Database monitoring security and data handling

Mini DBA is designed to run inside the environment you control. The Engine connects to monitored databases and retains operational evidence; users work through the browser-based Console. You decide which database accounts, network routes, AI providers, MCP clients and notification integrations are permitted.

Mini DBA Console

Provide authenticated browser access over HTTPS and limit Console reachability to the users and networks that need it. Reader access remains view-only for Engine and administration settings.

Mini DBA Engine

The Engine connects to database servers, collects monitoring evidence and maintains persistent configuration, metrics, alerts, logs and licence state. Protect the host and persistent data location as operational infrastructure.

Monitored databases

Use a dedicated monitoring login with the permissions needed for the views you enable. Mini DBA documents platform-specific permissions instead of requiring a general administrator account for routine monitoring.

Keep access proportionate to the job

Start with the monitoring permissions for each platform and add optional host or operational permissions only when the corresponding feature is required.

Database permissions

Query, wait, lock, plan, file, health-check and metadata pages rely on platform system views. If a permission is absent, the relevant data may be partial; use the Console permission checks to verify access.

Host metrics

Operating-system access is separate from the database login. Configure Windows, SSH or cloud-host access only when CPU, memory, drive or I/O evidence cannot be obtained from the database platform itself.

Operational actions

Session termination, maintenance and custom checks can require additional capability. Grant it only to the monitoring identity and operators that are expected to use those actions.

Start with the database connection and permissions guide, then follow the linked SQL Server, Azure SQL, PostgreSQL, MySQL/MariaDB or Oracle instructions.

Understand when monitoring data can leave your environment

Normal Engine-to-Console monitoring stays within the network paths you configure. Data is sent elsewhere only when a user or administrator enables a feature that needs an external destination.

AI Assistant

AI context is optional and can include selected metrics, alerts, server or database names, query text and execution plans. Do not send secrets or sensitive payload data. Use the Mini DBA allowance or a provider approved under your own policy.

Review AI context and privacy controls

Bring Your Own AI

Each browser user configures their own supported provider. Settings are encrypted before being stored in that browser's local storage. Provider terms, retention, private endpoints and identity controls remain your responsibility.

Review BYO AI configuration

Database MCP Server

MCP is used only when you enable it and configure a compatible client with an API key. Restrict endpoint reachability, create separate keys where useful, rotate them when access changes and treat returned monitoring evidence according to your data policy.

Review MCP Server settings

Credentials and persistent data

Treat database, host, cloud, notification and integration credentials as production secrets. Limit access to the Engine host, Console host, configuration, backups and persistent data volumes. BYO AI credentials belong to the individual browser profile rather than a shared installation setting.

External services and notifications

Email, Slack, Teams, PagerDuty, Jira, AI providers and other configured destinations receive the content required for the feature you enable. Review destination accounts, transport security, retention and access policy before sending production evidence.

Deployment checklist

  1. 1

    Place Console, Engine and persistent storage on managed Windows, VM or container infrastructure appropriate to your deployment.

  2. 2

    Use HTTPS for browser access and restrict Console, Engine and MCP network reachability with your normal firewall or reverse-proxy controls.

  3. 3

    Create dedicated monitoring identities, verify permissions in Mini DBA and avoid routine use of broad administrator accounts.

  4. 4

    Review AI context, MCP clients and notification destinations before enabling data flows outside the monitoring environment.

Security questions before purchase?

Use the documentation to assess the exact permissions and data paths for your platforms, or contact Mini DBA with an architecture or procurement question.

Read current documentation Contact Mini DBA