1. Access to your environment
- Every engineer connects with a personal, named account. We do not use shared or generic logins, and we ask you not to create them for us.
- Connections run over your VPN, a jump host you control, or our hardened gateway, always encrypted with TLS. Multi-factor authentication is required on every path.
- Monitoring uses a dedicated login with
VIEW SERVER STATEand read access to backup and job history. It cannot read the data in your tables. - Interventions use a separate DBA account with only the rights the agreed scope needs. Sysadmin rights are requested explicitly and can be time-limited.
- Access is reviewed with you at each quarterly review and withdrawn on the day an engagement ends. You receive a list of the accounts to remove.
2. What our monitoring collects
The monitoring platform collects technical telemetry: instance and database names, configuration, wait statistics, performance counters, blocking and deadlock graphs, Agent job outcomes, backup history, error-log entries and capacity figures. It does not copy business data from your tables. A deadlock graph or a slow query text may contain literal values from an application; these are stored encrypted, kept only as long as the monitoring contract runs plus 90 days, and can be excluded on request.
Telemetry and our own systems are hosted in Microsoft Azure data centres inside the European Union. Backups of our platform are encrypted and tested.
3. How changes are made
- No change on a production system without a logged reason: an alert, a ticket or an agreed plan.
- Changes are scripted, peer-reviewed where the risk warrants it, and executed inside the maintenance windows agreed with you. Every script has a rollback path.
- Emergency mitigation during an incident is allowed within the scope of your package and is reported to you the next morning with what was changed and why.
- We keep a change log per customer that you can request at any time.
4. Our people
Everyone who works on customer environments is bound by a confidentiality agreement and by your NDA where you require one. Engineers work from managed devices with disk encryption, screen lock and endpoint protection. Customer credentials are stored in a password manager with per-customer vaults, never in documents, e-mail or chat.
5. Incident response
- A security incident that affects your environment or your data is reported to your named contact within 24 hours of confirmation, with what we know, what we have done and what we recommend.
- Where DatabaseOnline acts as your processor under a data processing agreement, we support your 72-hour notification duty towards the Autoriteit Persoonsgegevens with the technical facts you need.
- Our own platform is monitored around the clock by the same team that monitors yours.
6. Supporting your compliance
We do not hold a certification of our own. We do support customer audits under ISO 27001, NEN 7510, SOC 2, GDPR and sector regulations by providing evidence: access lists, change logs, backup and restore test reports, and the data processing agreement. Where your policy requires it, we work under your procedures rather than ours.
7. Responsible disclosure
If you have found a vulnerability in this website, in one of our products or in our platform, we would like to hear from you before anyone else does.
- Report it to danny.riebeek@databaseonline.nl with the subject "Responsible disclosure", including the steps to reproduce.
- We confirm receipt within 3 business days, keep you informed of progress and tell you when the issue is fixed.
- Please do not access, change or delete data that is not yours, do not disrupt our services, and do not share the vulnerability with others until we have fixed it.
- If you follow these rules we will not take legal action against you and, if you wish, we will credit you when we publish the fix.
8. Questions from your security team
Supplier questionnaires and detailed questions about our practices can be sent to danny.riebeek@databaseonline.nl. We answer them ourselves, in technical detail, usually within a week.