Services · Go deeper

Your suppliers hold database access.
Nobody knows what they use.

Supplier-risk programmes run on questionnaires and contracts, and they almost never say which tables the integrator’s service account read last quarter. This engagement does both halves: we build the register and review the suppliers and their contract terms as people, and we establish from the query trail what each third-party identity has actually reached. You get the paperwork an assessor expects and the evidence behind it.

Both
Paperwork and evidence
Observed
Access, not attested
Fixed
Scope and fee
24h
Quote turnaround
Deliverables

What you get, in writing

Every deliverable below is named in the statement of work. Nothing here is aspirational.

Supplier register and questionnaire review

We build the register of suppliers holding database access with you, issue and review the security questionnaires, and assess each response against the access they actually hold — so the register reflects reality rather than procurement records.

Contract and clause review

Supplier agreements reviewed against DORA Article 28 and NIS2 supplier-relationship obligations: audit rights, notification duties, sub-processor terms, and exit provisions, with the gaps written up per supplier.

Third-party identity inventory, granted versus used

Every supplier, integrator, and managed-service account with access to in-scope data stores, the classified objects each can reach, and what each has actually touched over the review window — established from the query trail, not from an attestation. Shared accounts, vendor defaults, and standing privileges never once exercised are named.

Least-privilege plan and monitoring baseline

A per-supplier plan narrowing grants to observed need with the statements to run and a rollback path, plus the alerting baseline that makes future deviation from that pattern visible as it happens rather than at the next annual review.

How It Works

A defined path, with a defined end

1

Scope

We agree the in-scope data stores and which suppliers are in question on a short call.

2

Register and review

The supplier register is built, questionnaires issued, and contract terms reviewed against the framework obligations that apply to you.

3

Observe

Actual access per third-party identity is established from the audit trail over an agreed window.

4

Report

You receive the register, the per-supplier findings, the observed-access record, and an ordered remediation plan.

Good Fit

This is for you if

  • An integrator or managed-service provider holds database access you cannot fully account for
  • Your supplier register lists organisations but not the accounts they actually hold
  • DORA Article 28 or NIS2 supplier-relationship questions are on your audit plan
  • You cannot say which third-party identity performed a given action last quarter
  • Shared or vendor-default accounts are suspected but not evidenced

Not sure it fits? Ask anyway — if it isn't a fit, we'll say so on the scope call.

Pricing

Priced up front, quoted in 24 hours

Fixed fee banded by the number of in-scope suppliers and data stores. Scope, review window, and deliverables agreed before any work starts, and the price does not move after the scope call.

Get an Access Review Quote

Get a fixed-scope quote in 24 hours

Enter your business email. We'll come back within 24 hours with a written quote for Third-Party Database Access Review — scope, price, and end date included.