Does iDBQuery support penetration testing and security reviews?

Yes. iDBQuery supports customer-led penetration testing of your own deployment and follows secure development practices to minimise attack surface. Because you can run iDBQuery in your VPC or on-premise, you can test the exact instance you operate, and an air-gapped deployment removes external exposure entirely.

Security testing is most meaningful when you can examine the instance you actually run, and iDBQuery's deployment model makes that possible.

  • Test your deployment - because iDBQuery can run in your VPC or on-prem, you can penetration-test the very instance handling your data, on your schedule.
  • Reduced attack surface - private networking, IP allow-listing, least-privilege source credentials, and an air-gapped option all shrink what is exposed in the first place.
  • Secure practices - iDBQuery is built with security in mind, and we support responsible disclosure and coordinated review.
  • No overclaiming - this is about architecture and testing you can verify, not a certification; iDBQuery does not claim audits or certifications it does not hold.

For example, before rollout a security team can run their standard pentest against an iDBQuery instance in their own VPC, confirm the controls behave as documented, and only then open it to users - with an air-gapped variant available if external reachability must be zero. This puts verification in your hands rather than asking you to accept a marketing claim, which is consistent with how iDBQuery leads with architecture throughout: query-in-place, RBAC, and encryption in transit and at rest. We can also help complete your security questionnaire and provide a DPA. Contact us to coordinate testing and access the documentation your review needs.

Updated 2026-06-22