Blog

Notes from the data layer

Practitioner notes on database security, regulatory compliance, and sovereign infrastructure — grounded in what our products actually do, with no fabricated claims.

Database securitySIEMMonitoring

DAM vs SIEM: why a SIEM is not database monitoring

A SIEM gives you estate-wide correlation, but it does not understand the database. How database activity monitoring differs, why the two are complementary, and why compliance forces the distinction.

August 26, 2026 · 5 min read
KubernetesCIS BenchmarkCompliance

Turning the CIS Kubernetes Benchmark into an evidence pack

A benchmark scan is a snapshot; an auditor wants continuous, tamper-evident evidence mapped to frameworks. The difference between running the CIS Kubernetes Benchmark and producing an evidence pack.

August 23, 2026 · 5 min read
Managed databasesKubernetesData sovereignty

When to self-host your managed databases: a decision framework

A framework for regulated teams choosing between a public-cloud managed database and running their own: residency, isolation you can demonstrate, day-two operations, and the honest tradeoffs.

August 16, 2026 · 5 min read
ComplianceISO 27001Governance

ISO 27001 for banks: what certification actually requires

ISO/IEC 27001 is a risk-based management system, not a checklist. What certification really involves, where your databases fit, and why it is not the same as SOC 2, from a company that holds it.

August 9, 2026 · 6 min read