Available at no additional cost through February 28, 2027

Today, we are announcing the availability of Oracle Database Security Central (Security Central),a customer-managed offering that gives database and security teams a centralized view of user risk, sensitive data exposure, and security posture across their database fleet.

Oracle Database Security Central is available at no additional cost to eligible customers until February 28, 2027. This limited-time offer gives organizations an immediate opportunity to strengthen database security across on-premises, hybrid, and multicloud environments.

Data is one of the most sensitive assets organizations manage, yet database security is often managed through disconnected tools and manual processes. Monitoring activity, reviewing user access, assessing security posture, locating sensitive data, and validating controls frequently happen in isolation or not at all. As a result, many organizations lack a clear view of security risks across their database fleet.

AI-driven threats make this challenge more urgent. Adversaries can use AI to rapidly identify unpatched systems, uncover weak configurations, exploit excessive privileges, discover vulnerabilities across the stack, and move laterally across environments. Attacks that took weeks can now happen in hours or minutes, leaving security teams with little time to investigate and respond across on-premises, hybrid, and multi-cloud database environments.

At the same time, security and compliance teams spend significant time assembling evidence for audits, reviews, and policy validation because the required data is scattered across multiple components and tools.

Oracle Database Security Central helps organizations:

  • Assess security posture and detect configuration drift
  • Identify privileged-user and access risks
  • Discover sensitive data and analyze how it is accessed
  • Collect and review audit evidence, and create reports
  • Centrally manage selected security policies to reduce policy variance 

Security Central also includes a GenAI-powered security advisor that helps teams understand risk, prioritize findings, and improve security and compliance across the enterprise.

Figure 1. Oracle Database Security Central Overview

With the no-cost offer, eligible customers can begin using Security Central now until February 28, 2027 to gain fleet-wide visibility and strengthen their database security posture.

To learn more about Oracle’s approach to defending data against emerging AI threats, read Securing Your Business Data Amidst Emerging AI Threats.

Let’s review the salient capabilities of Database Security Central:

Get visibility into risky users before events become incidents

One of the persistent challenges in database security is understanding who has privileged access, how that access was granted, and whether those privileges are appropriate. Excessive privileges are one of the most common sources of security risk, providing adversaries opportunities to exploit over-privileged accounts, dormant identities, and misconfigured roles to gain a foothold and move laterally across environments.

In many organizations, privileges accumulate over time through direct grants, nested roles, inherited access, and temporary exceptions. Stale accounts that were never deprovisioned are often discovered far too late. These complexities make access reviews slow and incomplete, leaving the window open for adversaries to exploit privilege escalation and data exfiltration before security teams can answer a simple question: who had access to what, when, and why?

User360, a core capability within Security Central, helps teams understand user risk across the fleet. It identifies privileged and high-risk users, maps direct and indirect role and privilege graphs, surfaces stale and dormant accounts, and tracks entitlement drift over time. This comprehensive view of user access is increasingly important because AI-powered attacks increasingly target these types of identity and privilege weaknesses to move across environments rapidly and with less chance of detection.

Figure 2. User360 in Oracle Database Security Central

Find sensitive data across databases

Many organizations don’t have a reliable view of what sensitive data they have, where it is, or how much of it exists across their environments. Without this visibility, they may not know where to focus first.

Organizations often secure their production databases while overlooking non-production environments that contain the same sensitive data replicated across test, development, analytics, and backup systems.  When controls vary across environments, adversaries can more easily find and access sensitive data outside production.

Without that overall visibility, the same data can be classified differently, protected unevenly, and audited inconsistently.

Data360 helps organizations discover sensitive data across the fleet, classify it using more than 175 built-in sensitive types, and apply repeatable classification across environments. This enables teams to understand where sensitive data resides, assess exposure, and implement controls consistently at scale.

Figure 3. Data360 in Oracle Database Security Central

Track security configuration drift against approved baselines

Configuration drift is another problem that grows quietly over time. A database may begin in a compliant and hardened state, then gradually drift from that baseline through patch exceptions, temporary changes, local workarounds, or inconsistent hardening practices. At the same time, security baselines must evolve to address emerging threats.  Across a large database estate, it becomes increasingly difficult to determine which systems remain compliant, which have drifted, and which require remediation.

Configuration360 in Security Central helps provide continuous security posture visibility across the fleet. Teams can define baseline configuration, detect drift, measure compliance against standards such as CIS, DISA STIG, or GDPR, and prioritize the issues that pose the greatest risk. This helps ensure that security controls remain effective as environments evolve.

Figure 4. Configuration360 in Oracle Database Security Central

Fleet-wide auditing, reporting, and alerting for faster response

 While defined controls establish the security baseline, organizations also need visibility into how those databases are being used, how controls operate in practice, and how user activity aligns with security policies.

Security Central includes a powerful interactive reporting engine with dozens of out-of-the-box activity reports covering logins and logouts, sensitive data access and modification, privilege changes, stored procedure changes, and more. Report data can be easily filtered and customized with different conditions to expedite after-incident investigations. Reports can be scheduled, downloaded, and shared for compliance.

The Audit Insights dashboard offers a bird’s-eye view of database activity and highlights the most significant user activities across one or more databases.

Stop unauthorized SQL before it reaches the database

To prevent and protect against unauthorized activities across the database estate, Security Central delivers multiple approaches for firewalls.

Security Central delivers a Database Firewall that inspects SQL traffic at the network perimeter. It uses a patented grammar-based engine that understands SQL structure, not just signatures or patterns.  Database Firewall applies multi-stage policy controls based on source, application, connection path, user, and SQL to help reduce the risk of SQL injection, data exfiltration, and unauthorized access attempts before database traffic reaches the database.

