FOCTTA DetectionCheck every queryPostgreSQL gateway

A decision on every query to sensitive data, before it runs.

FOCTTA Detection checks every query to sensitive data before it runs, inside the database connection, and allows, masks, challenges or blocks it. (DDRDDR (Data Detection and Response): Software that checks each data request as it happens and allows, masks or blocks it, then responds to threats. - data detection and response) Then it runs the response playbook and drafts the regulator notification. Your application only changes its connection string.

AllowMaskAlertStep-upBreak-glassQuarantineBlock
ALLOW SELECT plan, city FROM customers no identifiers
MASK SELECT name, pan FROM customers pan masked
BLOCK SELECT * FROM kyc_documents name the columns · BLK-7F2C
STEP-UP SELECT * FROM ledger LIMIT 500000 10x normal volume
BLOCK SELECT dob, guardian FROM students children's data
MASK SELECT email, phone FROM leads phone masked
ALLOW SELECT sku, stock FROM inventory no personal data
BLOCK COPY customers TO STDOUT mass export
ALLOW SELECT plan, city FROM customers no identifiers
MASK SELECT name, pan FROM customers pan masked
BLOCK SELECT * FROM kyc_documents name the columns · BLK-7F2C
STEP-UP SELECT * FROM ledger LIMIT 500000 10x normal volume
BLOCK SELECT dob, guardian FROM students children's data
MASK SELECT email, phone FROM leads phone masked
ALLOW SELECT sku, stock FROM inventory no personal data
BLOCK COPY customers TO STDOUT mass export
How it works
  1. Point your application at the gateway
  2. Each query is checked against your rules
  3. Allowed, masked, challenged or blocked

The gateway decides. The database does the masking.

Hover or tap a card for detail. The gateway speaks the PostgreSQL protocol today.

41 built-in rules

Rules for Indian data, Indian banks and Indian law.

Core data security · 11 rules
Aadhaar outside a vault
Section 9 minor data without guardian consent
Cross-border personal data without safeguards
Publicly exposed personal data
Orphan personal data
Mass export by a privileged user
Mass export over a time window
Audit logging disabled
Consent-failed queries
Purpose drift
Schema-mapping reconnaissance
SIEM and SOARSIEM and SOAR: The security team's tools: SIEM collects and alerts on security events; SOAR runs automated responses.
29 targets, with native delivery to Microsoft Sentinel, Splunk and CEF syslog. Automatic push on the roadmapToday: test sends, a history per target, audit forwarding.
Named targetsSplunkMicrosoft SentinelIBM QRadarElasticSumo LogicSecuronixExabeamLogRhythmGoogle ChronicleDatadogCortex XSOARServiceNow SecOpsTinesWebhookCEF syslogKafka