Built for production databases
MotionQL is designed so that a mistake in the UI can't become a write to production, and so your credentials never leave your machine.
How a query travels
Three layers, each with one job. The part you click on is the part with the least power.
Interface
Sandboxed and context-isolated, with a strict content security policy. It never touches MongoDB, files or secrets.
App core
Runs every database call, enforces read-only, AI and script policies, and holds secrets encrypted with your OS keychain.
Your database
MotionQL connects straight from your computer. Nothing is proxied through us.
Safe enough for production. Simple enough for Friday afternoon.
The guardrails DBAs ask for, built into the app instead of bolted on.
Read-only connections
Mark a connection read-only and every write is blocked inside the app, including $out, $merge and explain-wrapped writes.
Secrets in your OS keychain
Passwords, keys and tokens are encrypted with macOS Keychain, Windows DPAPI or Linux Secret Service, and never reach the UI.
No data leaves your machine
MotionQL talks straight to your database. We never receive documents, queries, connection settings or credentials.
Local audit log
Writes and security events are recorded with credentials redacted. Typed-name confirmation guards every drop.
Works air-gapped
Licenses are verified offline with a digital signature. No phone-home, no hardware fingerprinting.
Policies for IT
Push policy.json through MDM or GPO to enforce read-only hosts, AI rules, script mode and idle lock across a fleet.
Self-hosted Team Server
SSO with Okta, Entra ID or Google, SCIM, shared queries and snippets, and a hash-chained central audit log.
Hardened Electron
Sandboxed renderer with strict CSP, verified IPC, Electron fuses and an integrity-checked app bundle.
Our privacy promises
We never receive your data
No documents, queries, connection settings or credentials ever reach MotionQL's servers.
Offline license checks
Keys are signed and verified on your machine. No phone-home at launch, no hardware fingerprinting.
AI goes to your provider, not us
Requests go straight from your computer to the provider you chose, with schema-level context only.
Opt-in telemetry only
Anonymous usage stats and crash reports are off unless you allow them, and IT can block them by policy.
Your next query deserves a better IDE.
Create a free account, download MotionQL, and paste your Pro key. You'll be querying in under two minutes.