DataSunrise Achieves AWS Data & Analytics Competency. Learn more →

Data Protection and Enforcement

Block Risky Access, Mask Sensitive Data, and Protect Data Copies

Apply firewall, masking, encryption, and Generative AI controls through methods matched to the source and data state.

  • Database Firewall
  • Masking and Test Data
  • Encryption and AI Controls

Protect data in use, in copies, and at rest

DataSunrise protects data while it is queried, copied, stored, and sent to Generative AI services. Teams can choose the control that matches the data state and the outcome they need.

Controls range from stopping risky live requests to creating protected copies for development, testing, and analytics.

Match the control to the data state

DataSunrise protects live traffic, sensitive results, non-production copies, and Generative AI interactions.

Data in use

  • Database Firewall
  • Dynamic Data Masking
  • AI masking and prompt controls

Data in copies

  • Static Data Masking
  • Synthetic Data Generation
  • Test Data Management

Stored PostgreSQL data

  • Selected columns or complete tables
  • Managed key exchange
  • Authorized proxy access
Monitoring shows what is happening and records evidence. Protection controls can block or mask live traffic, create protected copies, or encrypt selected PostgreSQL data.

See the workflow in DataSunrise

Product screens show how policy, evidence, and protection appear in practice.

Explore Data Protection and Enforcement

1 / 4

Protect Live Database Traffic

The DataSunrise Database Firewall evaluates requests through an inline proxy before they are executed. Rules can use the database user, configured application user, source, object, operation, time, and other session context to allow, block, or handle the request.

Dynamic Data Masking uses the same active path to change sensitive values in query results while the stored data remains unchanged.

Create Protected Data for Non-Production Work

Static Data Masking applies configured masking methods in batch tasks and writes a de-identified target for development, testing, analytics, or approved data sharing.

Test Data Management combines Static Data Masking with Synthetic Data Generation, so teams can prepare useful non-production datasets without relying only on clear production data.

Encrypt Selected PostgreSQL Data

PostgreSQL Encryption at Rest is a licensed workflow for selected columns or complete tables. It uses PostgreSQL pgcrypto and AES-128 with DataSunrise proxy query rewriting and managed key exchange.

Keys can be stored internally or through CyberArk and AWS KMS. Authorized applications receive clear values through the managed proxy path.

FAQ

Frequently Asked Questions

Can passive monitoring block or mask traffic?

No. Passive monitoring records activity without changing it. To block a request or mask a live result, traffic must pass through DataSunrise.

Does Dynamic Data Masking change stored data?

No. It changes the result shown to the user while the stored value remains unchanged. Static Data Masking, on the other hand, creates a de-identified copy.

Which databases does DataSunrise Encryption at Rest support?

It supports PostgreSQL and Amazon Aurora PostgreSQL.

See how DataSunrise works with your technology stack

View Integration Examples