Decide When a Rule Applies
| Rule input | How it is used |
| Database and instance | Choose the connection to protect |
| User and session | Apply rules by database user, application user, client, host, or application |
| Operation | Apply rules to selected requests or statement types |
| Object and field | Target schemas, tables, columns, or available NoSQL objects and fields |
| Information Type | Mask values that match a sensitive-data definition |
| Condition | Use row, value, expression, or session conditions |
When an application passes its user identity to DataSunrise, Application-User Attribution can apply policies to the individual user behind a shared database account.
Works Across Your Data Environment
DataSunrise applies Dynamic Data Masking across databases, analytics services, NoSQL systems, and object storage while the original data remains unchanged.
| Environment | What Dynamic Data Masking protects |
| Databases and analytics | Live results across PostgreSQL, MySQL and MariaDB, Oracle, Microsoft SQL Server, Redshift, Snowflake, Athena, and other supported platforms |
| NoSQL systems | Selected fields in MongoDB, DynamoDB, and Elasticsearch, with object-level visibility controls for MongoDB and DynamoDB |
| Object storage | Sensitive content in CSV, XML, JSON, and unstructured files stored in Amazon S3 and compatible object storage |
Explore integrations to see how DataSunrise fits the technologies in your environment.
Test and Review the Rule
Dynamic Masking Events show which rule matched. Before rollout, test the queries, prepared statements, functions, stored procedures, data types, privileges, and application behavior used by the database.
After rollout, review matching events and adjust the policy when the application or data handling changes.