Implemented controls
- JWT validation, database grants, organization-scoped RLS and guarded RPC functions for application access.
- HTTPS for the hosted website, API and collector ingest.
- Column encryption of stored connection credentials and supported AI keys using pgcrypto.
- Rate-limited collector API-key validation.
- Organization-level AI disable control and OpenRouter, OpenAI and Anthropic customer keys.
- A published vulnerability-disclosure policy and organization admin audit-log viewer.
Deployment choices
Shared managed collection and self-hosted collector software are included on Free and Pro. Dedicated managed machines are optional at £50 per machine per month. Running a collector privately still sends telemetry to the hosted service. Hosting the full platform has separate deployment and licensing requirements; it does not imply that every integrated service becomes local.
Security review
Implementation descriptions are not an independent certification. Ask for current evidence of the controls your organization requires, including infrastructure location, key management, backup protection and provider-processing terms. Contact security@mydba.dev for a questionnaire or contractual requirements.