{
  "id": 11161690,
  "title": "Voice-to-SQL: hablarle a tu base de datos con un LLM (y por qué la seguridad es lo difícil)",
  "url": "https://urgent.news/2026/10/01/voice-to-sql-hablarle-a-tu-base-de-datos-con-un-llm-y-por-que-la",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-01T10:00:03.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/adrian_368e1d3e691afab697/voice-to-sql-hablarle-a-tu-base-de-datos-con-un-llm-y-por-que-la-seguridad-es-lo-dificil-1gj1"
  },
  "original_language": "es",
  "account": "\"Voice-to-SQL\" is a system that allows anyone to ask questions about a database using natural language, whether spoken or typed. The system responds with the results in a matter of seconds. Traditionally, only those with knowledge of SQL could interact with a database directly, leading to delays and inefficiencies.\n\nThe core concept behind \"Voice-to-SQL\" is to enable users to interact with a database through voice or text, obtaining instant responses. The challenge is to create a system that is both cost-effective and secure. Three key requirements were established: the voice input must not incur additional costs, the system must ensure the security of exposing the database to a Large Language Model (LLM), and the response should be delivered within a second.\n\nTo meet these requirements, the system relies on the Web Speech API, integrated into modern web browsers such as Chrome, Edge, and Safari. This API handles voice transcription locally on the user's device, eliminating the need to send audio data to a backend server. The only cost associated with the transcription process is the browser dependency, a reasonable trade-off for a web-based demo.\n\nThe system utilizes the Qwen3.8 27B LLM through Groq, known for its low latency. The LLM's role is to convert natural language queries into SQL statements. However, the key to success lies not in the LLM itself, but in the input it receives. The system provides the LLM with the precise database schema, including tables, columns, data types, enum values, and SQLite dialect rules. This context enables the LLM to generate accurate JOINs and GROUP BY clauses, significantly improving the quality of the generated SQL.\n\nThe most critical aspect of the system is ensuring its security. Exposing a database to an LLM poses significant risks, as a poorly interpreted or maliciously crafted query could result in destructive actions such as DROP TABLE. To mitigate this risk, the system implements a sanitization layer that strictly enforces SQL generation rules. The sanitization process only accepts SELECT or WITH statements, rejects a blacklist of potentially harmful commands (INSERT, UPDATE, DELETE, DROP, ALTER, CREATE, PRAGMA, ATTACH, and REPLACE), prevents multi-statement queries separated by semicolons, and limits the response to a maximum of 100 rows.\n\nThis multi-layered defense approach provides a conservative approach, prioritizing the rejection of potentially legitimate but rare queries over allowing destructive ones. Once the LLM proposes a SQL statement, the sanitization layer validates it before execution. The system demonstrates the effectiveness of this approach by providing users with both the generated SQL and the resulting table, making the demo both functional and educational.\n\nThe database used for testing the \"Voice-to-SQL\" system is a SQLite database simulating the back-office of a SaaS company. It contains 200 customers, 8 products, and 5,000 sales from the previous year, providing a realistic dataset for conducting analytical queries on revenue, plans, and churn rates. This dataset enables users to ask meaningful questions and receive accurate results, showcasing the system's capabilities while maintaining a practical and relevant context.",
  "summary": "Las preguntas sobre datos casi nunca las hace quien sabe SQL. Las hace alguien de negocio, marketing o dirección, que tiene que pedírselas a un analista y esperar. Voice-to-SQL ataca justo esa fricción: que cualquiera pueda preguntarle a la base de datos hablando , y obtener la respuesta al instante. El problema Quería una demo que tradujera lenguaje natural —por voz o texto— a SQL, lo ejecutara…",
  "key_points": [
    "Voice-to-SQL enables natural language queries on databases via voice or text.",
    "System ensures security of database exposure to LLM with sanitization layer.",
    "SQLite database simulating SaaS back-office used for testing Voice-to-SQL."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}