Features

Audit every query.
Catch every threat.

DB Audit monitors every query across 20+ database types, scores it against AI behavioral baselines, and flags threats in under a second. This page covers the nine core capabilities and the architecture behind them — all deployed in minutes, with no appliances to rack.

Nine capabilities,
three pillars, one collector

These were never nine unrelated features. They are three jobs most teams buy separately — grouped below the way the platform actually organises them, all running on the same collector and the same classified inventory.

Compliance

Know what you hold, prove the controls around it, and produce the evidence on demand.

Explore Compliance

Sensitive Data Discovery

You cannot protect data you have not found. DB Audit scans every connected database and classifies PII, PHI, and financial data automatically, with 20+ classification categories out of the box.

  • 20+ data classification categories
  • PII, SSN, credit cards, PHI detection
  • Custom pattern matching
  • Data lineage mapping
Cited by 55 of 57 frameworks

Policy & Compliance

Define audit policies once and apply them everywhere. Pre-built templates cover GDPR, HIPAA, SOX, PCI-DSS, SOC 2, and ISO 27001, so your first compliance report ships in minutes — not after a six-month professional-services engagement.

  • Pre-built compliance templates
  • Custom policy builder
  • Violation tracking and alerting
  • Automated compliance scoring
Cited by 56 of 57 frameworks

No-Opt Change Request Tracking

Link every database change to a change request with a single SQL statement. No agents, no application changes, no database configuration. Just run SELECT 'CR:12345' WHERE 1 = 0 before your changes and DB Audit does the rest.

  • Zero-config CR tagging via SQL convention
  • Automatic session-to-CR correlation
  • SOX and ITIL change control compliance
  • Full audit trail per change request
Cited by 5 of 57 frameworks

Security

Capture the activity, scan for exposure, and watch the files the data actually lives in.

Explore Security

Real-time SQL Auditing

We capture and analyze every query as it happens. The streaming pipeline handles millions of events per second and keeps detection latency under a second — no nightly batch runs, no gaps in the trail.

  • Query normalization and deduplication
  • Parameter extraction and hashing
  • Query classification (SELECT, INSERT, UPDATE, DELETE, DDL)
  • User and session tracking
Cited by 57 of 57 frameworks

Vulnerability Scanning

Continuous CVE, misconfiguration, and network scanning across every connected database — ranked by exploitability and data classification, not raw CVSS.

  • CVE database scanning
  • Misconfiguration detection
  • Network security scanning
  • Ranked remediation guidance
Cited by 37 of 57 frameworksFull vulnerability management

File Activity Monitoring

Datafiles, transaction logs, backups, configs, and keystores are hashed and baselined, so a change is not just detected — it is attributed to the database session and user behind it.

  • XXH3 content hashing and drift detection
  • Datafile, backup, and config coverage
  • Permission and ownership changes
  • Attribution to session and OS user
Cited by 31 of 57 frameworksFile Activity Monitor

Incident Management

Score it, route it, escalate it if nobody picks it up, and keep the history as evidence.

Explore Incident Management

AI Threat Detection

Machine learning models baseline how every user and application normally behaves, then score each deviation in real time. You see SQL injection attempts and privilege escalation before they become breaches.

  • Behavioral baseline learning
  • Anomaly scoring and classification
  • SQL injection detection
  • Privilege escalation alerts
Cited by 38 of 57 frameworks

User Behavior Analytics

We build a behavioral baseline for every user, then compare activity against their history and their peers. When a service account reads tables it has never touched, you know in under a second.

  • Per-user behavioral baselines
  • Time-of-day analysis
  • Access pattern monitoring
  • Peer group comparison
Cited by 32 of 57 frameworks

Alerting & Response

Alerts route to Slack, Teams, email, PagerDuty, or any webhook. Events forward to 14 SIEM platforms, filtered at the collector so you are not paying per-gigabyte for noise.

  • Slack, email, PagerDuty alerts
  • Webhook integrations
  • SIEM forwarding to 14 platforms
  • Escalation policies
Cited by 49 of 57 frameworksSIEM & security analytics
Architecture

Built for scale

A hash-first streaming architecture that processes millions of events per second and keeps detection latency under a second.

Hash-First Design

XXH3 hashing deduplicates queries at the edge, before they touch storage. Less data stored, faster queries, lower cost.

Vector Embeddings

Semantic SQL analysis with sentence transformers. Find similar queries even when the parameters differ.

Streaming Pipeline

Built on Kafka and Redpanda for real-time event processing. No batching delays — detection latency stays under a second.

Columnar Storage

Audit logs land in Parquet. Query billions of events in seconds, at object-storage prices.

See it in action

Connect your first database in minutes with a free trial, or get a demo tailored to your environment.