Security-first backup control plane

Secure the backup surface
and the restore path.

DBAegis provides edition-controlled access, encrypted stored secrets, restore authorization, and audit-ready recovery workflows in a self-hosted deployment.

DBAegis securitysecure by design
DBAegis LDAP security
👥

LDAP + local users

Use centralized identity with LDAP while preserving local accounts for platform administration and break-glass access.

🧭

RBAC

Role-based access control separates admin and read-only responsibilities and supports group mapping for cleaner governance.

🔒

TLS

Terminate the DBAegis web interface behind HTTPS and use verified TLS for database and LDAP connections where supported by the target tools.

🗝️

Encrypted secrets

Connection passwords and sensitive credentials are stored encrypted, with secret-key rotation called out as a security practice.

📡

Webhook security

Enterprise webhook delivery validates destinations, restricts unsafe targets, protects sensitive headers, and records delivery outcomes.

🛡️

Restore authorization

Password re-authorization, restore reason capture, dry runs, and typed confirmation help prevent accidental or unauthorized restores.

📜

Audit-ready restore evidence

Capture who initiated restore, which artifact was used, what target was selected, when the action occurred, and why the restore was needed.

💾

Self-backup recovery

System snapshots protect DBAegis metadata and configuration so the control plane itself can be recovered after server or deployment issues.

Security resources

Review deployment guidance and report vulnerabilities privately.

Use the product security policy for private vulnerability reports. For production evaluations, review identity, TLS termination, database credentials, restore authorization, webhook destinations, audit evidence, backup encryption, and control-plane recovery against your environment.