1. The SaaS Proxy Threat Model
Many modern database tools route schema diffs and queries through web-based multi-tenant SaaS backends. For financial institutions, healthcare providers, and high-security enterprise teams, this introduces critical supply-chain and data residency risks:
- Credential Exposure: Storing database connection strings in cloud vaults creates high-value honeypots for attackers.
- Data Leakage via Telemetry: Cloud SaaS tools routinely log SQL queries, parameter values, and error messages containing sensitive information.
- AI Model Training Hazards: Cloud AI services can ingest proprietary schemas and business logic during automated analysis.
dbmigrate Design Principle: Your workstation connects directly to your databases.Database connections go directly to your chosen servers. No cloud AI service receives your row values.
2. Workstation Cryptography & Secret Storage
All application configuration, saved database profiles, and historical logs remain on your local disk. Saved database passwords and SSH secrets are protected using industry-standard cryptography:
AES-256-GCM Encryption
Saved secrets use authenticated AES-256-GCM encryption. Protect the workstation account and review local file access alongside the vault.
Master Password Vault
Saved secrets are protected by your master password. Automatic locking helps limit access to an unattended workspace.
3. Direct Wire Networking
When comparing schemas or synchronizing tables, dbmigrate establishes direct peer-to-peer TCP connections between your machine and the database servers.
- Transport configuration: Review TLS and certificate settings supported by the database and your installed product version.
- SSH tunneling: Use the configured tunnel when your database is reachable through an approved bastion.
- Network access: Confirm that the workstation can reach each endpoint with the required permissions.
4. In-Memory Masking Security
When refreshing staging or development databases with production data subsets, dbmigrate transforms values strictly in volatile RAM before network transmission.
- In-memory transformation: Values are masked before writing to the target. Workstation memory, swap, and debugging controls remain part of your own security boundary.
- Rule management: Review reusable masking rules, deterministic seeds, and salted-hash configuration. Protect access to that configuration.
- Privacy review: Deterministic replacements can remain linkable. Inspect the resulting dataset for re-identification risks and unexpected unmasked values.
5. Environment Protection Tiers
To prevent accidental destructive operations, dbmigrate assigns protection levels to every connection:
Lower-Protection Targets
Review the change list and generated SQL before applying, even in a development environment.
Production (High Tier)
High-protection targets require a passing dry run, a pre-apply snapshot, and typed database-name confirmation. Recompare if the target schema has changed.
6. Privacy and Governance Review
Treat local processing and masking as controls within your own governance process. Before refreshing a lower environment, review:
- Dataset scope: Direct identifiers, indirect identifiers, free-text fields, and remaining sensitive values.
- Approved rules: Masking coverage, deterministic behavior, final column overrides, and the privacy assessment for the resulting dataset.
- Operational controls: Target access, data retention, workstation security, and run records. Product presets do not certify compliance.