Field Encryption
Field-level database encryption with a separate AES-256-GCM key per field and row, derived via HKDF-SHA256 from the OS CSPRNG. Protects sensitive columns at rest. DB Shield never connects to your database: you send it a value, it returns ciphertext you store yourself.
Server-side schema analysis and tamper scanning are not available (those endpoints return 501). DB Shield holds the keys, so it is not a no-master-key or zero-knowledge design, and it has no HSM, SOC 2 report or HIPAA BAA.
curl -X POST https://dbshield-api.qntyx.io/configs/ \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json"
https://dbshield-api.qntyx.io
| Method | Path | Description |
|---|---|---|
POST | /configs/ | Register a database |
POST | /keys/encrypt | Encrypt a field — body: database_name, table_name, field_name, row_id, plaintext |
GET | /audit/ | Encryption audit log |
GET | /stats/ | Dashboard statistics |
All endpoints require a bearer token. See Authentication for details.
Manage this product visually at app-db.qntyx.io
Learn more at db.qntyx.io