How we work securely
We hold the keys to your databases. This is how we handle them.
A DBA-for-hire with access to production is a supplier your security team should question. These are the answers to the questions we get asked most.
1. Access to your environment
- Every engineer connects with a personal, named account that you create. We do not use shared or generic logins, and we ask you not to create them for us.
- Connections run over your VPN, a jump host you control, or our hardened gateway, always encrypted with TLS. Multi-factor authentication is required on every path.
- Rights follow the agreed scope. Sysadmin rights are requested explicitly, can be time-limited, and are withdrawn on the day an engagement ends. You receive a list of the accounts to remove.
- Where we monitor, the monitoring login has
VIEW SERVER STATEand read access to backup and job history. It cannot read the data in your tables.
2. How changes are made
- No change on a production system without a logged reason: an alert, a ticket or an agreed plan.
- Changes are scripted, reviewed where the risk warrants it, and executed inside the maintenance windows agreed with you. Every script has a rollback path.
- Emergency mitigation during an incident is allowed within the agreed scope and is reported to you the next morning: what was changed and why.
3. Our people
Everyone who works on customer environments is bound by a confidentiality agreement and by your NDA where you require one. Engineers work from managed devices with disk encryption, screen lock and endpoint protection. Customer credentials are stored in a password manager with per-customer vaults, never in documents, e-mail or chat.
4. Incident response and data processing
- A security incident that affects your environment or your data is reported to your named contact within 24 hours of confirmation, with what we know, what we have done and what we recommend.
- When we process personal data on your behalf we act as your processor under a data processing agreement (verwerkersovereenkomst) and support your 72-hour notification duty towards the Autoriteit Persoonsgegevens with the technical facts you need.
- Our own systems are hosted in Microsoft Azure data centres in the European Union.
5. Supporting your compliance
We do not hold a certification of our own. We do support customer audits under ISO 27001, NEN 7510, SOC 2, GDPR and sector regulations by providing evidence: access lists, change logs, backup and restore test reports and the data processing agreement. Where your policy requires it, we work under your procedures rather than ours.
6. Responsible disclosure
If you have found a vulnerability in this website or in our systems, report it to danny.riebeek@databaseonline.nl with the subject "Responsible disclosure" and the steps to reproduce. We confirm receipt within three business days, keep you informed, and do not take legal action against researchers who act in good faith.