MinervaDB Data Security Subscription · Americas. EMEA. APAC

Database Security Services for PostgreSQL, MySQL, SQL Server, Oracle, MongoDB, ClickHouse and Every Major Cloud DBaaS

MinervaDB database security services are a subscription for teams whose databases sit inside a SOC 2, ISO 27001, GDPR, DPDP, HIPAA, PCI DSS or RBI scope. We harden the engines, generate the evidence auditors ask for, and operate privileged access the way client CISOs expect a remote DBA firm to operate it.

Fifteen engines, one control framework, one conformance score you can put in front of procurement.

Why a subscription, not a one-off audit

Database security is a procurement problem before it is a technical one

Every enterprise deal your database estate touches now arrives with a security questionnaire. SIG, CAIQ, a bank's third-party risk template, a hospital's HIPAA addendum. The questions are not about whether your DBAs are good. They are about whether privileged access is just-in-time, whether the PostgreSQL, MySQL or SQL Server build is benchmarked against a published standard, and whether you can prove it on a dated document.

MinervaDB database security services exist to answer those questions with evidence rather than assurances. A one-off penetration test tells you what was true on a Tuesday. A subscription keeps the CIS benchmark conformance, the access reviews, the encryption inventory and the incident-response drills current across the whole audit window, which is what SOC 2 Type II and ISO 27001 surveillance actually measure.

The subscription is engine-agnostic by design. The same control catalogue is applied to PostgreSQL, MySQL, MariaDB, Microsoft SQL Server, Oracle, IBM Db2, MongoDB, SAP HANA, ClickHouse, Trino, Apache Cassandra, Redis, Valkey and Milvus, and to the managed versions of those engines on AWS, Azure, Google Cloud and vendor clouds. One score, one report, one evidence pack, however heterogeneous the estate.

What the subscription delivers every quarter

  • Per-engine hardening audit mapped to CIS Benchmarks and NIST CSF 2.0, with a conformance percentage per instance
  • Privileged-access review: every account, role, grant and standing credential, with a remediation diff
  • Encryption, key-rotation and backup-restore evidence, including a timed restore drill
  • Audit-log coverage check against SOC 2, ISO 27001 Annex A, HIPAA §164.312 and PCI DSS Requirement 10
  • A versioned Database Security Posture Report (MDB-SEC series) and a pre-filled questionnaire evidence pack
  • Incident-response tabletop and a review of client-notification SLAs
MinervaDB database security services: three tiers of compliance evidence built on one control base
MinervaDB database security services: three tiers of compliance evidence built on one control base

Tier 1

Database security services tier 1: what enterprise procurement will not pass without

Roughly eighty percent of security questionnaires are cleared by two attestations and two contractual packs. The first tier of MinervaDB database security services is scoped to exactly those, because they are the artifacts that stop a deal when they are missing.

United States procurement

SOC 2 Type II

Security, Availability and Confidentiality trust services criteria evidenced over a six-to-twelve-month observation window. We produce the database-layer control evidence (access reviews, change logs, backup tests, encryption inventory) that your auditor samples, on the cadence the observation period demands.

GCCs, EU, public sector

ISO/IEC 27001:2022

The global ISMS baseline and the layer every other framework in our database security services maps onto. Annex A controls for access, cryptography, logging, backup and supplier relationships are translated into concrete, engine-specific settings, and the Statement of Applicability gets a database annex you can defend.

European Union

GDPR Article 28 processing

Where MinervaDB database security services engineers access EU-hosted data from India, that access is a transfer. We deliver a signed Article 28 DPA with Standard Contractual Clauses and a technical-measures annex, so legal review does not stall the engagement for weeks.

India

India DPDP Act 2023 and Rules 2025

Rules notified on 13 November 2025, consent-manager provisions effective 13 November 2026, full obligations on 13 May 2027. Our database security services build the processor-side controls and a DPDP-readiness annexure for BFSI and enterprise MSAs that push fiduciary duties down to vendors.

