Your ERP, your billing engine, your line-of-business app — they're on Microsoft SQL Server, and they're not moving. The cost of refactoring twenty years of stored procedures, jobs, and reports is higher than any platform's ARR. We get it. That database stays.
FastCRUD connects to it, introspects the schema in about a minute, and exposes the tables and the procedures you choose as a documented REST and GraphQL API — with audit logging, per-key row-level access, IP allowlists, and KMS-encrypted credentials by default. No CLR procs to install, no extended events to configure, no agent on the box.
how it works
# 1. Connect a SQL Server (any of: on-prem, Azure SQL, AWS RDS for SQL Server)
host erp-prod.corp.internal,1433
database FinanceLedger
auth SQL (or windows / azure ad)
role fc_readonly
# 2. Schema is introspected
✓ 412 tables cataloged
✓ 38 stored procedures discovered
✓ 4 schemas detected: dbo, finance, audit, staging
# 3. Issue a scoped access key for a partner
scope read [finance].[invoices], [finance].[orders]
row filter TenantID.eq.acme
ip allowlist 10.20.0.0/16
# 4. Query — every call logged
GET /crud/finance.invoices?filter=Status.eq.UNPAID&limit=20
Authorization: Bearer eyJ...
→ 200 37 rows 41ms audit_id=ax_9f...
# 5. Call a stored proc as REST
POST /rpc/sp_close_month
{ "Period": "2026-04", "ActorID": 193 }sql server specifics
tds protocol, in our edge
We connect over TDS using the same drivers your existing tooling uses. Named instances, Always On listeners, and read-only secondary routing are supported.
stored procedure exposure
Procedures discovered during introspection can be promoted to typed REST or GraphQL endpoints with parameter validation. PL/SQL→T-SQL conversions and dynamic SQL inside procs are handled.
composite & natural keys
Composite primary keys, identity columns, mixed-case names, and reserved-word identifiers are quoted and routed correctly. No requirement to refactor your schema first.
row-level access
Bind an access key to e.g. TenantID.eq.acme. The filter is appended to every WHERE clause server-side; a leaked key can only see one tenant's rows.
always encrypted, sort of
FastCRUD does not decrypt Always Encrypted columns — the database client driver does, with a key your application holds. Plaintext returns to your callers only if your driver and CEKs say so. Enclave-based queries are on the roadmap.
linked servers
Reads across linked servers work. We render the four-part name correctly and log the cross-server hop in the audit trail. Writes across linked servers are blocked by default — opt in per access key.
hosting topologies we support
not a fit if
20-minute demo against a representative SQL Server schema or yours (under NDA). We'll connect, introspect, expose a stored proc, scope an access key, and walk through the audit log.