The first paid engagement
PostgreSQL database audit
Two days of work, after which you know what threatens your database, in what order to fix it and what it will cost. The report stays with you whether or not we work together afterwards.
What we examine
Six areas. We do not guess. We collect data from the running system and compare it with how the database is actually used at your site.
Engine configuration
Memory, connection limits, autovacuum, durability settings. We check whether they match your hardware and load, or whether they are left over from the default install.
Backups and restores
What exactly is copied, where it lives, how long it is kept and whether anyone has ever restored a database from it. This is the most common place where something does not add up.
Performance
The most expensive queries, missing and redundant indexes, table bloat, locks. We name specific queries rather than recommending more memory in general.
Access and privileges
Who has access, with what rights and from where. Service accounts, passwords in configuration files, privileges broader than the work requires.
Network exposure
Whether the database answers only where it should. We check this from the outside, because firewall rules can show something different from the actual state.
Version and life cycle
How long your version will be supported, what changes in the next ones, and what the upgrade path looks like given your acceptable downtime.
What you receive
A document you can put in front of the board, and which both the director and the administrator will understand.
Risks ranked by weight
Each risk described by its consequence, not by a parameter name. Not "autovacuum runs too rarely", but what will happen and when if you leave it alone.
Recommended order
What to fix this week, what this quarter, and what you can knowingly leave. We rank by consequence and cost, not by how easy something is to do.
Effort estimates
How many hours each item takes. That lets you decide what we do and what your own team does.
Answers for your auditor
Encryption, log retention and access described so that it can go straight into your compliance documentation.
What we do not do during an audit
We change nothing in production. Every change requires your separate written consent.
We do not need access to patient personal data. We work on configuration, statistics and query plans.
We do not enter the environment before a data processing agreement is signed.
We do not tie the report to further work. You may act on it yourself or hand it to somebody else.
Before you order an audit, let us talk
Thirty minutes is enough to say whether an audit makes sense for you at all, or whether the problem lies elsewhere.