Onam Security
Database Security

Are your databases encrypted, private, audited, and backed up?

The database is where the breach gets expensive.

Database Security evaluates every managed and self-hosted database across your estate — RDS, Aurora, Azure SQL, Cloud SQL, DynamoDB, Redshift, OCI DB Systems and more — against 310 cloud database posture rules plus 1,364 CIS engine-level benchmark rules.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

Nobody intends to leave a database public.

It happens because a read replica inherits a subnet group nobody reviewed, or a snapshot gets shared to make a staging refresh easier and never gets unshared, or audit logging was on in the original instance but not the one restored from backup. Each step was reasonable. The result is a production database with customer data and a path in from the internet.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Every database resource is discovered across AWS, Azure, GCP, OCI, IBM Cloud, Alibaba and Kubernetes through read-only APIs.

  2. 2

    Cloud-level posture is evaluated against 310 storage and database rules — encryption at rest and in transit, public accessibility, backup retention, deletion protection, and audit configuration.

  3. 3

    Engine-level hardening is evaluated against CIS benchmarks for the database software itself: PostgreSQL, MySQL, MariaDB, MSSQL, Oracle, IBM Db2, MongoDB and Cassandra.

  4. 4

    Database findings are joined with data classification from DSPM, so a misconfiguration on a store holding PII is ranked above the same misconfiguration on a scratch database.

  5. 5

    Identity context from CIEM shows which principals can actually connect, read, snapshot, or delete each database.

What do you actually get?

Specific outputs, measurable outcomes

Complete database inventory
managed services and self-hosted engines
Encryption coverage at rest and in transit, per instance
Public accessibility and network exposure detection
Snapshot and backup exposure
including snapshots shared outside your account
Audit logging configuration against CIS engine benchmarks
Backup retention and point-in-time recovery compliance
Privileged database account and grant review
Sensitivity-weighted ranking
databases holding regulated data ranked first
See it live

Database Security in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

Data Security — DSPM
Run Classification
847K
PII Records Found
3
Public Buckets
12
Unencrypted Stores
5
Cross-Region
Loading live data…
Know where your PII lives
847K PII records classified — public buckets and unencrypted stores flagged first
Clip length
10s
Data
Demo account
FAQ

Questions we get a lot

For cloud posture, no — everything comes from cloud control-plane APIs. Engine-level CIS benchmark evaluation is optional and uses a read-only database account you provision explicitly if you want that depth.
Ready to see it live

Ready to see Database Security in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.