Security by Design

NetDBA4U is built with enterprise security as a foundational principle — not an afterthought. Every component is hardened, encrypted, and auditable.

Defense in Depth

Multiple independent security layers protect your data, credentials, and infrastructure at every touchpoint.

🔐

Authentication

DUO Universal Prompt MFA enforced for all accounts. SAML 2.0 SSO with Active Directory integration (3 modes). Account lockout after failed attempts with automatic unlock.

  • DUO MFA (push, SMS, token)
  • SAML 2.0 / AD integration
  • Account lockout protection
  • Login audit trail
🔒

Encryption

AES-256-GCM for all credentials and AI chat content at rest. Transparent encryption on INSERT, automatic decryption on SELECT. TLS for all data in transit.

  • AES-256-GCM at rest
  • Transparent DB encryption
  • TLS in transit
  • Key rotation ready
🔏

Zero-Trust Access

Key-based SSH authentication only. Dedicated netdba4u OS user per target. No stored passwords. SSH commands fully audited with command-level logging.

  • SSH key auth only
  • Dedicated OS user
  • No password storage
  • Command audit trail

Session Management

Comprehensive session security with hardened cookie policies, automatic inactivity termination, server-side session management, and protection against hijacking and fixation attacks.

  • Hardened cookie policies
  • Automatic inactivity termination
  • Server-side session store
  • Anti-hijacking protections
🔑

Password Policy

Comprehensive and robust password policy with complexity enforcement, automatic rotation, history validation, and secure hashing. Configurable to align with your organizational standards.

  • Complexity enforcement
  • Automatic rotation
  • History validation
  • Secure hashing
👥

RBAC & Governance

Three-tier role system (READONLY, OPERATOR, ADMIN) with database-level restrictions. Every portal action logged. Oracle Unified Auditing integration for DDL and authentication events.

  • READONLY / OPERATOR / ADMIN
  • DB-level restrictions
  • Full action audit trail
  • Oracle Unified Auditing

OWASP-Aligned AI Governance

NetDBA4U implements the OWASP LLM Top 10 defensive patterns. Destructive workflows generated by AI (DDL, Drops, Grants, Container Switches) are trapped and queued for human approval.

All outbound cloud LLM requests pass through the Comms Sanitizer middleware, which strips topology details, masks passwords, and embeds firm "DO NOT TRAIN" restrictions to eliminate data leakage.

HITL Approval Queue Comms Sanitizer Data Air-Gap HMAC-Signed Links
🤖
Human-in-the-Loop AI Governance

Certification Roadmap

We are actively pursuing industry-recognized security certifications to meet enterprise procurement requirements.

  • ImplementedAES-256-GCM encryption for credentials and AI chat
  • ImplementedDUO MFA with Universal Prompt
  • ImplementedZero-trust SSH key-based authentication
  • ImplementedRBAC with database-level restrictions
  • ImplementedOracle Unified Auditing integration
  • ImplementedPassword history enforcement and rotation policy
  • PlannedSOC 2 Type II certification
  • PlannedISO 27001 alignment

Security Questionnaire?

Need a completed security questionnaire, architecture diagram, or penetration test report for your procurement team? We have them ready.

Request Security Docs View Architecture