Know what’s ina file beforeanyone opens it.

Gridline checks every CSV and XLSX upload the moment it lands: a quality score, any personal data, your own rules, which rows changed since the last version, and exactly who can open it. Then it cleans the file and answers questions about it.

Start free

The Free plan needs no card. The demo is a read-only company with sample files.

Sample file

payroll-march.csv

0 rows · 7 columns · 214 KB

Arrived

File received.

Restricted to 2 people

Sample file, invented for this page. Your report is built from your own file and your own rules.

Find the personal data before it spreads.

Every report says which columns look like email addresses, phone numbers, card numbers, IBANs, IP addresses, birth dates or secret keys. It is found by patterns and checksums, so it is never an AI guessing, and a value is never shown. If a file like that is open to the whole company, the people who can fix it are told.

Everything Gridline does
customers-export.csv · personal data (sample)
  • emailEmail addresses · 98% of cellsPersonal data
  • mobilePhone numbers · 91% of cellsPersonal data
  • card_on_fileCard numbers · Luhn check passesPersonal data
  • planNothing personalClear

Visible to the whole company. The uploader and your admins are told.

Found by patterns and checksums, never by an AI, and never shown as a value. Sample data, invented for this page.

Connect it to the rest of your stack.

The reference is generated from the API itself, so it cannot drift from what the API does.

Scoped API keys
A key acts as the person who made it, never with more than their role or its own scopes.
Signed webhooks
Every delivery carries an HMAC signature over the exact body, so you can verify it came from Gridline.
Live updates
Report status and quota arrive over Socket.IO as they change, with no polling.
Read-only GraphQL
One request for a whole page of files, reports and versions.
An MCP server for agents
An AI agent can list files, read reports, clean, compare versions row by row, and ask a file a question, with the same keys, scopes and limits as the API.
Upload a file
curl -X POST "$GRIDLINE_URL/api/files" \
  -H "Authorization: Bearer $GRIDLINE_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -F "file=@payroll-march.csv"
Ask a file for a total by region
curl -X POST "$GRIDLINE_URL/api/files/$FILE/explore" \
  -H "Authorization: Bearer $GRIDLINE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "query": { "groupBy": ["region"],
        "measures": [{ "fn": "sum", "column": "revenue" }] } }'
What your endpoint receives
POST /your/endpoint
webhook-id: 6c1f9e2a-…
webhook-timestamp: 1790000000
webhook-signature: v1=3f8a…

{ "type": "report.ready", … }

What happens to your files.

Other companies never see yours
Every query is scoped to your company. Another company’s data is not forbidden; it is simply not found.
Files stay private
Files sit in a private bucket and are handed out through links that expire after five minutes.
The record cannot be edited
Every change is written to an audit log that the database itself refuses to alter or delete.
The assistant never sees your rows
A summary or a question is answered from column names and statistics. Personal data is found by patterns and checksums, and Gridline runs every query itself.
Secrets are never stored as typed
Passwords and API keys are stored hashed, and webhook secrets are stored encrypted.
How it is built