AI DEFENCEBY ALTARI SYSTEMS
Menu

Coverage / Databases & sensitive data

Database security audits with governed remediation.

A database security audit examines who can reach data, how access is authenticated and authorised, and how data is protected and recovered. AI Defence’s intended model begins with read-only diagnostics and keeps material database changes behind explicit authorisation.

IN DEVELOPMENTExplore the specified scope. See capability availability.

Inspect access, privilege and data exposure

The specified database checks cover public and internal network exposure, authentication, encryption in transit and at rest, database privileges, superuser usage and default accounts. Weak configuration and sensitive-data exposure belong in the same contextual assessment.

Tenant or row isolation, where relevant, requires attention to application identities and the boundaries the system intends to enforce. Merely observing that an isolation feature exists does not establish that every query path applies it correctly. Available evidence and untested paths must be explained.

  • Backup and replication security, including access controls and encryption.
  • Data retention settings and audit logging.
  • Application and database credentials, machine identities and excessive scope.

A diagnostic permission is not authority to modify production

Read-only diagnostics should collect the minimum relevant evidence within agreed privacy controls. There is no need to frame the product as unrestricted AI write access to a customer’s production data. Collecting configuration or relevant metadata and authorising a migration are separate operations.

Where a finding requires a schema, query, permission or service change, the proposal needs to identify dependencies and possible impact. A privilege restriction can break an application worker; a network change can interrupt replication or backup. The report should show those consequences before approval.

Verify isolation, health and recoverability

The governed sequence is evidence, diagnosis, proposed repair, safe testing, approval, deployment and verification. The checks should cover both the original security condition and required application behaviour. Restore readiness and rollback matter when the change affects data or availability.

A backup file’s existence is not proof that it can be restored. The broader assessment includes backup frequency, integrity, off-host or off-site copies, immutability where possible and restore testing. Any recovery operation must follow the authorised environment and agreed test plan.

Questions answered

Will AI Defence modify database records during the initial audit?

The specified first-entry assessment is read-only. Material database changes need a separate, explicit approval and a governed workflow.

Does the specification guarantee support for every database?

No. Database security is part of the intended scope; engine-specific diagnostics, permissions and remediation support need confirmation for the customer’s environment.

Start with understanding

What does your environment need to defend?

Discuss the assessment scope, current capabilities and the control you need with Altari Systems.

Talk to Altari