PRIMATE TRACE
Home
Products
Solutions
Company
EN TH
Login
Sign Up
Back to attack surfaces
Data

Database security scanning

Where the data actually lives, checked before someone else finds a way in.

Why scan this?

Every other layer exists to protect this one. A database exposed to the internet, an account with a blank or default password, or a missing encryption setting turns any other vulnerability in your stack into a full data breach the moment it's exploited. This scan connects to your database the way an authorized admin would and checks the settings attackers specifically look for once they've found a database is reachable at all.

What you get from this scan

  • CVSS-scored findings covering access control, encryption and configuration
  • Confirmation of whether the database is reachable from outside your network
  • Account hygiene findings, such as default users, weak passwords or excess privileges
  • TLS/SSL and at-rest encryption status
  • A report suitable for a data-protection or compliance review

How this scan stays safe for your systems

  • The scan connects with the minimal privilege needed to inspect configuration; it never reads or exports your actual data rows
  • Credentials you provide are encrypted in transit and at rest, and never shown back in the UI
  • You can use a dedicated read-only account scoped just for this scan
  • No writes, schema changes, or data modification of any kind are ever performed
  • Only scan databases you own or have explicit written permission to test

What we check

Internet-exposed database instancesDefault or weak credentialsMissing encryption in transit (TLS/SSL)Missing encryption at restExcessive user privilegesOutdated database engine version

Database security scanning

Free to try. See real, CVSS-scored results in minutes.

Start scanning