Get advice
Security & trust

Built to pass the questions your auditors ask.

An unsecured database is board, regulatory and brand risk wearing a server's clothes. We assess SQL Server estates for a living, and hold our own access to the same standard we hold yours — read-only by default. Deliverables reach you through our client portal — segregated per client, access-controlled at the edge, every download logged.

Ask for the security pack, and we will send it
What we review and harden

Where SQL Server gets exposed — and how we close it.

A security review runs read-only first: we find the gaps, rank them by real exposure, and hand you a hardening plan with the evidence behind every finding.

Access & identity

Least-privilege roles, orphaned and over-privileged logins, the shared sa account everyone forgot. Who can do what — and who actually should.

Surface & exposure

What is switched on that need not be, and what is reachable from where it should not be. We shrink the attack surface to what the workload needs.

Encryption

At rest with TDE, in transit with TLS, and column-level for the data that truly warrants it. Mapped to what the regulation requires, not gold-plated.

Patching

Cumulative-update currency and a cadence you can evidence — so 'are you patched?' has a one-word answer, with a date.

Auditing & evidence

SQL Audit, login and change tracking, and a trail your auditors will accept. Findings, not opinions.

Recoverability

A ransomware story ends at your backups. We confirm they exist, they restore, and the DR plan has actually been run.

How we hold access

And we hold our own access to the same bar.

We are inside sensitive estates for a living, so the way we connect, store and hand back your data is held to a standard we would expect of you. Assessments run read-only, and the client portal that handles delivery is live — built to the design below.

Read-only by default

Assessments run read-only. No writes, no production impact. You see exactly what we run.

Per-client data segregation

Each client's data sits under its own isolated path — a request ID alone will not address another client's data. Clean permissions, clean offboarding.

Access controlled at the edge

The portal sits behind Cloudflare Access. An unauthenticated request never reaches the application, and there are no local passwords in it.

Signed-URL access

Deliverables are served through application-controlled signed URLs that expire after about ten minutes — no direct storage access.

Audit logging

Every download is recorded — who took which report, and when.

Data residency

Designed to host in-region for NZ and AU clients, with the US and other regions where a contract requires it.

Your data stays yours

We don't feed your data to AI.

We use AI for our own blog and internal documentation — never inside the client-data boundary. By default your reports and monitoring never go near an AI service, and anything AI-assisted on your data would only ever happen with your explicit, opt-in agreement. Your data is never used to train anyone's model.

Aligned to the frameworks auditors use
NZ Privacy Act 2020POPIA (South Africa)ISO 27001 controlsCIS SQL Server BenchmarkEssential Eight

Master Services Agreement, insurance certificates and a completed security questionnaire are available on request.

NZ · AU · ZA · USenterprise-scale estates under our care
Read-onlydefault posture, no production impact
ISO 27001controls we align to
References from enterprise clients are available under NDA. The fact that we hold them is the first answer to "can we trust you".

We slot in around your existing arrangements without disruption. Read-only by default, no agents left behind, no contest with your incumbent MSP or in-house team. We do the specialist work, hand back the evidence, and stay out of the way.

Not sure where your real exposure is?

Tell us what is going on. A senior DBA reads every message and points you at the right next step, even when that is not us.

Get pointed in the right direction Book a free 30-minute chat