Ship AI Agents Your Customers Can Trust.

Give your agent real access to real systems — without giving it unlimited access. Scoped per caller, human approval where it matters, every call on the record.

Built for agents that touch production — your own systems, or your customers'.

Free to start, no credit card · for enterprise & air-gapped

Scoped to one caller at a time

It can only reach what that person is allowed to

Asks before it changes anything

Risky actions wait for a human, enforced in code

Usage you can see

Cost per user, before it surprises you

Reaches on-prem systems too

Behind your firewall, outbound only

Developer-first

A few lines to ship

Sign a scoped token for each of your users — source allowlists, rate limits, read-only by default — then drop in the widget or call the SDK. The governance rides in the token, so there's no glue code to maintain.

typescript
1// Server-side: sign a scoped token for this user
2const token = cb.widgetToken(user.id, {
3 sources: ["orders", "invoices"],
4 limits: { daily: 50 },
5});
6
7// Client-side: drop the governed widget into your app
8import "@corebasehq/widget";
9
10CorebaseWidget.init({
11 publicId: "proj_•••",
12 getAuthToken: () => token,
13});
Govern

Room to think, rails that hold

Below is a real support procedure, running. Step five is the one to watch: the refund is over a limit somebody set, so the call is never made — it waits, visibly, until a person approves it.

Refund request · #1043running
In this rail, the agent canEnforced
Read orders & payments
Refund over $100 — waits for a human OK
Anything else — never runs

The tool is never handed over

A step that shouldn’t reach a source doesn’t get its tools built in the first place. There is no call to refuse, because there was never a tool to call — an agent can’t be talked into using something it was never given.

Approval binds to the call

A held action is stored whole. Approving runs exactly what the reviewer saw — not whatever the model would come up with when asked to try again.

Both halves are on the record

What ran and what was stopped, each stamped with the version of your rules that was in force at the time — so a long run that crossed an edit can still be explained afterwards.

Connect

Give your agents the data they run on

Every agent you ship reads straight from your real systems — databases, REST & GraphQL APIs, and 50+ apps. No ETL, no glue code, no integration sprint.

See all integrations
GitHub
Slack
Jira
Notion
Salesforce
Stripe
PostgreSQL
MSSQL
Gmail
HubSpot
Zendesk
Shopify

Cloud & SaaS

Connect in one click

Paste a connection string or sign in — PostgreSQL, MySQL, REST & GraphQL APIs, Slack and Microsoft 365 connect directly, live and read-only.

On-prem & legacy

When a customer needs it

When a customer's data lives behind the firewall, reach it too: the open-source CoreMCP agent runs inside their network to serve SQL Server 2000+, Firebird, and on-prem ERP / POS. It connects outward from the inside — nothing to open up, no VPN. Even works fully offline.

Why CoreBase

Everything you need to ship on real data

Guardrails, attack screening, per-user isolation — the governance you'd otherwise build yourself, already here. Batteries included, self-host optional.

Agents that stay on the rails

Draw the steps your assistant works through — what data each step can touch, what it may do, when it must ask for approval. It reasons freely inside; the rails are enforced, not suggested.

Every visitor connects their own

Gmail, Jira, or any of 50+ apps — each visitor links their own account, and the assistant acts on it alone. Isolation is the OAuth grant itself, not a filter that could slip.

Bring your own model

Use the built-in AI, or plug in your own keys — Claude, GPT, Gemini and more. Switch anytime.

Private by design

Read-only by default, isolated per customer, encrypted in transit and at rest — and every action is logged.

Screened at the door

Every message is checked for prompt injection, jailbreaks and abuse before it reaches the model — on chat, widget, voice and API alike.

It learns your schema

Query Memory remembers the queries that worked and what your tables mean — so natural-language → SQL gets sharper the more you run it.

Explore

Ask across every system — answers from live data

One query can hit your database, your CRM, and your inbox at once — read straight from the source, never a stale copy.

One question, every source

CoreBase fans your question out across the systems you have connected and assembles a single answer — with every step logged.

Real numbers, straight from the source

Answers come back as figures and tables computed from live data — not summaries of a stale copy.

Always current

Every answer is computed at ask time, straight from the live system.

Only their own rows

Each question runs as the person asking it, so one customer can never be answered with another’s data.

Asks before it changes

Nothing is written until someone says so — the customer for their own data, your team for anything you gated.

Full audit trail

Every question, query, and action is recorded — nothing happens off the record.

Customer story
DropThatShip

Support that answers first — and escalates when it should

DropThatShip's assistant answers customers from live order data — and when it can't, it opens the ticket itself.

Support tickets, down
Satisfaction, up
Handoffs, clean

Open source

CoreMCP — the open-source bridge.

The agent that reaches behind the firewall is open source. Audit it, run it yourself, or keep it fully offline. The managed platform is built on the same code your team can read line by line.

View on GitHub
Pricing

Start free. Scale when you're ready.

Every plan includes AI usage on built-in models — no key required to start. Bring your own LLM key any time and pay your provider directly instead.

Save 25% on annual billing

Free

Build against one source, free.

$0/ mo

Free forever

Get started
  • 1 data source
  • $1 one-time model credit — built-in models, no key needed
  • BYOK LLM keys (optional, your provider)
  • Developer API + embeddable widget
  • Query Memory — the assistant learns your schema
  • Per-tenant isolation at the database — every plan
  • Read-only by default
  • Community support

When the $1 runs out we pause model calls before any charge — top up a prepaid balance or add your own LLM key. Everything else here stays free.

GrowthMost popular

For developers wiring agents to real systems.

$79/ mo

billed monthly

Get started
  • Everything in Free, plus:
  • 5 data sources · 3 projects
  • $5/mo included AI usage
  • REST / GraphQL + cloud DB connectors
  • On-prem database access via CoreMCP
  • Upload documents — answers grounded in your files (RAG)
  • Guardrails — enforced conversation rails
  • Email support

Team

For teams that need governance and scale.

$249/ mo

billed monthly

Get started
  • Everything in Growth, plus:
  • Unlimited data sources & projects
  • $15/mo included AI usage
  • RBAC + full audit log
  • Usage & cost analytics per member
  • Priority support

Enterprise

Air-gapped or regulated environments, dedicated infrastructure, and SSO.

  • Air-gapped / on-prem container
  • Dedicated infrastructure
  • SSO / SAML
  • SLA + dedicated support
Contact sales

Need the full breakdown across every plan?

Compare all plans

FAQ

Frequently asked questions

Reach, safety, isolation, and deployment — what security and data teams ask before connecting an agent to live systems.











Can't find what you're looking for? Contact our support team

Ship your first agent today.

Connect a source, wire up an agent, and stream your first answer in minutes. Free to start — no credit card.

Need air-gapped or enterprise?