Underwriting

Cyber liability and E&O evidence

The fourth item on every questionnaire is not a standard at all. The subscription keeps the insurer-facing control narrative current, so renewal and the largest client contract exposure are underwritten on the same facts.

Sales-cycle acceleration

Questionnaire evidence pack

A maintained SIG Lite and CAIQ response set, MSA security schedule and a database security services whitepaper, pre-filled from your live conformance data. This is what shortens a ninety-day procurement cycle into a thirty-day one.

Tier 2

Regulated-industry unlocks, added when the pipeline demands them

These frameworks are not needed by every client, but when they are needed nothing else substitutes, and most database security services on the market stop before reaching them. They are delivered as add-on scopes to the base subscription so the control base is shared and only the mapping and evidence change.

Healthcare

HIPAA Security Rule and BAA readiness

The moment a US healthcare client's database holds ePHI, the operator is a Business Associate. We map §164.312 technical safeguards (access control, audit controls, integrity, transmission security) to concrete engine configuration and produce the evidence a signable BAA depends on.

Payments, BFSI

PCI DSS v4.0.1, service-provider scope

When engineers touch a cardholder-data environment, the client needs you on its service-provider list. Our database security services scope the database segment, implement Requirements 3, 7, 8 and 10 at the engine level and prepare the SAQ D-SP or Report on Compliance evidence with your QSA.

Indian banking

RBI IT Outsourcing Directions 2023

Indian banks and NBFCs must flow the Master Direction into every material vendor, database security services included: audit and inspection rights, data-localisation posture, concentration risk, exit and transition plans. We maintain a pre-built RBI outsourcing compliance pack that most DBA vendors cannot produce.

Privacy, single audit

ISO/IEC 27701:2025 privacy management

The 2025 edition made the privacy information management system a standalone certifiable standard. Bolted onto a 27001 ISMS it answers GDPR and DPDP obligations in a single audit; we prepare the database-processing records and controls it requires.

Tier 3

Differentiators that make “most trusted” a verifiable claim

ISO 22301 business continuity

Certified continuity is what turns a follow-the-sun support story into an auditable one, and what separates database security services from a hardening checklist. We align the 24×7 operating model, restore drills and cross-region failover runbooks to ISO 22301 so the 3 a.m. page is answered by design, not by luck.

CIS Benchmarks and NIST CSF 2.0 as the delivery standard

Every hardening finding our database security services raise cites the benchmark recommendation number and the NIST CSF 2.0 subcategory it satisfies. Competitors claim expertise; a conformance report cites the control framework.

UK Cyber Essentials Plus and TISAX

For UK public-sector supply chains and automotive OEM data, respectively. Scoped on request when the pipeline justifies the assessment cost.

The controls beneath the paper

How MinervaDB secures privileged access to your databases

Certificates are the output. What auditors and client CISOs actually probe, when they assess a remote DBA firm, is the access path. This is the operating standard every MinervaDB database security services engagement runs under, and it is written into the MSA security schedule as a control rather than left as a promise.

MinervaDB database security services privileged-access model: just-in-time credentials, recorded sessions, no data egress
MinervaDB database security services privileged-access model: just-in-time credentials, recorded sessions, no data egress

Just-in-time, per-engagement credentials

No standing access to any client system. Credentials are issued against a ticket, scoped to the least privilege the change needs, and revoked automatically at expiry. Quarterly access reviews reconcile issued credentials to closed tickets.

MFA, SSO and session recording

Engineers authenticate through single sign-on with hardware-backed multi-factor authentication. Sessions on client systems are recorded through the client's bastion or PAM tooling, so every command is attributable to a person and a change ID.

Client-side-only work, no data egress

Diagnostics, dumps and exports stay inside your environment. Nothing is copied to MinervaDB laptops, and endpoints run MDM and DLP so the rule is enforced technically rather than by policy alone.