Inside the database, Oracle AI Database 26ai’s native SQL Firewall enforces a similar trusted baseline of approved SQL statements and authorized connection paths directly within the database kernel. Any deviations are blocked in real time, helping prevent threats that bypass network controls or are executed from within the database from reaching the data.

Both solutions are centrally managed through Security Central, giving teams a single point of control for defining, enforcing, and monitoring firewall policies across the entire fleet.

Security Central combines these preventative controls with continuous monitoring and auditing. By aggregating audit records and network-based SQL activity into a secure centralized repository protected with Oracle security controls, it provides both a point-in-time view of risk and real-time visibility into database activity. Together, auditing and SQL firewall controls help organizations understand who did what, detect anomalous behavior, investigate incidents more quickly, and identify potential data exfiltration risks.

Standardize policy management across the estate

Visibility alone is not enough. Security teams also need a consistent way to define, deploy, and enforce security policies across the database fleet.

In many environments, policies for auditing, alerting, and protection are managed for each database separately. Over time, that creates policy variance across environments, making it difficult to have the same changes everywhere, and leaving teams with more manual effort when they need to prove that controls are applied consistently.

Unified Policy Management in Security Central gives teams one place to create, standardize, and enforce security policies for auditing, alerting, Database Vault, Database Firewall, and SQL Firewall across the estate. This helps bring consistency, simplify administration, and ensure that the same controls are applied consistently across multiple databases.

For example, you can define a privileged-user audit policy to track activities such as user creation, privilege grants, role changes, and other administrative actions, and deploy it consistently across the database fleet from a single console. Similarly, teams can create audit policies to monitor access to sensitive data and apply them across multiple databases. As requirements evolve, policy updates can be managed centrally and propagated across the estate, eliminating the need to configure and maintain each database individually.

Figure 5. Security Policy Console

AI Advisor and Assistant

The GenAI-powered AI Advisor in Security Central helps the team explore user activity, security risks, data exposure, and compliance posture using natural language. It also provides step-by-step guidance for security configuration, investigations, and administrative tasks, helping teams find answers and act more quickly.

The Security Central AI Assistant also allows administrators to define alert conditions in natural language, translating intent into structured policy rules that can be applied directly. This helps reduce human error, improve detection quality, and enable teams to move faster from question to action.


Together, these capabilities help reduce manual effort, minimize configuration errors, improve detection quality, and accelerate the path from insight to action.

Move from isolated findings to prioritized actions

Security teams do not need more findings. They need a faster way to determine what risk matters most and what to address first.

User risk, sensitive-data exposure, posture drift, firewall events, and SQL activity are often reviewed in separate tools and separate workflows. As a result, security teams spend significant time correlating information manually and may miss the relationships between seemingly independent findings.

The Security Control Center in Security Central brings these signals together, providing a unified view of risk across the fleet and prioritizing remediation more effectively. Instead of reviewing each finding in isolation, teams can identify the combinations that matter most, such as a high-risk user with access to sensitive data on a system that has drifted from baseline. This enables security teams to focus on the issues most likely to lead to compromise, data loss, or compliance violations.

Figure 6. Security Control Center

Built for modern database estates

Security Central is designed to scale from small deployments to large heterogeneous database estates, spanning on-premises, multi-cloud, or hybrid environments.  It supports a full spectrum of Oracle Database deployment patterns, including Exadata, RAC, Data Guard, and Multitenant pluggable databases.

Beyond Oracle databases, Security Central collects audit records from Microsoft SQL Server, MySQL, PostgreSQL, IBM Db2, and MongoDB, and monitors SQL traffic across these environments. It can also collect audit data from operating systems and custom audit sources in XML, JSON, and CSV formats.

Security Central is designed to integrate with third-party SIEM and IAM platforms. It can currently be deployed on-premises or in cloud environments, including Oracle Cloud Infrastructure, AWS, and Microsoft Azure.

What Security Central Delivers

For CISOs: As AI-powered attacks grow more targeted, automated, and difficult to detect, Security Central brings the fleet-wide visibility needed to understand database risk, prioritize remediation guidance, strengthen compliance, and demonstrate security effectiveness and reporting across the entire estate.

For security and database operations teams: Security Central reduces manual effort by centralizing visibility, monitoring, policy management, and risk analysis. Teams can enforce controls more consistently, respond to threats more quickly, and manage security at fleet scale from a single platform.

Security Central brings visibility, policy management, monitoring, and threat protection together in a single platform, helping organizations secure their databases consistently across the entire estate.

For existing Oracle Audit Vault and Database Firewall Customers

Oracle Database Security Central builds on the proven foundation of Oracle Audit Vault and Database Firewall (AVDF) for database activity monitoring and SQL threat prevention. It extends these capabilities with broader risk visibility, security posture management, sensitive data discovery, privileged-user risk analysis, unified policy management, and AI-assisted operations across the database fleet.

As Figure 7 illustrates, Database Security Central represents the natural evolution of AVDF’s focused activity monitoring and firewall solution to a comprehensive command center for database security. By bringing together risk visibility, threat detection, policy governance, and compliance assessment in a single platform, Security Central helps organizations manage database security more consistently and effectively at fleet scale.

Figure 7. From Activity Monitoring to Single Command Center

Simple, Low-Risk Upgrade for Existing Deployments

Existing AVDF customers can seamlessly transition to Security Central using the out-of-place upgrade process. The upgrade preserves your existing deployment while transferring data and configuration to the new environment, minimizing disruption and reducing operational risk. Because the original Audit Vault Server remains available throughout the process, organizations also benefit from a straightforward recovery path if needed, making it easier to adopt Security Central with confidence. Existing AVDF customers can download patch number 39197299 from My Oracle Support and follow the documented out-of-place upgrade procedure to move to Oracle Database Security Central.

Call to action