Oracle has launched Database Security Central, a client-managed platform that consolidates user privilege analysis, sensitive data location, security configuration, auditing, and certain protection policies into a single console. The solution works with Oracle databases and can also collect logs or monitor traffic from Microsoft SQL Server, PostgreSQL, MySQL, IBM Db2, and MongoDB. Oracle offers it at no additional cost to selected customers until February 28, 2027.
Key Highlights of Oracle Database Security Central in 20 Seconds
- Centralizes analysis of users, sensitive data, configurations, auditing, and SQL traffic.
- Can be deployed on on-premises infrastructure, Oracle Cloud Infrastructure (OCI), AWS, and Microsoft Azure.
- Includes generative AI tools for risk inquiries and creating alert conditions using natural language.
- Supports Oracle sources and multiple third-party databases.
- The free offer for eligible customers ends on 02/28/2027.
The product represents an evolution of Oracle Audit Vault and Database Firewall (AVDF), the technology Oracle has used to centralize audits and monitor or block specific SQL traffic. Database Security Central expands this approach to address a broader question: understanding the cumulative risk across an organization that may have dozens or hundreds of databases distributed among on-premises data centers and various clouds.
The challenge isn’t purely technical. A database may be properly protected when deployed and deviate over time from its initial configuration. Old accounts, inherited permissions, temporary exceptions, and copies of sensitive data used for development or testing can also accumulate. Analyzing each element separately makes it harder to identify when multiple risks coincide within the same system.
From Privileged Users to Sensitive Data
Oracle has structured some functions around different views called User360, Data360, Configuration360, and Compliance360.
User360 assesses risks associated with users. It can identify privileged or high-risk accounts, display direct and indirect relationships between roles and privileges, locate inactive accounts, and track permission changes.
This is especially relevant in large organizations. A user’s privileges may not come solely from direct assignment but through roles, groups, or inherited permissions, complicating straightforward questions like: what information can a particular user actually access?
Data360 focuses on stored information. According to Oracle, it can utilize over 175 predefined types of sensitive information to classify data and locate its whereabouts within the infrastructure.
It also addresses a common issue: data copies outside of production environments. An organization might enforce strict controls on the primary database but maintain similar data in development, testing, analytics, or backup systems under different policies.
Database Security Central enables repeatable classification across these environments to provide a unified view of exposure.
Meanwhile, Configuration360 compares configurations against a defined organizational baseline. It detects changes or deviations from approved settings and assesses compliance with various standards.
Oracle cites standards such as CIS Benchmarks, DISA STIGs, and GDPR requirements. While these checks don’t automatically certify regulatory compliance, they serve as tools to identify configurations needing review.
Two Firewalls to Control SQL Traffic
A core technical feature of Security Central concerns monitoring SQL language used to communicate with databases.
Oracle Database Firewall inspects network SQL traffic and enforces policies considering connection origin, application, user, or the executed statement.
The goal is to detect and block activity that violates policies, including potential SQL injection, unauthorized access, or data exfiltration attempts.
Additionally, SQL Firewall, integrated within Oracle AI Database 26ai, performs control inside the database engine itself, establishing authorized SQL statements and connection paths. Deviations can be blocked in real-time.
Both technologies are managed centrally through Security Central.
The platform also aggregates audit logs and SQL activity into a centralized repository. Administrators can generate reports on logins, privilege changes, stored procedure modifications, and sensitive data access, among other events.
Compliance360 uses this data to generate reports aligned with frameworks and regulations such as GDPR, PCI DSS, HIPAA, SOX, IRS 1075, and UK data protection laws.
Another component, Unified Policy Management, allows defining policies once and deploying them across multiple databases, including audit, alert, Database Vault, Database Firewall, and SQL Firewall policies.
AI Also Enhances the Security Console
Oracle has integrated generative artificial intelligence into two aspects of Database Security Central.
AI Advisor enables natural language queries about user activity, data exposure, security risks, and compliance issues. It can also provide instructions for configuration, investigation, and administrative tasks.
AI Assistant allows describing an alert condition in natural language, which is then transformed into structured rules that can be applied within the platform.
Oracle promotes these features as ways to reduce manual workload and misconfigurations. However, they do not eliminate the need to validate generated policies, particularly when they may impact access or database functionality.
Security Control Center also aims to relate different pieces of information that are often investigated separately. For example, it can show that a high-risk user has access to sensitive data within a database whose configuration deviates from the baseline.
The goal is that incident prioritization considers the combination of multiple risk factors, not just isolated alerts.
Beyond Oracle Database
One of the most compelling aspects for hybrid infrastructures is that Security Central is not limited solely to Oracle databases.
It supports various Oracle Database architectures such as Exadata, Real Application Clusters (RAC), Data Guard, and Multitenant container databases.
It can also collect audit logs from Microsoft SQL Server, MySQL, PostgreSQL, IBM Db2, and MongoDB, and monitor SQL traffic in these environments. Oracle notes that it can receive audit data from operating systems and custom sources in XML, JSON, and CSV formats.
Deployment options include on-premises infrastructure or cloud environments like OCI, AWS, and Azure. It is also designed for integration with external identity and access management (IAM) platforms and security information and event management (SIEM) systems.
This reflects a common scenario in large organizations: data infrastructure often spans multiple products, data centers, or cloud providers.
For current Oracle Audit Vault and Database Firewall customers, Security Central offers an upgrade path. Oracle provides an out-of-place update procedure that preserves the original Audit Vault server while transferring data and configuration to the new platform. This update is identified by patch 39197299, available via My Oracle Support.
Oracle first announced Database Security Central on April 8, 2026, indicating it was approaching general availability. It was officially made available on August 4, and a limited-time promotion allows eligible support customers to use it at no extra cost until February 28, 2027. Oracle’s published conditions state the free period started on June 12, 2026.
Frequently Asked Questions
What is Oracle Database Security Central?
It is a client-managed security platform that consolidates risk analysis, user activity, sensitive data, configurations, audits, and protection policies across a fleet of databases.
Does Database Security Central only work with Oracle Database?
No. While its primary functions are tied to Oracle databases, it can also collect audit logs and monitor SQL traffic from Microsoft SQL Server, MySQL, PostgreSQL, IBM Db2, and MongoDB.
Where can Oracle Database Security Central be installed?
Oracle states it can be deployed on-premises and in cloud environments, including Oracle Cloud Infrastructure, Amazon Web Services, and Microsoft Azure.
Is Oracle Database Security Central free?
Currently, Oracle offers Database Security Central at no additional charge to certain supported customers through February 28, 2027. This is a limited-time promotion, not a permanent free offering.
via: blogs.oracle

