rmBug
Identity-based database access management for engineers, AI agents, and automation with SSO authentication, time-limited access, and full query audit logging.
At a Glance
About rmBug
rmBug provides identity-based database access management that lets teams know exactly who is connecting to their databases — humans, AI agents, and automation alike. Engineers authenticate via SSO and get time-limited access through the tools they already use, while AI agents and CI/CD pipelines receive their own machine identity, credentials, and access policies. Every connection is named, every query is logged, and the entire system deploys in under 10 minutes without VPN tunnels or firewall changes.
- Identity for every connection — Engineers authenticate via SSO; AI agents and CI/CD pipelines authenticate via API key, each with their own RBAC role and audit trail.
- Time-limited access — Engineers request access for a defined duration; approvals can be manual, automatic, or always-on for trusted teams.
- Machine identity built in — Register AI agents, CI/CD pipelines, and automation scripts as org members with their own grants, security settings, and audit trail — not just tagged sessions.
- Full query audit logging — Session metadata, query text, PII redaction, and policy decisions are all captured in a tamper-evident, searchable audit log.
- Query firewall — Block dangerous operations before they execute, with rules configurable per resource, role, or environment.
- Works with existing tools — psql, mysql CLI, TablePlus, DBeaver, and DataGrip all work via a local transparent proxy — no client changes required.
- No network changes required — Deploy a gateway inside your VPC; engineers connect through rmBug's secure relay without VPN tunnels or bastion hosts.
- Compliance-ready — Audit trail, access controls, and credential isolation support SOC 2, HIPAA, SOX, and ISO 27001 requirements.
- Concurrent agent billing — Buy a pool of concurrent connection slots for automation rather than per-agent seats; unlimited agents can be registered.
- Credential isolation — Database credentials are stored encrypted and injected by the gateway; engineers never see or handle passwords directly.
Community Discussions
Be the first to start a conversation about rmBug
Share your experience with rmBug, ask questions, or help others learn from your insights.
Pricing
14-Day Trial
Full-featured trial on any plan. No credit card required. Includes 2 concurrent agent connections.
- All plan features available
- 2 concurrent agent connections included
- No credit card required
Teams
For small teams getting started. Billed annually.
- Unlimited users & resources
- All protocols
- Direct gateways
- Always-available access
- Agent members
- Slack & Teams notifications
- 30-day audit logs
- Add-on: SSO + SCIM ($125/mo)
Teams
For small teams getting started. Billed monthly.
- Unlimited users & resources
- All protocols
- Direct gateways
- Always-available access
- Agent members
- Slack & Teams notifications
- 30-day audit logs
- Add-on: SSO + SCIM ($125/mo)
Business
For growing teams. Billed annually.
- Everything in Teams
- Relayed gateways
- Governed Access approvals
- SSO + SCIM included
- Data masking
- Audit export (CSV/JSON)
- Auditor role
Business
For growing teams. Billed monthly.
- Everything in Teams
- Relayed gateways
- Governed Access approvals
- SSO + SCIM included
- Data masking
- Audit export (CSV/JSON)
- Auditor role
Enterprise
For organizations with compliance needs. Custom pricing.
- Everything in Business
- Compliant Access approvals
- Query firewall
- Row-level security
- Column-level security
- SIEM integrations
- Priority support & SLA
- Dedicated infrastructure
SSO + SCIM
SSO and SCIM provisioning add-on for Teams plan.
- Single sign-on (SSO)
- SCIM provisioning
- Group sync
90-Day Audit Log Retention
Extended audit log retention add-on. Per user, per month.
- 90-day audit log retention
1-Year Audit Log Retention
Extended audit log retention add-on. Per user, per month.
- 1-year audit log retention
3-Year Audit Log Retention
Extended audit log retention add-on. Per user, per month.
- 3-year audit log retention
6-Year Audit Log Retention
Extended audit log retention add-on. Per user, per month.
- 6-year audit log retention
Capabilities
Key Features
- SSO authentication
- Time-limited access grants
- Machine identity for AI agents and CI/CD
- Full query audit logging
- PII redaction in audit logs
- Query firewall
- Row-level and column-level security
- Data masking
- Approval workflows
- Credential isolation
- AWS Secrets Manager integration
- HashiCorp Vault integration
- SCIM provisioning
- SIEM integrations
- Audit log export (CSV/JSON)
- Slack and Teams notifications
- No VPN required
- Cross-platform CLI agent
- Transparent local proxy
