MinervaDB Data Security Subscription · Americas. EMEA. APAC
Database Security Services for PostgreSQL, MySQL, SQL Server, Oracle, MongoDB, ClickHouse and Every Major Cloud DBaaS
MinervaDB database security services are a subscription for teams whose databases sit inside a SOC 2, ISO 27001, GDPR, DPDP, HIPAA, PCI DSS or RBI scope. We harden the engines, generate the evidence auditors ask for, and operate privileged access the way client CISOs expect a remote DBA firm to operate it.
Fifteen engines, one control framework, one conformance score you can put in front of procurement.
Why a subscription, not a one-off audit
Database security is a procurement problem before it is a technical one
Every enterprise deal your database estate touches now arrives with a security questionnaire. SIG, CAIQ, a bank's third-party risk template, a hospital's HIPAA addendum. The questions are not about whether your DBAs are good. They are about whether privileged access is just-in-time, whether the PostgreSQL, MySQL or SQL Server build is benchmarked against a published standard, and whether you can prove it on a dated document.
MinervaDB database security services exist to answer those questions with evidence rather than assurances. A one-off penetration test tells you what was true on a Tuesday. A subscription keeps the CIS benchmark conformance, the access reviews, the encryption inventory and the incident-response drills current across the whole audit window, which is what SOC 2 Type II and ISO 27001 surveillance actually measure.
The subscription is engine-agnostic by design. The same control catalogue is applied to PostgreSQL, MySQL, MariaDB, Microsoft SQL Server, Oracle, IBM Db2, MongoDB, SAP HANA, ClickHouse, Trino, Apache Cassandra, Redis, Valkey and Milvus, and to the managed versions of those engines on AWS, Azure, Google Cloud and vendor clouds. One score, one report, one evidence pack, however heterogeneous the estate.
What the subscription delivers every quarter
- Per-engine hardening audit mapped to CIS Benchmarks and NIST CSF 2.0, with a conformance percentage per instance
- Privileged-access review: every account, role, grant and standing credential, with a remediation diff
- Encryption, key-rotation and backup-restore evidence, including a timed restore drill
- Audit-log coverage check against SOC 2, ISO 27001 Annex A, HIPAA §164.312 and PCI DSS Requirement 10
- A versioned Database Security Posture Report (MDB-SEC series) and a pre-filled questionnaire evidence pack
- Incident-response tabletop and a review of client-notification SLAs
Tier 1
Database security services tier 1: what enterprise procurement will not pass without
Roughly eighty percent of security questionnaires are cleared by two attestations and two contractual packs. The first tier of MinervaDB database security services is scoped to exactly those, because they are the artifacts that stop a deal when they are missing.
United States procurement
SOC 2 Type II
Security, Availability and Confidentiality trust services criteria evidenced over a six-to-twelve-month observation window. We produce the database-layer control evidence (access reviews, change logs, backup tests, encryption inventory) that your auditor samples, on the cadence the observation period demands.
GCCs, EU, public sector
ISO/IEC 27001:2022
The global ISMS baseline and the layer every other framework in our database security services maps onto. Annex A controls for access, cryptography, logging, backup and supplier relationships are translated into concrete, engine-specific settings, and the Statement of Applicability gets a database annex you can defend.
European Union
GDPR Article 28 processing
Where MinervaDB database security services engineers access EU-hosted data from India, that access is a transfer. We deliver a signed Article 28 DPA with Standard Contractual Clauses and a technical-measures annex, so legal review does not stall the engagement for weeks.
India
India DPDP Act 2023 and Rules 2025
Rules notified on 13 November 2025, consent-manager provisions effective 13 November 2026, full obligations on 13 May 2027. Our database security services build the processor-side controls and a DPDP-readiness annexure for BFSI and enterprise MSAs that push fiduciary duties down to vendors.
Underwriting
Cyber liability and E&O evidence
The fourth item on every questionnaire is not a standard at all. The subscription keeps the insurer-facing control narrative current, so renewal and the largest client contract exposure are underwritten on the same facts.
Sales-cycle acceleration
Questionnaire evidence pack
A maintained SIG Lite and CAIQ response set, MSA security schedule and a database security services whitepaper, pre-filled from your live conformance data. This is what shortens a ninety-day procurement cycle into a thirty-day one.
Tier 2
Regulated-industry unlocks, added when the pipeline demands them
These frameworks are not needed by every client, but when they are needed nothing else substitutes, and most database security services on the market stop before reaching them. They are delivered as add-on scopes to the base subscription so the control base is shared and only the mapping and evidence change.