Background-verified engineers

Every engineer with client access is identity- and background-verified under a firm-wide standard, and named in the engagement roster your security team approves before access is granted.

Incident response with notification SLAs

A documented incident-response procedure, tested by tabletop each quarter, with client-notification timelines written into the MSA schedule and a named security contact on both sides.

No customer data in third-party AI tools

It is now a standard line item on enterprise security questionnaires. MinervaDB policy prohibits pasting customer data, schemas with data, or logs containing data into external AI services, and the control is part of the ISMS with a vendor-risk register behind it.

Engine coverage

Database security services for fifteen engines and every major cloud DBaaS

MinervaDB database security services apply the published CIS Benchmark wherever one exists and a vendor-guide-derived baseline mapped to NIST CSF 2.0 where it does not. Both paths produce the same conformance percentage, so a mixed estate reports on one scale.

EngineBenchmark appliedRepresentative controls in scope
PostgreSQLCIS PostgreSQL Benchmark (per major version)pg_hba.conf, role and grant model, ssl and scram-sha-256, pgaudit, log_connections, TDE options, pgBackRest encryption
MySQL / MariaDBCIS MySQL and CIS MariaDB BenchmarksAuthentication plugins, TLS enforcement, audit plugin, keyring/TDE, binary-log encryption, ProxySQL and MaxScale access rules
Microsoft SQL ServerCIS SQL Server BenchmarkSurface-area configuration, TDE and Always Encrypted, SQL Audit, contained users, Always On endpoint security
Oracle DatabaseCIS Oracle Database BenchmarkProfiles and password policy, unified auditing, TDE and wallet management, Database Vault where licensed, listener hardening
IBM Db2CIS IBM Db2 BenchmarkAuthentication and encryption of data in motion and at rest, native encryption, db2audit, RCAC row and column access control
MongoDBCIS MongoDB BenchmarkSCRAM/x.509 authentication, role-based access, TLS, auditing, encrypted storage engine, client-side field-level encryption
SAP HANASAP HANA Security Guide (no CIS benchmark)User and privilege model, audit policies, data volume and log encryption, HSR channel security, SQL trace hygiene
ClickHouseVendor hardening guidance mapped to NIST CSF 2.0RBAC and SQL-driven access control, row policies, quotas, TLS on native and HTTP ports, query_log and session_log audit retention
Apache CassandraCIS Apache Cassandra BenchmarkAuthenticator and authorizer, role hierarchy, inter-node and client TLS, audit logging, JMX lockdown
Redis / ValkeyVendor hardening guidance mapped to NIST CSF 2.0ACL users and command allow-lists, TLS, protected mode, renamed dangerous commands, replication auth
TrinoVendor hardening guidance mapped to NIST CSF 2.0Authentication providers, system and connector access control, TLS/JWT, query event listeners for audit
MilvusVendor hardening guidance mapped to NIST CSF 2.0RBAC, TLS, tenant isolation, object-storage credentials and rotation
Cloud DBaaS (AWS, Azure, GCP, vendor clouds)CIS Foundations Benchmarks for AWS, Azure and GCP plus engine benchmarkIAM-to-database auth, KMS-managed keys, network paths, parameter groups, audit-log export, snapshot encryption and sharing

Measurement, not opinion

Conformance is a number, and every finding cites its source

Each control in the MinervaDB database security services catalogue has a query, a command or a configuration read behind it, and a pass condition. The audit runs those checks against every instance in scope and computes conformance as passed weighted controls over applicable weighted controls. A control that does not apply to an engine (for example, TDE on an engine without it) is excluded from the denominator rather than counted as a failure.

The three queries below are typical of the access-review layer. They are read-only, run under a monitoring role, and their output is attached to the posture report as evidence. Nothing in the subscription writes to a production system without a change record, a verification query before and a validation query after, and a written rollback path.

