. The pieces it punts on — the ones that get a project killed in security review — are why FastCRUD exists.
Most auto-API tools are Postgres-first and ship MSSQL/Oracle as an afterthought. FastCRUD is built around the databases that actually run inside banks, hospitals, insurers, and 20-year-old enterprises — and runs PostgreSQL, MySQL, and MongoDB just as well.
Every request is recorded with the access key, source IP, table, operation, and response code. Exportable for SOC 2 evidence collection, internal audits, and incident response — no extra service to bolt on.
Restrict an access key to specific tables, columns, or row filters (e.g. tenant_id = X). Multi-tenant isolation without rewriting your schema or your auth system.
Legacy databases live in stored procedures. FastCRUD lets you publish a procedure as a typed REST or GraphQL endpoint, with parameter validation and the same audit trail as everything else.
Connection strings are encrypted with AES-GCM via AWS KMS and stored in AWS Secrets Manager. Per-project IP allowlists block traffic from anywhere it shouldn't be. Credentials never appear in logs.
Point FastCRUD at your existing database. The schema is introspected, validated, and cached. You get a working, documented REST and GraphQL API in about a minute — without rebuilding the database your business already depends on.
The audit log is the product. Every customer plan ships with full request-level logging — what was queried, by whom, from where, when, and with what outcome — surfaced in the dashboard and exportable for evidence.
audit log
Every read, write, and procedure call is recorded with actor, IP, query, latency, and outcome. Exportable for SOC 2, ISO 27001, and HIPAA evidence collection.
access control
Per-key scopes, table/column allowlists, row-level filters, and IP restrictions. Revoke a key in one click — every downstream caller is cut off immediately.
encryption
Database credentials encrypted with AES-GCM via AWS KMS. Secrets live in AWS Secrets Manager. Credentials never appear in application logs.
data residency
France today. Additional regions (other EU, US, APAC) provisioned per Enterprise customer request — we do not pre-spin infrastructure we don't have a customer for.
Controls aligned with SOC 2 Type II and HIPAA expectations. SOC 2 attestation in progress. BAA and DPA available on Business and Enterprise plans.
Generic auto-API tools handle the easy 80% — single-table CRUD on a clean Postgres schema. These are the cases they punt on, and the ones FastCRUD is built around.
stored procedures
Expose existing procedures as typed endpoints with parameter validation. The legacy logic stays inside the database, where the DBAs want it.
ugly schemas
Composite keys, denormalized tables, mixed-case column names, decade-old conventions — handled. No requirement to refactor your schema before shipping.
multi-tenant isolation
Bind an access key to a tenant filter. Even if a key leaks, it can only see one tenant's rows. No new tables, no rewrite.
computed fields
Expose derived columns and view-backed reads as first-class API resources, without committing them back into the production schema.
Connect a database, get a working, audited API. Four steps, one dashboard, no config file, no schema migration.
Add a connection in the dashboard — SQL Server, Oracle, PostgreSQL, MySQL, or MongoDB. Credentials are encrypted with KMS the moment they hit our infrastructure.
# dashboard → new connection
type SQL Server
host erp-prod.corp.internal
port 1433
db FinanceLedger
role fc_readonlyFastCRUD walks the schema, catalogs tables, columns, and types, and caches the result. Nothing in your database changes.
# schema introspected
✓ 412 tables catalogued
✓ 38 stored procedures discovered
✓ REST + GraphQL endpoints readyGenerate access keys with row-level filters, IP allowlists, and table/column scopes. Every key's activity is independently audited.
# dashboard → new access key
scope read invoices, orders
row filter tenant_id.eq.acme
ip allowlist 10.0.0.0/8
key key_01JABC...Hit /crud over REST or POST /graphql. Filter, paginate, join, insert, update, and call stored procedures — with the audit trail your security team is going to ask for anyway.
GET /crud/invoices?filter=status.eq.unpaid&limit=20
Authorization: Bearer eyJhbGci...
→ logged: actor, IP, query, ms
[{ "id": 7741, "tenant_id": "acme", "total": "199.00" }, ...]REST and GraphQL from the same project. Tenant filters and row-level policies enforced server-side on both.
# Read with filter, scoped to a tenant
GET /crud/invoices?filter=status.eq.unpaid%20AND%20tenant_id.eq.acme&limit=20
Authorization: Bearer <token>
# Call a stored procedure
POST /rpc/sp_close_month
Content-Type: application/json
{ "period": "2026-04", "actor_id": "u_193" }
# Insert with audit metadata captured automatically
POST /crud/orders
{ "user_id": "42", "total": "99.99", "status": "pending" }
# Update with a filter — every change is logged
PUT /crud/orders?filter=id.eq.7
{ "status": "shipped" }# Joined read across legacy tables
{
join(
from: "orders"
joins: [{ table: "users", on: "orders.user_id.eq.users.id" }]
columns: ["orders.id", "orders.total", "users.name"]
filter: "orders.total.gt.50 AND orders.tenant_id.eq.acme"
)
}
# Mutation with row-level policy enforced server-side
mutation {
insertOrders(rows: [{ user_id: "42", total: "99.99" }]) {
rowsInserted
}
}Annual contracts available on Business and Enterprise. Pay monthly via Stripe on Free Trial and Team. Upgrade, downgrade, or cancel anytime from the billing dashboard — access continues until the end of the paid period.
Every plan includes the full audit log, REST + GraphQL, KMS-encrypted credentials, and IP allowlists. Higher tiers add SSO, data residency, row-level policies, and an SLA.
free trial
team
business
enterprise
Self-serve checkout via Stripe on Free Trial and Team. Business and Enterprise billed via invoice. All prices USD.
Annual contracts available. Cancel anytime.
Twenty-minute call. We'll demo against your schema or a representative one, walk through the audit log and access model, and give you a deployment plan tailored to your compliance posture.