Healthcare
HIPAA Security Rule and BAA readiness
The moment a US healthcare client's database holds ePHI, the operator is a Business Associate. We map §164.312 technical safeguards (access control, audit controls, integrity, transmission security) to concrete engine configuration and produce the evidence a signable BAA depends on.
Payments, BFSI
PCI DSS v4.0.1, service-provider scope
When engineers touch a cardholder-data environment, the client needs you on its service-provider list. Our database security services scope the database segment, implement Requirements 3, 7, 8 and 10 at the engine level and prepare the SAQ D-SP or Report on Compliance evidence with your QSA.
Indian banking
RBI IT Outsourcing Directions 2023
Indian banks and NBFCs must flow the Master Direction into every material vendor, database security services included: audit and inspection rights, data-localisation posture, concentration risk, exit and transition plans. We maintain a pre-built RBI outsourcing compliance pack that most DBA vendors cannot produce.
Privacy, single audit
ISO/IEC 27701:2025 privacy management
The 2025 edition made the privacy information management system a standalone certifiable standard. Bolted onto a 27001 ISMS it answers GDPR and DPDP obligations in a single audit; we prepare the database-processing records and controls it requires.
Tier 3
Differentiators that make “most trusted” a verifiable claim
ISO 22301 business continuity
Certified continuity is what turns a follow-the-sun support story into an auditable one, and what separates database security services from a hardening checklist. We align the 24×7 operating model, restore drills and cross-region failover runbooks to ISO 22301 so the 3 a.m. page is answered by design, not by luck.
CIS Benchmarks and NIST CSF 2.0 as the delivery standard
Every hardening finding our database security services raise cites the benchmark recommendation number and the NIST CSF 2.0 subcategory it satisfies. Competitors claim expertise; a conformance report cites the control framework.
UK Cyber Essentials Plus and TISAX
For UK public-sector supply chains and automotive OEM data, respectively. Scoped on request when the pipeline justifies the assessment cost.
The controls beneath the paper
How MinervaDB secures privileged access to your databases
Certificates are the output. What auditors and client CISOs actually probe, when they assess a remote DBA firm, is the access path. This is the operating standard every MinervaDB database security services engagement runs under, and it is written into the MSA security schedule as a control rather than left as a promise.
Just-in-time, per-engagement credentials
No standing access to any client system. Credentials are issued against a ticket, scoped to the least privilege the change needs, and revoked automatically at expiry. Quarterly access reviews reconcile issued credentials to closed tickets.
MFA, SSO and session recording
Engineers authenticate through single sign-on with hardware-backed multi-factor authentication. Sessions on client systems are recorded through the client's bastion or PAM tooling, so every command is attributable to a person and a change ID.
Client-side-only work, no data egress
Diagnostics, dumps and exports stay inside your environment. Nothing is copied to MinervaDB laptops, and endpoints run MDM and DLP so the rule is enforced technically rather than by policy alone.
Background-verified engineers
Every engineer with client access is identity- and background-verified under a firm-wide standard, and named in the engagement roster your security team approves before access is granted.
Incident response with notification SLAs
A documented incident-response procedure, tested by tabletop each quarter, with client-notification timelines written into the MSA schedule and a named security contact on both sides.
No customer data in third-party AI tools
It is now a standard line item on enterprise security questionnaires. MinervaDB policy prohibits pasting customer data, schemas with data, or logs containing data into external AI services, and the control is part of the ISMS with a vendor-risk register behind it.
Engine coverage
Database security services for fifteen engines and every major cloud DBaaS
MinervaDB database security services apply the published CIS Benchmark wherever one exists and a vendor-guide-derived baseline mapped to NIST CSF 2.0 where it does not. Both paths produce the same conformance percentage, so a mixed estate reports on one scale.
