Built for Sovereignty. Designed for Choice.

Every deployment option, connectivity model, and security layer is architected to keep you in control of your data, your network, and your operations.

Two Ways to Run NetDBA4U

Full on-premise sovereignty or managed SaaS through an encrypted VPN tunnel. You choose. Your databases never move either way.

Self-Hosted

Deploy the entire platform on your infrastructure. The portal, the repository database, and all background agents run inside your network. You choose where AI runs — local Ollama on your own GPU hardware, or cloud AI with your own API keys (BYOK).

Air-Gapped Capable No External Dependencies Full Data Custody Local AI (Your Hardware) Cloud AI BYOK
Customer Data Center / Cloud VPC
Portal PostgreSQL Ollama AI
Oracle PostgreSQL MongoDB MySQL SQL Server
All data stays inside your network perimeter.

VPN-Tunnel SaaS

We host the portal. You host your databases. An encrypted VPN tunnel connects the two. AI runs on cloud providers (Gemini, OpenAI, Kimi) with managed API pooling — fast, GPU-backed responses without hardware investment. Your databases never leave your network.

No Inbound Firewall Rules Three VPN Technologies Managed Cloud AI Zero Customer DB Migration
NetDBA4U Hosted Infrastructure
Portal PostgreSQL Ollama AI
┌───────────────────┐
│ Encrypted VPN Tunnel │
│ WG / IPsec / OpenConn │
└───────────────────┘
Customer Premises / Cloud VPC
Oracle PostgreSQL MongoDB
Your databases never leave your network.

Three VPN Technologies. One Platform.

Other SaaS platforms dictate how you connect. We offer three options because every network is different.

WireGuard

The Modern Default

Fast, crypto-agile, and simple. For teams running cloud-native infrastructure who need performance without complexity.

  • UDP 51820
  • Curve25519 / ChaCha20-Poly1305
  • Kernel-level throughput
  • Single keypair setup
  • Ideal for AWS/Azure/GCP VPCs
🌎
OpenConnect

The Corporate Survivor

Runs over TCP 443. Works through HTTP proxies, captive portals, and the most restrictive corporate firewalls. If HTTPS works, this works.

  • TCP 443 (same as HTTPS)
  • HTTP CONNECT proxy support
  • Cisco AnyConnect compatible
  • Split-tunnel routing
  • Works on guest WiFi

Your Databases Stay Put. Our Intelligence Reaches In.

Traditional SaaS monitoring platforms require an agent on your database host that streams telemetry outward. Query text, execution plans, schema metadata, and metrics all flow to the vendor's cloud. The volume is massive and continuous.

NetDBA4U's VPN-Tunnel SaaS inverts that model. The portal lives on our infrastructure but connects to your databases through an encrypted tunnel. Your tables, rows, and query results never leave your network. Only diagnostic metadata necessary for incident response is stored in the portal repository — a fraction of what traditional platforms collect.

No Telemetry Streaming Incident-Driven Collection Customer-Controlled Retention AES-256-GCM at Rest
Traditional SaaS Model
Your DB Vendor Cloud Vendor AI
Query text, plans, metrics stream outward continuously.
NetDBA4U VPN-Tunnel Model
Portal + AI VPN Your DB
Portal reaches in for live queries. Data does not stream out.

Defense in Depth

Eight independent security layers protect your data, credentials, and infrastructure at every touchpoint.

1

Transport Encryption

WireGuard (Curve25519/ChaCha20), IPsec IKEv2 (AES-256-GCM), and OpenConnect TLS 1.3. Every tunnel is cryptographically hardened.

2

Data at Rest

AES-256-GCM encryption for credentials, AI chat sessions, and sensitive incident fields. Transparent encrypt-on-write, decrypt-on-read.

3

Authentication

Local secure hashing, Active Directory (3 modes), SAML 2.0 SSO, and DUO Universal Prompt MFA. Account lockout with automatic unlock.

4

Zero-Trust Access

SSH key-based authentication only. Dedicated OS user per target. No passwords stored. Oracle BEQ and Wallet support for privileged access.

