Built to pass the questions your auditors ask.
An unsecured database is board, regulatory and brand risk wearing a server's clothes. We assess SQL Server estates for a living, and hold our own access to the same standard we hold yours — read-only by default. Deliverables reach you through our client portal — segregated per client, access-controlled at the edge, every download logged.
Where SQL Server gets exposed — and how we close it.
A security review runs read-only first: we find the gaps, rank them by real exposure, and hand you a hardening plan with the evidence behind every finding.
Access & identity
Least-privilege roles, orphaned and over-privileged logins, the shared sa account everyone forgot. Who can do what — and who actually should.
Surface & exposure
What is switched on that need not be, and what is reachable from where it should not be. We shrink the attack surface to what the workload needs.
Encryption
At rest with TDE, in transit with TLS, and column-level for the data that truly warrants it. Mapped to what the regulation requires, not gold-plated.
Patching
Cumulative-update currency and a cadence you can evidence — so 'are you patched?' has a one-word answer, with a date.
Auditing & evidence
SQL Audit, login and change tracking, and a trail your auditors will accept. Findings, not opinions.
Recoverability
A ransomware story ends at your backups. We confirm they exist, they restore, and the DR plan has actually been run.
And we hold our own access to the same bar.
We are inside sensitive estates for a living, so the way we connect, store and hand back your data is held to a standard we would expect of you. Assessments run read-only, and the client portal that handles delivery is live — built to the design below.
Read-only by default
Assessments run read-only. No writes, no production impact. You see exactly what we run.
Per-client data segregation
Each client's data sits under its own isolated path — a request ID alone will not address another client's data. Clean permissions, clean offboarding.
Access controlled at the edge
The portal sits behind Cloudflare Access. An unauthenticated request never reaches the application, and there are no local passwords in it.
Signed-URL access
Deliverables are served through application-controlled signed URLs that expire after about ten minutes — no direct storage access.
Audit logging
Every download is recorded — who took which report, and when.
Data residency
Designed to host in-region for NZ and AU clients, with the US and other regions where a contract requires it.
We don't feed your data to AI.
We use AI for our own blog and internal documentation — never inside the client-data boundary. By default your reports and monitoring never go near an AI service, and anything AI-assisted on your data would only ever happen with your explicit, opt-in agreement. Your data is never used to train anyone's model.
Master Services Agreement, insurance certificates and a completed security questionnaire are available on request.
References from enterprise clients are available under NDA. The fact that we hold them is the first answer to "can we trust you".
We slot in around your existing arrangements without disruption. Read-only by default, no agents left behind, no contest with your incumbent MSP or in-house team. We do the specialist work, hand back the evidence, and stay out of the way.
Not sure where your real exposure is?
Tell us what is going on. A senior DBA reads every message and points you at the right next step, even when that is not us.