Findings from the database security services audit are reported with the CIS recommendation number, the NIST CSF 2.0 subcategory (PR.AA, PR.DS, DE.CM and so on), the affected instances, the observed value, the expected value and the blast radius of the fix. Your team, or ours under the remote DBA subscription, applies the remediation in a staged, reversible sequence.

-- PostgreSQL: standing superuser and unexpired-password evidence for the quarterly access review
-- Source: pg_roles / pg_authid (rolpassword never selected); run as a monitoring role
SELECT
    r.rolname                                   AS role_name,
    r.rolsuper                                  AS is_superuser,
    r.rolcreaterole                             AS can_create_role,
    r.rolbypassrls                              AS bypasses_rls,
    r.rolvaliduntil                             AS password_valid_until,
    COALESCE(r.rolconnlimit, -1)                AS connection_limit
FROM pg_roles AS r
WHERE r.rolcanlogin
  AND (r.rolsuper OR r.rolvaliduntil IS NULL OR r.rolvaliduntil > now() + INTERVAL '90 days')
ORDER BY r.rolsuper DESC, r.rolname;

-- MySQL 8.x: accounts without an authentication plugin that enforces a password policy or with wildcard hosts
SELECT
    u.user,
    u.host,
    u.plugin,
    u.password_expired,
    u.account_locked
FROM mysql.user AS u
WHERE u.host = '%'
   OR u.plugin NOT IN ('caching_sha2_password', 'authentication_ldap_sasl', 'authentication_kerberos')
ORDER BY u.user, u.host;

-- SQL Server: sysadmin membership and SQL logins without policy enforcement
SELECT
    sp.name                                     AS login_name,
    sp.type_desc,
    sl.is_policy_checked,
    sl.is_expiration_checked,
    IS_SRVROLEMEMBER('sysadmin', sp.name)       AS is_sysadmin
FROM sys.server_principals AS sp
LEFT JOIN sys.sql_logins AS sl
       ON sl.principal_id = sp.principal_id
WHERE sp.type IN ('S', 'U', 'G')
  AND sp.is_disabled = 0
ORDER BY is_sysadmin DESC, sp.name;

Dates that matter

Statutory dates that shape the database security services plan

Two of the frameworks these database security services cover carry hard statutory dates, and a SOC 2 Type II report needs a full observation window behind it. The timeline below reads today's date and marks each milestone as upcoming or in force, so the position it shows is always the current one. Starting the database-layer work before the next milestone is what makes that milestone reachable.

Statutory milestones for database security services: DPDP Rules 2025 timeline with live status Statutory milestones your database security services plan has to hit 13 Nov 2025 DPDP Rules 2025 notified; Board and DPBI provisions live 13 Nov 2026 DPDP consent-manager provisions take effect 13 May 2027 Full DPDP obligations on fiduciaries and processors TODAY SOC 2 observation windows and ISO 27001 surveillance audits run continuously.PCI DSS v4.0.1 future-dated requirements mandatory since 31 March 2025; NIST CSF 2.0 published February 2024.
Statutory milestones for database security services: DPDP Rules 2025 timeline.

India's DPDP Rules 2025 were notified on 13 November 2025 with a phased timeline: consent-manager provisions from 13 November 2026 and the remaining obligations, including breach notification and significant data fiduciary duties, from 13 May 2027. ISO/IEC 27701:2025 is certifiable on its own. PCI DSS v4.0.1 supersedes v4.0, with its future-dated requirements mandatory since 31 March 2025. The CIS Benchmarks and NIST CSF 2.0 are the control references every finding is mapped to.

Subscription tiers

Scoped to the size of your estate and the regulators in your pipeline

Each database security services tier is a fixed monthly subscription with a defined instance count and framework scope. Remediation is either executed by your team from our runbooks or bundled with a MinervaDB remote DBA subscription so the same engineers who found the gap close it. Pricing is quoted against the instance inventory; ask for the rate card.