5

RBAC & Governance

READONLY, OPERATOR, and ADMIN roles with database-level restrictions. Fail-closed design. Every action logged to Oracle Unified Auditing.

6

Session Security

Comprehensive session security with hardened cookie policies, automatic inactivity termination, and server-side session management with cleanup.

7

AI Safety Architecture

OWASP-aligned LLM defenses. Comms Sanitizer strips topology and masks passwords. Destructive DDL trapped. HITL approval required.

8

Password Policy

Comprehensive and robust password policy with complexity enforcement, automatic rotation, and secure hashing. Configurable to align with your organizational standards.

The Only AI Platform That Asks Before It Acts

Every AI-generated destructive command is trapped, queued, and requires explicit human approval via cryptographically signed email links or the web dashboard.

Anomaly Detected
🤖
AI Diagnosis
🔐
OWASP Check
📩
Admin Approval
Execution
Resolution

Safe commands execute immediately. Destructive commands (DROP, TRUNCATE, SHUTDOWN, KILL SESSION) are trapped and queued. The admin receives an HMAC-signed email with Approve / Deny / Regenerate options. Every step is logged.

What Stays Where

An honest inventory of what resides in your network versus what is stored in the portal repository.

Query Result Rows

When you run SELECT * FROM employees, result rows stream to your browser through the tunnel and are discarded from memory. No result data is persisted in the portal repository.

Database Backups

RMAN, PostgreSQL, MySQL, and MongoDB backups are orchestrated by the platform but stored entirely on customer infrastructure. Backup files never traverse the VPN tunnel.

SSH Private Keys & Passwords

SSH authentication uses key-based auth only. Private keys remain on customer hosts. Database passwords are encrypted with AES-256-GCM and never exposed in logs.

Incident Diagnostic Metadata

Incident titles, descriptions, and HTML performance reports are stored in the portal PostgreSQL repository. These contain truncated SQL snippets (up to 150 characters), wait events, and segment names — not query results.

AI Workbench Sessions

Chat messages are stored for session continuity. Self-hosted: Local AI processes everything on your hardware; chat history stays in your PostgreSQL repository. SaaS: Chat prompts are sent to managed cloud AI (Gemini/OpenAI) through the Comms Sanitizer. Chat history is stored in the hosted PostgreSQL repository. Encrypted at rest in both cases.

AI-Generated Remediation Scripts

Commands proposed by the Triage Agent and Sentinel AI are stored in the approval queue. These include SQL fixes, bash commands, and DDL statements awaiting human approval.

Self-Hosted Eliminates All Third-Party Custody

If your compliance framework (HIPAA, SOX, PCI-DSS) requires zero third-party data access, the self-hosted deployment places the entire portal repository under your direct control.

AI Where It Makes Sense

Self-hosted deployments can run Ollama locally on your own GPU hardware for complete air-gapped AI, or use cloud AI with your own API keys (BYOK). You control the hardware, the models, and the data flow.

SaaS deployments use managed cloud AI (Gemini, OpenAI, Kimi) with pooled, metered API keys. This delivers fast, GPU-backed responses without requiring you to provision AI hardware. All outbound requests pass through the Comms Sanitizer: topology details are stripped, passwords are masked, and "DO NOT TRAIN" restrictions are embedded.

Self-Hosted: Local AI or BYOK SaaS: Managed Cloud AI Comms Sanitizer Single Toggle Control
Self-Hosted: Local AI (Air-Gapped)
User Query Ollama (Local GPU) AI Response
No internet required. Zero external data exposure. Customer provides GPU.
Self-Hosted: Cloud AI (BYOK)
User Query Sanitizer Gemini/OpenAI/Kimi
Customer's own API key. Customer controls spend and data.
SaaS: Managed Cloud AI (Pooled)
User Query Sanitizer Managed Gemini/OpenAI
Fast GPU-backed responses. Metered, pooled API access. No hardware needed.

Architecture Questions?

Need a security questionnaire, architecture diagram, or deployment guide for your procurement team? We have them ready.

Request Architecture Docs