Vyrell
Full visibility into database activity across ten engines: threat detection, compliance reporting, and an audit trail that survives inspection. Nothing installed on your production databases.
Vyrell is an agentless database activity monitoring platform. It gives security and compliance teams full visibility into database activity across ten engines — threat detection, 215 built-in rules, compliance reporting for 21 frameworks, and a tamper-evident audit trail — with nothing installed on the production databases.

What Vyrell does
Oracle, MySQL and MariaDB, PostgreSQL, MSSQL, MongoDB, Cassandra, Db2, Sybase ASE, Couchbase, and Firebird.
Pre-built detection for privileged access, policy violation, and suspicious activity, evaluated against every event.
PCI-DSS, HIPAA, SOX, GDPR, NIST 800-53, ISO 27001, SOC 2, and fourteen more.
A read-only audit account per target. No software on the production database.
Email, webhooks, SIEM forwarding, and in-app notification, routed by severity.
Users, hosts, IPs, and applications scored against their own baselines with peer-group comparison.
26 guideline rules in the policy library, with a matching report in the reporting engine.
SHA-256 hash-chained, insert-only, with a daily verifier for chain breaks and sequence gaps.
Column and table scanning classifies PII, health, and payment data, then proposes masking policies.
Scheduled scans match monitored engine versions against published CVE data.
TOTP on by default, LDAP sign-on, group-to-role mapping, progressive lockout.
A timed-out query marks its report incomplete with no score, rather than rendering a pass.
Engines covered
The Sybase ASE and Cassandra connectors are built, but not yet supported on Kubernetes deployments. Eight engines feed our live demo estate today.
Access and control
TOTP is on for every account, with LDAP directory sign-on, group-to-role mapping, and progressive lockout.
One console for the whole estate, with each operator’s permissions scoped to what they are allowed to see.
Email, webhooks, SIEM forwarding, and in-app notification, routed by severity.
What does Vyrell monitor, and how?
Vyrell watches database activity across ten engines — Oracle, MySQL and MariaDB, PostgreSQL, SQL Server, MongoDB, Cassandra, Db2, Sybase ASE, Couchbase, and Firebird — by reading each engine's native audit facility through a read-only account. Nothing is installed on the production database.
Which compliance frameworks does Vyrell cover?
Twenty-one framework rule-packs ship in the policy library — including PCI-DSS, HIPAA, SOX, GDPR, ISO 27001, and the Bangladesh Bank ICT Security Guideline v4.0 (26 rules) — each with a matching report in the reporting engine.
How long does Vyrell take to deploy?
One to two days. Because it is agentless — a read-only audit account per target — there is no software to roll out on the production databases.
How is Vyrell different from a traditional DAM appliance?
There is no inline appliance and no agent on the database, so Vyrell adds no chokepoint in the data path. It reads each engine's native audit stream through a read-only account, and its audit trail is SHA-256 hash-chained and insert-only, with a daily verifier for chain breaks and sequence gaps.
Does Vyrell use machine learning?
No. Its behaviour analytics score users, hosts, IPs, and applications against their own statistical baselines with peer-group comparison — a statistical engine, not a machine-learning model.