Network exposure
Whether the server is reachable beyond the hosts that need it, and how listen and firewall settings are configured.
Technology Security
PostgreSQL is trusted with the data that matters, and its security rests on a small set of decisions — who can connect, how they authenticate, what their role can do, and whether the connection is encrypted.
PostgreSQL gives you precise control over access — and that precision is exactly what gets misconfigured. Host-based authentication rules that are too permissive, roles that carry more than they need, superuser handed out for convenience, and connections left unencrypted are the recurring themes.
We assess who can reach the server, how the authentication rules are written, what each role can actually do, and whether transport is encrypted — then hand back a hardening plan ordered by how directly each item leads to data loss.
Coverage
The decisions that determine whether the database is defensible.
Whether the server is reachable beyond the hosts that need it, and how listen and firewall settings are configured.
The rules that decide who may connect and how — the most consequential and most misconfigured control.
Least-privilege review across roles, and application accounts that carry more than they should.
Who holds superuser and whether they need it.
Whether connections require TLS, or credentials and data cross the network in clear text.
Extensions and defaults that widen what a foothold can do.
End-of-life or unpatched versions with known vulnerabilities.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Who can reach and authenticate to the database, and what each role can do.
The grants and superuser assignments to remove.
Authentication rules, TLS enforcement and safe defaults.
Confirmation each change closed the finding.
How we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
Yes. It is read-only and non-disruptive; we never modify or delete data, and active checks stay within the agreed scope.
Overly permissive host-based authentication combined with a network path that should not exist — together they let someone connect who never should have been able to. Over-privileged roles are a close second.
It helps for the deepest review of roles and settings, but is not required. Without it we assess exposure and authentication externally; with a suitable account we review privileges and configuration directly.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.