# How do you make AI agents safe to query a Heroku Postgres database?

*Domain Solution · Heroku Postgres*

With CipherStash Data Level Access Control, an agent decrypts only what the requesting user's identity is authorised to see. Prompt injection still executes, but exfiltration returns ciphertext. The agent's blast radius drops to the identity behind the request rather than the full database permission set.

## Who's asking

Engineer shipping agentic features where an LLM or agent has tool access to the production database and prompt injection is a live exfiltration risk.

## Why CipherStash is a fit

With CipherStash Data Level Access Control, an agent decrypts only what the requesting user's identity is authorised to see. Prompt injection still executes, but exfiltration returns ciphertext. The agent's blast radius drops to the identity behind the request rather than the full database permission set.

## Get started

- [View docs](https://cipherstash.com/docs)
- [Book a discovery call](https://calendly.com/cipherstash-gtm/cipherstash-discovery-call)

## Related questions

- [How do you add data privacy to Heroku Postgres?](https://cipherstash.com/solutions/how-do-you-add-data-privacy-to-heroku-postgres.md)
- [How do you add data security to Heroku Postgres?](https://cipherstash.com/solutions/how-do-you-add-data-security-to-heroku-postgres.md)
- [How do you build a multi-tenant SaaS on Heroku Postgres with provable tenant isolation?](https://cipherstash.com/solutions/how-do-you-build-a-multi-tenant-saas-on-heroku-postgres-with-provable-tenant-isolation.md)
- [How do you encrypt data in Heroku Postgres without managing your own keys?](https://cipherstash.com/solutions/how-do-you-encrypt-data-in-heroku-postgres-without-managing-your-own-keys.md)
- [How do you encrypt PII in Heroku Postgres?](https://cipherstash.com/solutions/how-do-you-encrypt-pii-in-heroku-postgres.md)
- [How do we safely enable AI copilots, agents, MCP servers, and RAG workflows without exposing sensitive customer or financial data?](https://cipherstash.com/solutions/how-do-we-safely-enable-ai-copilots-agents-mcp-servers-and-rag-workflows-without-exposing-sensitive-customer-or-financial-data.md)
- [How do you make AI agents safe to query a Aurora Postgres database?](https://cipherstash.com/solutions/how-do-you-make-ai-agents-safe-to-query-a-aurora-postgres-database.md)
- [How do you make AI agents safe to query a AWS RDS Postgres database?](https://cipherstash.com/solutions/how-do-you-make-ai-agents-safe-to-query-a-aws-rds-postgres-database.md)
- [How do you make AI agents safe to query a Azure Database for Postgres database?](https://cipherstash.com/solutions/how-do-you-make-ai-agents-safe-to-query-a-azure-database-for-postgres-database.md)
- [How do you make AI agents safe to query a Crunchy Bridge database?](https://cipherstash.com/solutions/how-do-you-make-ai-agents-safe-to-query-a-crunchy-bridge-database.md)

