🗄 DB SHIELD

Field Encryption

Field-level database encryption with a separate AES-256-GCM key per field and row, derived via HKDF-SHA256 from the OS CSPRNG. Protects sensitive columns at rest. DB Shield never connects to your database: you send it a value, it returns ciphertext you store yourself.

Server-side schema analysis and tamper scanning are not available (those endpoints return 501). DB Shield holds the keys, so it is not a no-master-key or zero-knowledge design, and it has no HSM, SOC 2 report or HIPAA BAA.

Quick Example

curl -X POST https://dbshield-api.qntyx.io/configs/ \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json"

API Base URL

https://dbshield-api.qntyx.io

Endpoints

MethodPathDescription
POST/configs/Register a database
POST/keys/encryptEncrypt a field — body: database_name, table_name, field_name, row_id, plaintext
GET/audit/Encryption audit log
GET/stats/Dashboard statistics

Authentication

All endpoints require a bearer token. See Authentication for details.

Dashboard

Manage this product visually at app-db.qntyx.io

Marketing Page

Learn more at db.qntyx.io