| Engine | Benchmark applied | Representative controls in scope |
|---|---|---|
| PostgreSQL | CIS PostgreSQL Benchmark (per major version) | pg_hba.conf, role and grant model, ssl and scram-sha-256, pgaudit, log_connections, TDE options, pgBackRest encryption |
| MySQL / MariaDB | CIS MySQL and CIS MariaDB Benchmarks | Authentication plugins, TLS enforcement, audit plugin, keyring/TDE, binary-log encryption, ProxySQL and MaxScale access rules |
| Microsoft SQL Server | CIS SQL Server Benchmark | Surface-area configuration, TDE and Always Encrypted, SQL Audit, contained users, Always On endpoint security |
| Oracle Database | CIS Oracle Database Benchmark | Profiles and password policy, unified auditing, TDE and wallet management, Database Vault where licensed, listener hardening |
| IBM Db2 | CIS IBM Db2 Benchmark | Authentication and encryption of data in motion and at rest, native encryption, db2audit, RCAC row and column access control |
| MongoDB | CIS MongoDB Benchmark | SCRAM/x.509 authentication, role-based access, TLS, auditing, encrypted storage engine, client-side field-level encryption |
| SAP HANA | SAP HANA Security Guide (no CIS benchmark) | User and privilege model, audit policies, data volume and log encryption, HSR channel security, SQL trace hygiene |
| ClickHouse | Vendor hardening guidance mapped to NIST CSF 2.0 | RBAC and SQL-driven access control, row policies, quotas, TLS on native and HTTP ports, query_log and session_log audit retention |
| Apache Cassandra | CIS Apache Cassandra Benchmark | Authenticator and authorizer, role hierarchy, inter-node and client TLS, audit logging, JMX lockdown |
| Redis / Valkey | Vendor hardening guidance mapped to NIST CSF 2.0 | ACL users and command allow-lists, TLS, protected mode, renamed dangerous commands, replication auth |
| Trino | Vendor hardening guidance mapped to NIST CSF 2.0 | Authentication providers, system and connector access control, TLS/JWT, query event listeners for audit |
| Milvus | Vendor hardening guidance mapped to NIST CSF 2.0 | RBAC, TLS, tenant isolation, object-storage credentials and rotation |
| Cloud DBaaS (AWS, Azure, GCP, vendor clouds) | CIS Foundations Benchmarks for AWS, Azure and GCP plus engine benchmark | IAM-to-database auth, KMS-managed keys, network paths, parameter groups, audit-log export, snapshot encryption and sharing |
Measurement, not opinion
Conformance is a number, and every finding cites its source
Each control in the MinervaDB database security services catalogue has a query, a command or a configuration read behind it, and a pass condition. The audit runs those checks against every instance in scope and computes conformance as passed weighted controls over applicable weighted controls. A control that does not apply to an engine (for example, TDE on an engine without it) is excluded from the denominator rather than counted as a failure.
The three queries below are typical of the access-review layer. They are read-only, run under a monitoring role, and their output is attached to the posture report as evidence. Nothing in the subscription writes to a production system without a change record, a verification query before and a validation query after, and a written rollback path.
Findings from the database security services audit are reported with the CIS recommendation number, the NIST CSF 2.0 subcategory (PR.AA, PR.DS, DE.CM and so on), the affected instances, the observed value, the expected value and the blast radius of the fix. Your team, or ours under the remote DBA subscription, applies the remediation in a staged, reversible sequence.
-- PostgreSQL: standing superuser and unexpired-password evidence for the quarterly access review
-- Source: pg_roles / pg_authid (rolpassword never selected); run as a monitoring role
SELECT
r.rolname AS role_name,
r.rolsuper AS is_superuser,
r.rolcreaterole AS can_create_role,
r.rolbypassrls AS bypasses_rls,
r.rolvaliduntil AS password_valid_until,
COALESCE(r.rolconnlimit, -1) AS connection_limit
FROM pg_roles AS r
WHERE r.rolcanlogin
AND (r.rolsuper OR r.rolvaliduntil IS NULL OR r.rolvaliduntil > now() + INTERVAL '90 days')
ORDER BY r.rolsuper DESC, r.rolname;
-- MySQL 8.x: accounts without an authentication plugin that enforces a password policy or with wildcard hosts
SELECT
u.user,
u.host,
u.plugin,
u.password_expired,
u.account_locked
FROM mysql.user AS u
WHERE u.host = '%'
OR u.plugin NOT IN ('caching_sha2_password', 'authentication_ldap_sasl', 'authentication_kerberos')
ORDER BY u.user, u.host;
-- SQL Server: sysadmin membership and SQL logins without policy enforcement
SELECT
sp.name AS login_name,
sp.type_desc,
sl.is_policy_checked,
sl.is_expiration_checked,
IS_SRVROLEMEMBER('sysadmin', sp.name) AS is_sysadmin
FROM sys.server_principals AS sp
LEFT JOIN sys.sql_logins AS sl
ON sl.principal_id = sp.principal_id
WHERE sp.type IN ('S', 'U', 'G')
AND sp.is_disabled = 0
ORDER BY is_sysadmin DESC, sp.name;Dates that matter
Statutory dates that shape the database security services plan
Two of the frameworks these database security services cover carry hard statutory dates, and a SOC 2 Type II report needs a full observation window behind it. The timeline below reads today's date and marks each milestone as upcoming or in force, so the position it shows is always the current one. Starting the database-layer work before the next milestone is what makes that milestone reachable.
