Everything You Need to Know

OneDB Overview

Estimated reading: 4 minutes 656 views

What is OneDB?

OneDB is a secure database gateway designed to protect sensitive data directly at the database layer.

It sits between applications, users, APIs, and databases to help apply data protection, masking, access control, and activity visibility without requiring major changes to existing applications.

OneDB helps organizations reduce sensitive data exposure while maintaining operational control over database access.

Why OneDB?

Sensitive data is often accessed through applications, database tools, reporting systems, support activities, and internal operations.

In many environments, organizations have limited visibility into what data is being accessed, who is accessing it, and whether sensitive information is properly protected.

OneDB helps address this by placing a secure control layer between clients and databases.

With OneDB, organizations can:

  • Protect sensitive data before it reaches unauthorized users
  • Apply masking and protection policies consistently
  • Monitor database query and command activity passing through the gateway
  • Reduce direct database exposure
  • Support audit and compliance requirements
  • Minimize changes to existing applications

Supported Database Platforms

OneDB supports multiple relational and document database platforms, enabling organizations to apply consistent security controls across heterogeneous database environments.

Database Type Description
Oracle Displays Oracle-related database objects and information available through OneDB.
Microsoft SQL Server Displays Microsoft SQL Server-related database objects and information available through OneDB.
PostgreSQL Displays PostgreSQL-related database objects and information available through OneDB.
MySQL Displays MySQL-related database objects and information available through OneDB.
MongoDB Displays MongoDB-related databases, collections, and document information available through OneDB. Available since OneDB v.3.0.0
IBM Db2 Displays IBM Db2-related schemas, tables, views, and database object information available through OneDB. Available since OneDB v3.2.0.

How OneDB Works

OneDB acts as a secure intermediary between applications and databases. Instead of connecting directly to the database, users and applications connect to OneDB, which transparently processes database traffic while enforcing security policies and governance controls.

OneDB manages client sessions, evaluates security rules, applies data masking and tokenization policies, records audit activities, and routes approved requests to the target database. Responses are then returned to the client while ensuring sensitive information is protected according to the configured policies.

Administrators use the OneDB Management Console to define and maintain security policies, field protection settings, masking rules, access controls, and audit configurations. These policies are applied centrally, allowing organizations to protect sensitive data without requiring changes to existing applications.

This architecture enables centralized database security, monitoring, auditing, and data protection across multiple database platforms while maintaining compatibility with existing database clients and applications.

This approach allows OneDB to protect sensitive data before it is returned to users or applications.

Key Capabilities

Secure Database Gateway

OneDB can operate as a proxy between applications and databases, allowing database traffic to pass through a controlled security layer.

Dynamic Data Masking

OneDB can mask sensitive values returned from database queries based on configured policies.

Examples of sensitive data may include:

  • Identity numbers
  • Phone numbers
  • Email addresses
  • Account numbers
  • Customer information

API-Based Data Protection

OneDB provides REST APIs for data protection operations such as masking, tokenization, detokenization, encryption, and decryption.

Database Query and Command Activity Visibility

OneDB can capture database query and command activity passing through the gateway to help administrators understand database access patterns and support audit review.

Policy-Based Control

OneDB uses policies to define what data should be protected, when protection should be applied, and which users or systems are allowed to access sensitive data.

Centralized Administration

OneDB provides a centralized Management Console for managing database connections, listeners, users, groups, access permissions, security policies, field protection settings, masking configurations, and audit activities across supported database environments.

Cluster and High Availability

OneDB supports clustered deployment across multiple nodes to help improve service availability and operational resilience. Supported configuration data is synchronized between cluster nodes, helping maintain consistent security policies and administrative settings across the deployment.

When used with appropriate network routing or load-balancing infrastructure, OneDB clustering can help reduce service disruption if an individual node becomes unavailable.

OneDB as a Database Gateway

In this model, applications connect to OneDB instead of connecting directly to the database.

This model is suitable for database access control, database activity visibility, and sensitive data masking.

OneDB as an API Data Protection Service

In this model, applications call OneDB APIs to protect or reveal data.

This model is suitable for tokenization, masking, encryption, and application-level data protection.

OneDB as a Secure Access Layer

In this model, database users, administrators, or support teams access databases through OneDB.

This model is suitable for controlled database access, audit visibility, and masking for operational users.

Next Steps

To continue learning about OneDB, see the following sections:

Share this Doc

OneDB Overview

Or copy link

Table of Contents