Enya Security
Request an audit
SERVICE

Database
security audit

Identify vulnerabilities in your MySQL, PostgreSQL, MariaDB or MongoDB databases through a non-intrusive technical audit, carried out remotely.

Non-intrusive
read-only access
Clear report
you can act on
100% remote
no downtime
Rigorous
methodology
Request a quote
Response within 24-48 business hours

WHY THIS SERVICE?

Your databases are a strategic target for attackers.

They hold your most sensitive information: customer records, personal data, credentials, financial data.

A misconfiguration, an overly permissive access rule or a missing backup can have serious consequences: data breach, business interruption, financial loss and reputational damage.

Our audit helps you find these weaknesses before someone else exploits them.

100+ targeted, field-tested technical checks
Risk score so you know what to fix first
Report in 5 to 10 days depending on the tier
Confidentiality data handled under a signed NDA

WHAT WE CHECK

User accounts Access, privileges and authentication
Access rights Least privilege and role design
Backups Existence, storage and restore testing
Encryption Data in transit and at rest
Logging Access logs and anomaly detection
Versions Network exposure, ports and patching

OUR APPROACH IN 4 STEPS

1

Qualification

We talk through your environment and what matters to you.

2

Technical audit

We run the checks read-only, with no impact on your operations.

3

Report

You receive a clear report with a risk score and prioritised recommendations.

4

Debrief

We walk you through the findings and help you decide what to do next.

WHAT YOU GET

  • Detailed PDF audit report
  • Overall risk score
  • Findings ranked by priority

    P1 (within 48h), P2 (2 weeks), P3 (this quarter)

  • Technical and organisational recommendations
  • Debrief call

    30 min (Standard) · 45 min (Premium)

  • Costed action plan

    Included in Premium

  • Post-remediation verification

    Included in Premium

WHY ENYA SECURITY?

  • Complete independence

    No partnership with any software vendor — and no remediation to sell you afterwards.

  • Focused expertise

    A tested methodology built for small and medium-sized organisations.

  • Clarity over jargon

    A report a business owner and their team can actually read.

  • Flexibility

    Fully remote engagements, with no interruption to your business.

  • Transparency

    Fixed fees, no surprises.

FREQUENTLY ASKED QUESTIONS

How long does an audit take?

Actual working time varies by tier: around 9 hours for Express, 13 hours for Standard, 14 to 16 hours for Premium. Report delivery is within 5, 7 and 10 business days respectively.

Do we need to pause production during the audit?

No. The audit is entirely non-intrusive: it runs read-only (SELECT, SHOW, DESCRIBE queries and the like), with no changes to your data and no service interruption.

Do you need administrator access?

No. A read-only account limited to the scope set out in the Rules of Engagement — signed before any work begins — is enough to carry out the audit.

Do you work remotely only?

Yes. Every engagement is delivered remotely, so no travel is required on either side.

Is my data kept confidential?

Yes. A non-disclosure agreement is signed before any technical access. Your credentials are destroyed immediately after the report is delivered, and other collected data (technical output, notes) within 30 days. More detail in our privacy policy.

Want to know how secure your database really is?

Tell us about your setup and get a tailored quote in under 48 hours.

Request a quote Response within 24-48 business hours