Know what's exposed,
before someone else does.
A scanner licensed per asset, run once a quarter by a different team, produces a several-hundred-page report nobody acts on. We scan continuously from the collector already watching your databases, and rank findings by what the data is worth — so the top of the list is the thing to fix on Monday.
Eight classes of finding,
across every engine you run
A generic infrastructure scanner sees a host with a port open. These checks understand the engine behind it.
CVE matching per engine and version
Every connected database is fingerprinted down to the patch level and matched against known CVEs. New advisory published overnight? The finding is waiting for you, not queued behind next quarter's scan window.
Missing patches and end-of-life versions
Which instances are behind, how far behind, and which are running a version that no longer receives security fixes at all. The last one is usually the finding nobody knew about.
Misconfiguration detection
Audit logging disabled, verbose errors exposed, dangerous extensions loaded, insecure authentication methods in pg_hba.conf, default ports and sample databases left in place.
Benchmark-based configuration checks
Configuration is compared against hardening benchmarks per engine, so you get a posture score with named gaps rather than a generic pass or fail.
Default and weak credentials
Accounts still on vendor defaults, shared service accounts, passwords that never rotate, and logins with no expiry policy.
Excessive privilege and role sprawl
Who holds superuser, who inherited it through three nested roles, and which service accounts hold standing privileges they have never once used.
Unencrypted connections
Instances accepting plaintext connections, weak ciphers still enabled, and clients connecting without TLS even where TLS is available.
Stale and orphaned accounts
Logins belonging to people who left, accounts unused for months, and credentials with no owner. Cross-referenced against the query trail, so "unused" means genuinely unused.
A patched database
on an open port is still exposed
Network posture is where most database breaches actually start. These checks run on the same schedule and land in the same findings list as the engine-level ones.
Exposed listeners and open ports
Which database ports are reachable, from where, and whether that matches what your architecture documents claim. Findings name the source segment, not just the port.
Unexpected network reachability
A production database answering from a guest VLAN or a build network is a finding regardless of how well patched it is. We compare observed reachability against the documented baseline.
TLS, cipher, and certificate checks
Protocol versions and cipher suites in active use, self-signed and mismatched certificates, and expiry warnings with enough lead time to renew before the outage.
Credentialed and uncredentialed scanning
Uncredentialed scans show what an attacker on the network sees. Credentialed scans go deeper into configuration and privilege. Run either, or both, on independent schedules.
Listener and endpoint hardening
Listener configuration, admin endpoints, management interfaces, and cloud security-group rules that widen access beyond the intended segment.
Drift from the network baseline
An approved snapshot of the network posture, then alerts when it changes. New ingress rules are the single most common way a hardened estate quietly stops being hardened.
The expected baseline is documented innetwork requirements, and hardening guidance insecurity hardening.
The same CVE is not
the same risk twice
A critical CVE on a database holding classified cardholder data is an emergency. The identical CVE on a dev instance with synthetic data is a ticket. Standalone scanners rank both at 9.8 because they cannot tell the difference — they never did the data discovery. We did, on the same platform, so ranking accounts for it.
- Ranked by exploitability, exposure, and the classification of the data at risk
- Correlated with observed activity — a vulnerable instance seeing unusual queries escalates
- Named remediation guidance per finding, not a CVE link and a shrug
- Findings routed to the owning team through existing alert channels and SIEM forwarding
- Remediation history retained as audit evidence, with before-and-after posture scores
Scan evidence,
mapped to the requirement
Audit Trail Implementation
MUST implement audit trails to link all access to system components to each individual user.
Every finding is tied to a named instance and the individuals holding access to it, so remediation evidence links back to accountable users.
Internal Controls
Companies MUST assess and report on internal control effectiveness. REQUIRES documented evidence of controls over financial data.
Continuous posture scoring on financial systems, with documented scan history and remediation trail as control evidence.
See all 57 frameworks we map to, or have us produce the evidence pack viaAudit Evidence-as-a-Service.
Continuous, because it's already
standing next to the database
Quarterly scanning exists because scanning used to be expensive and disruptive. The collector is already connected and already read-only, so a new database gets scanned the day it is added — no scheduling ticket, no scan window, no extra credentials.
Cost
No per-asset scanner licence and no per-core fee. Adding a database adds a scan target at no marginal cost, which is why teams here scan everything instead of only what the budget covers.
Ease of use
The databases are already connected, so there is nothing to onboard. No scan credentials to provision separately, no target list to maintain, no scheduling ticket for a new instance.
Runs local
Scanning runs from the collector inside your network. Air-gapped estates get an offline CVE feed, so classified environments are scanned without an internet path.
AI that ranks by real risk
A CVSS score knows nothing about your estate. Ours weighs exploitability against what the data is classified as and what activity the instance is actually seeing — so the top of the list is the thing to fix first.
Cited by 37 of the 57 frameworks
we map
Each one below has at least one cited requirement whose evidence this capability produces. Follow any framework through to see the exact articles and why.
Find out what's exposed right now
Enter your business email and we'll scan a representative slice of your estate, then walk you through the ranked findings — including the ones your current scanner is not looking for.