Audit every query.
Catch every threat.
DB Audit monitors every query across 20+ database types, scores it against AI behavioral baselines, and flags threats in under a second. This page covers the nine core capabilities and the architecture behind them — all deployed in minutes, with no appliances to rack.
Nine capabilities,
three pillars, one collector
These were never nine unrelated features. They are three jobs most teams buy separately — grouped below the way the platform actually organises them, all running on the same collector and the same classified inventory.
Compliance
Know what you hold, prove the controls around it, and produce the evidence on demand.
Sensitive Data Discovery
You cannot protect data you have not found. DB Audit scans every connected database and classifies PII, PHI, and financial data automatically, with 20+ classification categories out of the box.
- 20+ data classification categories
- PII, SSN, credit cards, PHI detection
- Custom pattern matching
- Data lineage mapping
Policy & Compliance
Define audit policies once and apply them everywhere. Pre-built templates cover GDPR, HIPAA, SOX, PCI-DSS, SOC 2, and ISO 27001, so your first compliance report ships in minutes — not after a six-month professional-services engagement.
- Pre-built compliance templates
- Custom policy builder
- Violation tracking and alerting
- Automated compliance scoring
No-Opt Change Request Tracking
Link every database change to a change request with a single SQL statement. No agents, no application changes, no database configuration. Just run SELECT 'CR:12345' WHERE 1 = 0 before your changes and DB Audit does the rest.
- Zero-config CR tagging via SQL convention
- Automatic session-to-CR correlation
- SOX and ITIL change control compliance
- Full audit trail per change request
Security
Capture the activity, scan for exposure, and watch the files the data actually lives in.
Real-time SQL Auditing
We capture and analyze every query as it happens. The streaming pipeline handles millions of events per second and keeps detection latency under a second — no nightly batch runs, no gaps in the trail.
- Query normalization and deduplication
- Parameter extraction and hashing
- Query classification (SELECT, INSERT, UPDATE, DELETE, DDL)
- User and session tracking
Vulnerability Scanning
Continuous CVE, misconfiguration, and network scanning across every connected database — ranked by exploitability and data classification, not raw CVSS.
- CVE database scanning
- Misconfiguration detection
- Network security scanning
- Ranked remediation guidance
File Activity Monitoring
Datafiles, transaction logs, backups, configs, and keystores are hashed and baselined, so a change is not just detected — it is attributed to the database session and user behind it.
- XXH3 content hashing and drift detection
- Datafile, backup, and config coverage
- Permission and ownership changes
- Attribution to session and OS user
Incident Management
Score it, route it, escalate it if nobody picks it up, and keep the history as evidence.
AI Threat Detection
Machine learning models baseline how every user and application normally behaves, then score each deviation in real time. You see SQL injection attempts and privilege escalation before they become breaches.
- Behavioral baseline learning
- Anomaly scoring and classification
- SQL injection detection
- Privilege escalation alerts
User Behavior Analytics
We build a behavioral baseline for every user, then compare activity against their history and their peers. When a service account reads tables it has never touched, you know in under a second.
- Per-user behavioral baselines
- Time-of-day analysis
- Access pattern monitoring
- Peer group comparison
Alerting & Response
Alerts route to Slack, Teams, email, PagerDuty, or any webhook. Events forward to 14 SIEM platforms, filtered at the collector so you are not paying per-gigabyte for noise.
- Slack, email, PagerDuty alerts
- Webhook integrations
- SIEM forwarding to 14 platforms
- Escalation policies
Built for scale
A hash-first streaming architecture that processes millions of events per second and keeps detection latency under a second.
Hash-First Design
XXH3 hashing deduplicates queries at the edge, before they touch storage. Less data stored, faster queries, lower cost.
Vector Embeddings
Semantic SQL analysis with sentence transformers. Find similar queries even when the parameters differ.
Streaming Pipeline
Built on Kafka and Redpanda for real-time event processing. No batching delays — detection latency stays under a second.
Columnar Storage
Audit logs land in Parquet. Query billions of events in seconds, at object-storage prices.
See it in action
Connect your first database in minutes with a free trial, or get a demo tailored to your environment.