Patented Runtime encryption for data in use

Sensitive data stays encrypted, even after the query.

SecureDB protects PII, PHI and payment fields at the column level, so only authorized users ever see clear values — across production, warehouses, ETL and test environments.

  • No application changes
  • On-prem, cloud & hybrid
  • Minimal performance impact
View query results as
SELECT * FROM customers LIMIT 5;

Session: app_billing@prod · Role: billing

Session: etl_svc@warehouse · Role: analytics

Policy: PII-mask-v3

Sample query results
id name ssn card_number region
10041 Encrypted value:Xq7#Lm9vR2 Maria Lopez Encrypted value:k9F2·pQ8z·W1 900-14-2231 Encrypted value:a7Hx··9Lm2··Qz4 4111 1111 1111 1111 TX
10042 Encrypted value:Pz3!Hd8nT0 James Chen Encrypted value:Rt5m·Zx2c·L8 900-27-8812 Encrypted value:Bv9q··2Kd7··Wm1 5555 5555 5555 4444 CA
10043 Encrypted value:Ma6$Wq1kY4 Priya Patel Encrypted value:e3Ns·Jh7w·P2 900-38-1045 Encrypted value:Lp4z··8Tr6··Xn5 3782 822463 10005 NY
10044 Encrypted value:Gt2%Vb5jC8 David Kim Encrypted value:u8Kd·Mn1x·F6 900-41-6673 Encrypted value:Qw3e··7Yc1··Hs9 6011 1111 1111 1117 FL
10045 Encrypted value:Ry9&Fo4sE1 Sarah Olsen Encrypted value:h2Wb·Dz6q·N3 900-55-9020 Encrypted value:Zm8k··4Gv2··Jt7 4012 8888 8888 1881 WA

3 of 5 columns protected by policy

0 lines of application code changed

Access logged Audit event #A-48213

Works with the databases you already run

Persistent Data Protection

Encrypt and identify sensitive data at rest and in use.

Granular Access Control

Enforce least-privilege access with dynamic policies.

Real-Time Policy Enforcement

Detect and protect sensitive data in real time.

Comprehensive Visibility

Monitor activity with detailed audit logs and reporting.

Protect Across Your Data Ecosystem

OnData integrates at the data layer—securing data in motion and at rest across your entire ecosystem without requiring changes to applications or business processes.

  1. Data is requested by applications or users
  2. OnData intercepts and enforces security policy
  3. Data is encrypted/decrypted in real time
  4. Authorized data is returned—safely and securely

Request a Demo
Diagram of Ondata Runtime Security Layer with security features and data flow.

Database security needs to protect more than storage and
transport.

Most database environments already include important security controls. Teams encrypt storage volumes. They use encrypted connections. They manage user permissions. They secure applications. They monitor infrastructure. These are necessary controls, but they do not always protect sensitive values once authorized systems, privileged accounts or downstream workflows can access the data.

The risk increases when sensitive data moves beyond the original production system. Data may be copied into a warehouse, used in a data lake, sent through an ETL pipeline, replicated to a reporting database or exported into a staging environment. Development and quality assurance teams may need realistic data to test business applications. Analysts may need correlation across records without direct visibility into the original sensitive fields. Compliance teams may need proof that sensitive data is protected consistently across environments.

SecureDB helps organizations protect sensitive database fields before those movements create exposure.

Runtime encryption for persistent database protection

SecureDB uses OnData's patented runtime encryption and access management technology to protect sensitive data beyond the traditional boundaries of data-at-rest and data-in-transit encryption. Sensitive values can remain encrypted while moving through databases, applications, ETL pipelines, data warehouses and analytics environments.

Authorized users and applications can access the original data when policy allows. Unauthorized users, compromised accounts or downstream systems without explicit permission cannot view meaningful sensitive values. This helps organizations reduce the impact of database exposure while preserving the ability to run applications, correlate protected records and analyze data safely.

How SecureDB works

  1. Identify sensitive data: Security and data teams determine which database fields contain confidential, regulated or mission-critical information.
  2. Classify and apply rules: Teams classify fields and apply protection rules based on data type, business use, user role and compliance requirements.
  3. Encrypt sensitive values: SecureDB applies runtime encryption designed to protect sensitive data while keeping authorized workflows operational.
  4. Enforce need-to-know access: Access to original sensitive
    data is controlled through identity-based authorization so only approved users or systems can view clear data.
  5. Support downstream use: Protected data can move into ETL, reporting, analytics, test or data warehouse environments without exposing unnecessary sensitive values.
  6. Audit sensitive data usage: Access activity can be logged to support internal monitoring, investigations and compliance reporting.
Table with customer information including CustomerID, CompanyName, ContactName, and ContactTitle.
Table with CustomerID, CompanyName, ContactName, and ContactTitle columns.

You may also like