SECURITY ARCHITECTURE / LOCAL-FIRST BY DESIGN

Database security.
Start with the boundary.

Saved secrets belong in an encrypted local vault. Review the master-password model, direct database connections, in-memory masking, and the protection gates that control sensitive targets.

Choose your license
14-DAY TRIAL

Meet your next workflow.

Choose the installer for your computer.

On a Mac, check Apple menu → About This Mac for your chip.

Trial installers are not available here yet. Please check back for the download.

$10.95 monthly or $99 yearly One developer, up to two devices

The cryptographic irisWORKFLOW STUDY
The cryptographic irisAn iris of interlocking plates closes around locally encrypted secrets. A master password protects the saved-secret vault.AES-256GCMSAVEDSECRETS

AES-256-GCM / saved secrets on your machine.

Illustration / example workflow
Local secret storage · architecture illustration

1. The SaaS Proxy Threat Model

Many modern database tools route schema diffs and queries through web-based multi-tenant SaaS backends. For financial institutions, healthcare providers, and high-security enterprise teams, this introduces critical supply-chain and data residency risks:

  • Credential Exposure: Storing database connection strings in cloud vaults creates high-value honeypots for attackers.
  • Data Leakage via Telemetry: Cloud SaaS tools routinely log SQL queries, parameter values, and error messages containing sensitive information.
  • AI Model Training Hazards: Cloud AI services can ingest proprietary schemas and business logic during automated analysis.
dbmigrate Design Principle: Your workstation connects directly to your databases.
Database connections go directly to your chosen servers. No cloud AI service receives your row values.

2. Workstation Cryptography & Secret Storage

All application configuration, saved database profiles, and historical logs remain on your local disk. Saved database passwords and SSH secrets are protected using industry-standard cryptography:

AES-256-GCM Encryption

Saved secrets use authenticated AES-256-GCM encryption. Protect the workstation account and review local file access alongside the vault.

Master Password Vault

Saved secrets are protected by your master password. Automatic locking helps limit access to an unattended workspace.

3. Direct Wire Networking

When comparing schemas or synchronizing tables, dbmigrate establishes direct peer-to-peer TCP connections between your machine and the database servers.

  • Transport configuration: Review TLS and certificate settings supported by the database and your installed product version.
  • SSH tunneling: Use the configured tunnel when your database is reachable through an approved bastion.
  • Network access: Confirm that the workstation can reach each endpoint with the required permissions.

4. In-Memory Masking Security

When refreshing staging or development databases with production data subsets, dbmigrate transforms values strictly in volatile RAM before network transmission.

  • In-memory transformation: Values are masked before writing to the target. Workstation memory, swap, and debugging controls remain part of your own security boundary.
  • Rule management: Review reusable masking rules, deterministic seeds, and salted-hash configuration. Protect access to that configuration.
  • Privacy review: Deterministic replacements can remain linkable. Inspect the resulting dataset for re-identification risks and unexpected unmasked values.

5. Environment Protection Tiers

To prevent accidental destructive operations, dbmigrate assigns protection levels to every connection:

Lower-Protection Targets

Review the change list and generated SQL before applying, even in a development environment.

Production (High Tier)

High-protection targets require a passing dry run, a pre-apply snapshot, and typed database-name confirmation. Recompare if the target schema has changed.

6. Privacy and Governance Review

Treat local processing and masking as controls within your own governance process. Before refreshing a lower environment, review:

  • Dataset scope: Direct identifiers, indirect identifiers, free-text fields, and remaining sensitive values.
  • Approved rules: Masking coverage, deterministic behavior, final column overrides, and the privacy assessment for the resulting dataset.
  • Operational controls: Target access, data retention, workstation security, and run records. Product presets do not certify compliance.
SECURITY QUESTIONS

Frequently Asked Security Questions

Where does database traffic go?

dbmigrate connects from your workstation to your configured source and target databases. Schema comparison and masking run locally. No cloud AI service receives your row values; copied values are written to the selected target database.

How are saved secrets protected?

Saved database passwords and SSH secrets are encrypted locally with AES-256-GCM and protected by a master password. Use appropriate workstation access controls and database permissions alongside the application vault.

Does masking establish regulatory compliance?

Masking supports a controlled test-data workflow, but presets are configuration aids rather than certifications. Review direct and indirect identifiers, final overrides, access controls, and retention rules. Your organisation must assess whether the resulting dataset meets its obligations.

What should I check for a restricted-network deployment?

Confirm that your workstation or runner can reach the intended databases and any required SSH bastion. Review installation, trial, licensing, and update requirements for the product version you plan to use. Local database processing does not by itself establish an air-gapped deployment guarantee.