Last updated: 2026-08-20
QueryPie AIP, built by the Seoul-based database security company QueryPie, is an enterprise platform that centrally governs a wide range of pre-built MCP (Model Context Protocol) servers. Teams build AI agents on Claude, GPT and Gemini with per-agent access control, data loss prevention and audit logs kept 90 to 180 days.
About QueryPie AIP
QueryPie AIP is an enterprise AI agent platform built by QueryPie, a Seoul-based company founded in 2017 that started out building database access control software before expanding into AI governance. AIP lets an organization connect Claude Opus, OpenAI's GPT models and Google Gemini to more than 45 pre-built MCP (Model Context Protocol) servers, covering tools like Slack, GitHub, Jira, Salesforce, PostgreSQL and Snowflake, so employees can build and run custom AI agents without writing integration code. The core mechanism is a centralized MCP gateway: instead of every team wiring its own agent into Slack or a production database, IT sets per-tool MCP Access Control and per-agent Agent Access Control once, and QueryPie's Smart Edge Tunneling lets agents reach firewall-protected internal systems without opening new network paths. A data loss prevention layer screens what enters those AI conversations, and every action is written to an audit log. That governance layer is the differentiator from a generic MCP hub: QueryPie is applying more than eight years of database access-control experience to agent traffic instead of adding security as an afterthought. AIP is built for IT and security teams at mid-size to large enterprises who need to let employees use AI agents against real company systems without losing control of who can touch what. A platform engineering team can standardize which of a wide range of MCP servers, from Slack and Google Workspace to Kubernetes and Oracle Database, different departments are allowed to connect, while a security lead can pull a full audit trail if an agent touches a regulated database. It is not built for a solo developer who just wants a free personal AI agent; there is no lightweight self-serve tier. QueryPie AIP is sold on a single named paid plan billed monthly through usage-based credits, plus a custom-priced Enterprise plan that adds single sign-on, data loss prevention, custom branding and longer audit retention. There is no permanent free tier, only a short trial period to test the platform. It runs as a web application, with a proxy mode that lets the same MCP presets be used inside Cursor, Claude Desktop and Windsurf. QueryPie has raised roughly $45.7 million across four funding rounds, including a $17.75 million Series Seed round in December 2021 co-led by Atinum Investment and Murex Partners, with later backing from Salesforce Ventures, Shinhan Venture Investment and Z Venture Capital, according to Tracxn. It holds SOC 2, ISO 27001 and CSA STAR attestations on its public trust center, credentials it built for its original database access control product and has extended to AIP's agent traffic.
Pricing
Business plan is $650/month for 20,000 monthly credits, up to 30 custom AI agents, 10 RAG knowledge bundles, 90-day audit logs and 1GB storage per user. Enterprise plan is custom-priced (contact sales) and adds unlimited agents, unlimited RAG bundles, SSO, DLP, custom branding and 180-day audit logs. No permanent free tier; a 14-day trial with 2,000 credits is available instead.
Key Features
- MCP Gateway: Centrally manages 45+ pre-built MCP servers, including Slack, GitHub, Jira Cloud, Salesforce, PostgreSQL and Snowflake, so agents connect to business systems without custom integration code.
- Smart Edge Tunneling: Lets AI agents reach firewall-protected internal systems and on-prem databases without opening new network ports or changing existing security infrastructure.
- Per-Agent Access Control: Applies granular MCP Access Control and Agent Access Control so admins can turn specific tools on or off for specific agents or team members from one console.
- Built-in Data Loss Prevention: Automatically blocks credit card numbers, SSNs, API keys and other confidential data from entering AI conversations before they reach the model.
- MCP Proxy for IDEs: Exposes the same MCP presets to Cursor, Claude Desktop and Windsurf through a secure local proxy, so the governed connections work outside the QueryPie web app too.
- RAG Knowledge Bundles: Includes RAG knowledge bundles so agents can ground answers in uploaded company documents, not just live MCP tool calls; Enterprise adds an unlimited allotment.
Pros
- Bundles enterprise access governance, per-tool and per-agent permissions plus long-retention audit logs, directly into the agent platform instead of requiring a separate security product.
- Pre-built MCP integrations cover common enterprise systems (Slack, Jira, Salesforce, PostgreSQL, Kubernetes) out of the box, cutting the custom integration work needed to stand up a first agent.
- Its trust center publicly lists SOC 2, ISO 27001 and CSA STAR certifications, credentials carried over from QueryPie's original database access control product rather than newly acquired for AIP.
Cons
- There is no low-cost entry tier; teams wanting to try AI agents cheaply only get a short, credit-limited trial rather than an ongoing free plan.
- QueryPie does not publish the full list of AI models it supports beyond naming Claude Opus, GPT and Gemini, so buyers must ask sales for the current model list before committing.
- QueryPie's own site claims dramatic cost savings versus ChatGPT with no published methodology or case study backing the figure.
Frequently Asked Questions
What does QueryPie AIP actually cost?
QueryPie AIP's Business plan is priced at $650 per month. That tier covers 20,000 monthly credits, consumed per LLM token as agents run, a cap of 30 concurrent custom agents, 10 bundles of RAG knowledge, and 1GB of per-user storage. Enterprise removes those caps and adds SSO, DLP and custom branding for a custom quote; QueryPie does not publish that number, so teams have to contact sales.
Can you use QueryPie AIP without paying?
Not on an ongoing basis. QueryPie offers a free trial with a limited credit allowance so a team can build and test agents before committing, but there is no permanent free tier; the cheapest paid plan is the Business tier.
What are QueryPie AIP's closest competitors?
n8n and Zapier both let teams wire AI steps into automation workflows but neither bundles QueryPie's per-agent access control and audit logging. LangChain is the closer technical peer for building custom agents, but it is a developer framework you code against rather than a governed, no-code platform. Portkey and Composio are newer MCP gateway products aimed at a similar enterprise-governance use case.
How does QueryPie AIP compare to n8n in 2026?
n8n is a workflow automation tool that can call AI models as one step in a chain, and is itself one of the many MCP integrations QueryPie AIP connects to. QueryPie AIP is built specifically around AI agents, MCP server governance and per-agent access control, features n8n does not offer natively. Teams that need audit logs and DLP around agent activity get more from QueryPie AIP; teams that mainly need general workflow automation get more flexibility from n8n's broader node library.
How do you set up QueryPie AIP?
A team signs up for the trial, then connects the MCP servers it needs, such as Slack, GitHub or a database, from the pre-built options in the MCP Gateway. An admin sets MCP Access Control and Agent Access Control rules for which teams can use which tools, then a user combines connected MCP servers into a preset and starts an agent conversation referencing that preset. The same presets can be exposed to Cursor, Claude Desktop or Windsurf through the MCP proxy for developers who want to work outside the web app.
Top Alternatives
- n8n: Pick QueryPie AIP if you need built-in per-agent access control and audit logs; pick n8n if you want a cheaper workflow builder without QueryPie's governance layer.
- LangChain: Pick QueryPie AIP if you want a governed, no-code agent platform for business teams; pick LangChain if your developers want to code custom agent logic directly.
- Zapier: Pick Zapier if you want cheap, simple app-to-app automation; pick QueryPie AIP if you specifically need MCP-based AI agents with enterprise access control.