More and more companies are placing compliance with their security policies at a critical level, and especially the database architecture. At HexaCluster, when we work on a client's PostgreSQL infrastructure, security teams often ask us how the database architecture can comply with their security policy. The answer is invariably to implement the recommendations issued by the CIS.
The Center for Internet Security (CIS) develops security repositories for PostgreSQL, as well as for most components of an IT infrastructure. The resulting document is a checklist for verifying the compliance of PostgreSQL installations with the company's security policies.
To facilitate the automated and iterative processing of this checklist of our clients, HexaCluster has developed an open-source PostgreSQL security assessment tool that complies with these CIS recommendations. Thus, verifying the security of the PostgreSQL infrastructure is no longer a simple checklist; it can now be an integral part of a security pipeline.
Version 2.0 of PGDSAT (PostgreSQL Database Security Assessment Tool) checks the 80 controls based on last version of CIS benchmarks for PostgreSQL v17 including more than 10 additionals checks from HexaCluster to conform to more security policies rules.

The security items checked by the PostgreSQL security assessment tool are the following:
and much more.
The green sign means test passed, the red sign means the check fail and the square means that it requires manual check on the details reported by pgdsat.
Here is a full sample report.
| 🔹HexaRocket Recommendation |
|---|
| To ensure a seamless and end-to-end database migrations, we recommend using HexaRocket, which enables you to automate and manage your migration process with precision. HexaRocket supports Schema conversion with near to 100% accuracy with validation, data migration and cdc for live replication with validation of data at every stage. HexaRocket enables you to perform online migration and rollback capability using its live replication functionality. Supported databases are Oracle, MSSQL (SQL Server), MySQL, MariaDB, Sybase and PostgreSQL |
Subscribe to our Newsletters and Stay tuned for more interesting topics.
If you need expert support migrating legacy or complex Oracle, SQL Server, Sybase, MySQL, MariaDB databases to PostgreSQL or distributed databases, we’re here to help. HexaCluster provides end-to-end migration and modernization services, including application migration and modernization, database migration, and PostgreSQL consulting such as performance tuning, health audits, managed DBA services, and 24/7/265 support. To start a conversation or explore how we can support your migration journey, please contact us at connect@hexacluster.ai
Gilles Darold is the CTO of HexaCluster. Gilles is one of the Major PostgreSQL Contributors and the creator of Ora2Pg, pgBadger, and many more popular PostgreSQL tools and extensions. His leadership has enabled HexaCluster in contributing to 50 plus popular PostgreSQL extensions and also create multiple PostgreSQL tools and extensions. Gilles is an expert in all the popular programming languages and is always passionate about contributing to PostgreSQL.
Start your migration journey 🚀
start your migration journey with our expert team
Database & Application Migration Assessment Tool
End-to-End Database Migration & Modernization Tool
Database Code Object Conversion to PostgreSQL
MyBatis Mapper Conversion to PostgreSQL
Enterprise Data Replication & Live CDC
Oracle Compatibility Layer for PostgreSQL