EssentialsRegulatedEnterprise
ScopeUp to 10 database instances, one cloud or on-premises platformUp to 40 instances across mixed engines and cloudsUnlimited instances, multi-region, multiple regulated scopes
Hardening auditQuarterly, CIS/NIST mapped, conformance scoreQuarterly plus post-change re-auditContinuous with monthly posture report
Privileged-access reviewQuarterlyMonthlyMonthly plus JIT access operated by MinervaDB
Framework evidenceSOC 2 and ISO 27001 database controlsAdds GDPR Art. 28 DPA/SCC pack and DPDP annexureAdds HIPAA/BAA, PCI DSS v4.0.1 SP scope, RBI outsourcing pack, ISO 27701
Questionnaire supportEvidence pack, annual refreshSIG Lite / CAIQ pre-filled, semi-annual refreshNamed security liaison for procurement calls and audit fieldwork
Incident responseDocumented procedure and notification SLAAdds annual tabletopAdds quarterly tabletop and restore-plus-failover drill
DeliveryPosture report (MDB-SEC series)Posture report plus remediation runbooksPosture report, runbooks and executive risk brief for the board

Frequently asked questions

Database security services: the questions procurement teams ask

Does MinervaDB claim to be SOC 2 or ISO 27001 certified?

No. This page describes the database security services MinervaDB delivers on your databases so that your organisation's SOC 2, ISO 27001, HIPAA, PCI DSS or DPDP programme has the database-layer controls and evidence it needs. MinervaDB's own certification status is stated on request and in the MSA security schedule, never implied on a web page.

Which databases are covered by the database security services subscription?

PostgreSQL, MySQL, MariaDB, Microsoft SQL Server, Oracle Database, IBM Db2, MongoDB, SAP HANA, ClickHouse, Trino, Apache Cassandra, Redis, Valkey and Milvus, on premises or on AWS, Azure, Google Cloud and vendor-managed clouds such as MongoDB Atlas, ClickHouse Cloud and Redis Cloud. Coverage for a managed service is scoped to what the provider exposes.

How is the conformance score calculated?

Each control has a check and a weight. Conformance is the weighted sum of passed controls divided by the weighted sum of applicable controls for that engine and version, expressed as a percentage per instance and rolled up per estate. Controls that do not exist on an engine are excluded rather than failed.

Do MinervaDB engineers have standing access to our databases?

No. Access is issued per engagement, scoped to a ticket, time-boxed and revoked at expiry. Sessions run through your bastion or PAM tooling and are recorded. No data is copied to MinervaDB endpoints and no customer data is entered into third-party AI tools.

Can database security services include remediation, not just findings?

Yes. Findings ship with staged, reversible remediation runbooks. Where the estate is under a MinervaDB remote DBA or managed-services contract, the same engineers apply the changes with a verification query before, a validation query after and a documented rollback path.

How do MinervaDB database security services relate to India's DPDP Act?

MinervaDB acts as a data processor for clients and, for Indian fiduciaries, the subscription includes a DPDP-readiness annexure covering processor obligations, breach-notification timelines and the controls your fiduciary duties push down into vendor contracts, timed to the 13 November 2026 and 13 May 2027 milestones.

Related MinervaDB services

Database security services are one layer of the support you already buy

The database security services subscription runs alongside the engine support and remote DBA contracts most clients already hold, so hardening findings are closed by the same on-call team that answers the pages.

Start with a baseline

Get a database security services baseline before your next questionnaire arrives

A database security services baseline audit takes two to three weeks for a typical estate and produces the first posture report, the gap list against the frameworks in your pipeline and a dated remediation plan. It is the natural first month of the subscription and the fastest way to find out where you already stand.

Standing advice on every MinervaDB engagement: test each control change in a non-production environment before applying it to production, and maintain a verified backup and DR posture throughout.