India's DPDP Rules 2025 were notified on 13 November 2025 with a phased timeline: consent-manager provisions from 13 November 2026 and the remaining obligations, including breach notification and significant data fiduciary duties, from 13 May 2027. ISO/IEC 27701:2025 is certifiable on its own. PCI DSS v4.0.1 supersedes v4.0, with its future-dated requirements mandatory since 31 March 2025. The CIS Benchmarks and NIST CSF 2.0 are the control references every finding is mapped to.
Subscription tiers
Scoped to the size of your estate and the regulators in your pipeline
Each database security services tier is a fixed monthly subscription with a defined instance count and framework scope. Remediation is either executed by your team from our runbooks or bundled with a MinervaDB remote DBA subscription so the same engineers who found the gap close it. Pricing is quoted against the instance inventory; ask for the rate card.
| Essentials | Regulated | Enterprise | |
|---|---|---|---|
| Scope | Up to 10 database instances, one cloud or on-premises platform | Up to 40 instances across mixed engines and clouds | Unlimited instances, multi-region, multiple regulated scopes |
| Hardening audit | Quarterly, CIS/NIST mapped, conformance score | Quarterly plus post-change re-audit | Continuous with monthly posture report |
| Privileged-access review | Quarterly | Monthly | Monthly plus JIT access operated by MinervaDB |
| Framework evidence | SOC 2 and ISO 27001 database controls | Adds GDPR Art. 28 DPA/SCC pack and DPDP annexure | Adds HIPAA/BAA, PCI DSS v4.0.1 SP scope, RBI outsourcing pack, ISO 27701 |
| Questionnaire support | Evidence pack, annual refresh | SIG Lite / CAIQ pre-filled, semi-annual refresh | Named security liaison for procurement calls and audit fieldwork |
| Incident response | Documented procedure and notification SLA | Adds annual tabletop | Adds quarterly tabletop and restore-plus-failover drill |
| Delivery | Posture report (MDB-SEC series) | Posture report plus remediation runbooks | Posture report, runbooks and executive risk brief for the board |
Frequently asked questions
Database security services: the questions procurement teams ask
Does MinervaDB claim to be SOC 2 or ISO 27001 certified?
No. This page describes the database security services MinervaDB delivers on your databases so that your organisation's SOC 2, ISO 27001, HIPAA, PCI DSS or DPDP programme has the database-layer controls and evidence it needs. MinervaDB's own certification status is stated on request and in the MSA security schedule, never implied on a web page.
Which databases are covered by the database security services subscription?
PostgreSQL, MySQL, MariaDB, Microsoft SQL Server, Oracle Database, IBM Db2, MongoDB, SAP HANA, ClickHouse, Trino, Apache Cassandra, Redis, Valkey and Milvus, on premises or on AWS, Azure, Google Cloud and vendor-managed clouds such as MongoDB Atlas, ClickHouse Cloud and Redis Cloud. Coverage for a managed service is scoped to what the provider exposes.
How is the conformance score calculated?
Each control has a check and a weight. Conformance is the weighted sum of passed controls divided by the weighted sum of applicable controls for that engine and version, expressed as a percentage per instance and rolled up per estate. Controls that do not exist on an engine are excluded rather than failed.
Do MinervaDB engineers have standing access to our databases?
No. Access is issued per engagement, scoped to a ticket, time-boxed and revoked at expiry. Sessions run through your bastion or PAM tooling and are recorded. No data is copied to MinervaDB endpoints and no customer data is entered into third-party AI tools.
Can database security services include remediation, not just findings?
Yes. Findings ship with staged, reversible remediation runbooks. Where the estate is under a MinervaDB remote DBA or managed-services contract, the same engineers apply the changes with a verification query before, a validation query after and a documented rollback path.
How do MinervaDB database security services relate to India's DPDP Act?
MinervaDB acts as a data processor for clients and, for Indian fiduciaries, the subscription includes a DPDP-readiness annexure covering processor obligations, breach-notification timelines and the controls your fiduciary duties push down into vendor contracts, timed to the 13 November 2026 and 13 May 2027 milestones.
Related MinervaDB services
Database security services are one layer of the support you already buy
The database security services subscription runs alongside the engine support and remote DBA contracts most clients already hold, so hardening findings are closed by the same on-call team that answers the pages.
Start with a baseline
Get a database security services baseline before your next questionnaire arrives
A database security services baseline audit takes two to three weeks for a typical estate and produces the first posture report, the gap list against the frameworks in your pipeline and a dated remediation plan. It is the natural first month of the subscription and the fastest way to find out where you already stand.
Standing advice on every MinervaDB engagement: test each control change in a non-production environment before applying it to production, and maintain a verified backup and DR posture throughout.