Part of the Security pillar

Know what's exposed,
before someone else does.

A scanner licensed per asset, run once a quarter by a different team, produces a several-hundred-page report nobody acts on. We scan continuously from the collector already watching your databases, and rank findings by what the data is worth — so the top of the list is the thing to fix on Monday.

Get a Posture Review
Daily
Not quarterly
20+
Engines scanned
0
Per-asset licence fees
<1%
CPU overhead
Database Scanning

Eight classes of finding,
across every engine you run

A generic infrastructure scanner sees a host with a port open. These checks understand the engine behind it.

CVE matching per engine and version

Every connected database is fingerprinted down to the patch level and matched against known CVEs. New advisory published overnight? The finding is waiting for you, not queued behind next quarter's scan window.

Missing patches and end-of-life versions

Which instances are behind, how far behind, and which are running a version that no longer receives security fixes at all. The last one is usually the finding nobody knew about.

Misconfiguration detection

Audit logging disabled, verbose errors exposed, dangerous extensions loaded, insecure authentication methods in pg_hba.conf, default ports and sample databases left in place.

Benchmark-based configuration checks

Configuration is compared against hardening benchmarks per engine, so you get a posture score with named gaps rather than a generic pass or fail.

Default and weak credentials

Accounts still on vendor defaults, shared service accounts, passwords that never rotate, and logins with no expiry policy.

Excessive privilege and role sprawl

Who holds superuser, who inherited it through three nested roles, and which service accounts hold standing privileges they have never once used.

Unencrypted connections

Instances accepting plaintext connections, weak ciphers still enabled, and clients connecting without TLS even where TLS is available.

Stale and orphaned accounts

Logins belonging to people who left, accounts unused for months, and credentials with no owner. Cross-referenced against the query trail, so "unused" means genuinely unused.

Network Security Scanning

A patched database
on an open port is still exposed

Network posture is where most database breaches actually start. These checks run on the same schedule and land in the same findings list as the engine-level ones.

Exposed listeners and open ports

Which database ports are reachable, from where, and whether that matches what your architecture documents claim. Findings name the source segment, not just the port.

Unexpected network reachability

A production database answering from a guest VLAN or a build network is a finding regardless of how well patched it is. We compare observed reachability against the documented baseline.

TLS, cipher, and certificate checks

Protocol versions and cipher suites in active use, self-signed and mismatched certificates, and expiry warnings with enough lead time to renew before the outage.

Credentialed and uncredentialed scanning

Uncredentialed scans show what an attacker on the network sees. Credentialed scans go deeper into configuration and privilege. Run either, or both, on independent schedules.

Listener and endpoint hardening

Listener configuration, admin endpoints, management interfaces, and cloud security-group rules that widen access beyond the intended segment.

Drift from the network baseline

An approved snapshot of the network posture, then alerts when it changes. New ingress rules are the single most common way a hardened estate quietly stops being hardened.

The expected baseline is documented innetwork requirements, and hardening guidance insecurity hardening.

Prioritization

The same CVE is not
the same risk twice

A critical CVE on a database holding classified cardholder data is an emergency. The identical CVE on a dev instance with synthetic data is a ticket. Standalone scanners rank both at 9.8 because they cannot tell the difference — they never did the data discovery. We did, on the same platform, so ranking accounts for it.

  • Ranked by exploitability, exposure, and the classification of the data at risk
  • Correlated with observed activity — a vulnerable instance seeing unusual queries escalates
  • Named remediation guidance per finding, not a CVE link and a shrug
  • Findings routed to the owning team through existing alert channels and SIEM forwarding
  • Remediation history retained as audit evidence, with before-and-after posture scores
Compliance

Scan evidence,
mapped to the requirement

PCI-DSSRequirement 10.1

Audit Trail Implementation

MUST implement audit trails to link all access to system components to each individual user.

Every finding is tied to a named instance and the individuals holding access to it, so remediation evidence links back to accountable users.

SOXSection 404

Internal Controls

Companies MUST assess and report on internal control effectiveness. REQUIRES documented evidence of controls over financial data.

Continuous posture scoring on financial systems, with documented scan history and remediation trail as control evidence.

See all 57 frameworks we map to, or have us produce the evidence pack viaAudit Evidence-as-a-Service.

Already Built In

Continuous, because it's already
standing next to the database

Quarterly scanning exists because scanning used to be expensive and disruptive. The collector is already connected and already read-only, so a new database gets scanned the day it is added — no scheduling ticket, no scan window, no extra credentials.

Cost

No per-asset scanner licence and no per-core fee. Adding a database adds a scan target at no marginal cost, which is why teams here scan everything instead of only what the budget covers.

Ease of use

The databases are already connected, so there is nothing to onboard. No scan credentials to provision separately, no target list to maintain, no scheduling ticket for a new instance.

Runs local

Scanning runs from the collector inside your network. Air-gapped estates get an offline CVE feed, so classified environments are scanned without an internet path.

AI that ranks by real risk

A CVSS score knows nothing about your estate. Ours weighs exploitability against what the data is classified as and what activity the instance is actually seeing — so the top of the list is the thing to fix first.

Find out what's exposed right now

Enter your business email and we'll scan a representative slice of your estate, then walk you through the ranked findings — including the ones your current scanner is not looking for.