LiveFlagship product

Vyrell

Database activity monitoring

Full visibility into database activity across ten engines: threat detection, compliance reporting, and an audit trail that survives inspection. Nothing installed on your production databases.

ISO/IEC 27001:2022 · ISO 9001:2015 — certifications

Vyrell is an agentless database activity monitoring platform. It gives security and compliance teams full visibility into database activity across ten engines — threat detection, 215 built-in rules, compliance reporting for 21 frameworks, and a tamper-evident audit trail — with nothing installed on the production databases.

Vyrell data classification screen: 95 columns classified, classification patterns for SSN, email, phone, credit card and CVV with confidence scores.
Vyrell / Analytics / Data classification, sensitive-column discovery with proposed masking policies.
01

What Vyrell does

Ten database engines

Oracle, MySQL and MariaDB, PostgreSQL, MSSQL, MongoDB, Cassandra, Db2, Sybase ASE, Couchbase, and Firebird.

215 security rules

Pre-built detection for privileged access, policy violation, and suspicious activity, evaluated against every event.

21 compliance frameworks

PCI-DSS, HIPAA, SOX, GDPR, NIST 800-53, ISO 27001, SOC 2, and fourteen more.

Agentless deployment

A read-only audit account per target. No software on the production database.

Real-time alerting

Email, webhooks, SIEM forwarding, and in-app notification, routed by severity.

Behaviour analytics

Users, hosts, IPs, and applications scored against their own baselines with peer-group comparison.

Bangladesh Bank ICT v4.0

26 guideline rules in the policy library, with a matching report in the reporting engine.

Tamper-evident audit trail

SHA-256 hash-chained, insert-only, with a daily verifier for chain breaks and sequence gaps.

Sensitive data discovery

Column and table scanning classifies PII, health, and payment data, then proposes masking policies.

Vulnerability scanning

Scheduled scans match monitored engine versions against published CVE data.

Enforced two-factor

TOTP on by default, LDAP sign-on, group-to-role mapping, progressive lockout.

Reports that show gaps

A timed-out query marks its report incomplete with no score, rather than rendering a pass.

02

Engines covered

OracleUnified auditing
MySQL / MariaDBAudit plugin
PostgreSQLpgaudit
Microsoft SQL ServerSQL Server Audit
MongoDBAudit log
CassandraAudit logging
IBM Db2db2audit
Sybase ASENative auditing
CouchbaseAudit events
FirebirdTrace and audit

The Sybase ASE and Cassandra connectors are built, but not yet supported on Kubernetes deployments. Eight engines feed our live demo estate today.

03

Access and control

Two-factor enforced by default

TOTP is on for every account, with LDAP directory sign-on, group-to-role mapping, and progressive lockout.

Role-scoped visibility

One console for the whole estate, with each operator’s permissions scoped to what they are allowed to see.

Alerting into your stack

Email, webhooks, SIEM forwarding, and in-app notification, routed by severity.

Common questions

What does Vyrell monitor, and how?

Vyrell watches database activity across ten engines — Oracle, MySQL and MariaDB, PostgreSQL, SQL Server, MongoDB, Cassandra, Db2, Sybase ASE, Couchbase, and Firebird — by reading each engine's native audit facility through a read-only account. Nothing is installed on the production database.

Which compliance frameworks does Vyrell cover?

Twenty-one framework rule-packs ship in the policy library — including PCI-DSS, HIPAA, SOX, GDPR, ISO 27001, and the Bangladesh Bank ICT Security Guideline v4.0 (26 rules) — each with a matching report in the reporting engine.

How long does Vyrell take to deploy?

One to two days. Because it is agentless — a read-only audit account per target — there is no software to roll out on the production databases.

How is Vyrell different from a traditional DAM appliance?

There is no inline appliance and no agent on the database, so Vyrell adds no chokepoint in the data path. It reads each engine's native audit stream through a read-only account, and its audit trail is SHA-256 hash-chained and insert-only, with a daily verifier for chain breaks and sequence gaps.

Does Vyrell use machine learning?

No. Its behaviour analytics score users, hosts, IPs, and applications against their own statistical baselines with peer-group comparison — a statistical engine, not a machine-learning model.

See it against your own database estate.

Request a demo