Data Safe
Oracle Data Safe empowers organizations to discover sensitive data, assess database configurations and user security, evaluate data risks, implement and monitor security controls, and monitor database activity. From one unified console, teams can also mask sensitive data, create subsets for nonproduction use, and manage Oracle AI Database SQL Firewall.
These capabilities help organizations manage day-to-day security and compliance requirements across Oracle databases in OCI, multicloud, and on-premises environments.
2025 KuppingerCole Leadership Compass for Data Security Platforms Discover why KuppingerCole recognized Oracle as a Leader in database security
Why Oracle Data Safe
Unified risk management
One cloud service to assess security, monitor activity, discover sensitive data, mask and subset data across Oracle databases in OCI, Cloud@Customer, multicloud, and on-premises. Oracle Data Safe also manages Oracle AI Database 26ai SQL Firewall.
Accelerate compliance and privacy
Discover and classify regulated data, apply consistent audit policies, and generate turnkey reports to meet GDPR, CCPA, DPDPA, PCI DSS, HIPAA, and other compliance needs.
Reduce attack surface and insider risk
Identify risky users and excessive privileges across your fleet, flag weak configurations, and get alerts on suspicious activity.
Simplify operations
Cloud‑native, centrally managed workflows and APIs streamline onboarding, policy deployment, and continuous monitoring for large fleets.
Free Oracle Patching and Security Tools
Access free tools to help close patch gaps faster and strengthen database security amidst emerging AI threats.
Oracle Data Safe features
Organizations struggle with weak passwords, overprivileged users, and misconfigured databases that create vulnerabilities attackers exploit. Teams lack visibility into where sensitive data resides, how users behave, and whether they meet compliance requirements. Oracle Data Safe provides a unified platform that automatically identifies vulnerabilities, discovers and classifies sensitive data, monitors suspicious activity, and maintains audit trails for GDPR, CIS, and STIG compliance.
Security assessment
Quickly evaluate database security posture by identifying, categorizing, and prioritizing risks. Get comprehensive reports on configuration parameters, security controls, user roles, and privileges. Maintain baselines, detect drift, and enforce consistent controls fleet-wide with actionable recommendations mapped to GDPR, DISA STIGs, and CIS benchmarks.
User assessment
Identify highly privileged accounts that pose threats if misused or compromised. Data Safe calculates risk scores for each user based on user types, authentication methods, password policies, and password change frequency. Review privileges and activity through direct links to audit records, then deploy appropriate security controls based on risk insights.
Activity auditing
Collect audit data from databases and identify anomalous operations. Manage audit and alert policies using out-of-box or custom reports to analyze database activity. Retain audit data up to 7 years for compliance and forensic investigation.
Sensitive data discovery
Discover and classify sensitive data using 150+ predefined types, extendable with custom types. Built-in sensitive types cover personal identifiers, biographic, IT, financial, healthcare, academic, and employment data. Gain clear insight into the type, location, and volume of sensitive data to assess risk and determine protection needs.
Data masking
Mask sensitive data using prebuilt formats and extend using custom rules. Preserves referential integrity so your applications run on masked data. Build masking policies from discovered data, run scheduled jobs, and generate audit reports.
Data subsetting
Create smaller, targeted datasets for development, testing, patch validation, and other focused scenarios. Apply percentage rules, filter conditions, or both on registered non-production database, preserving relevant table relationships where supported. Combine Data Subsetting with data masking when sensitive values in the retained data also need protection.
SQL Firewall management
SQL Firewall in Oracle AI Database 26ai learns normal application behavior—tracking SQL statements, network addresses, OS users, and programs. Centrally manage policies and monitor violations with alerts and reports.
Security policies
Centrally deploy and manage audit policies and SQL Firewall configurations across database fleets. Use Oracle predefined policies aligned to compliance frameworks or create custom policies. Policies automatically apply to database groups and dynamically update as targets change.
Alerts and notifications
Define policies to alert on risky events including privileged actions, failed logins, and configuration drift. Route notifications to operations teams for immediate response.
APIs and automation
Comprehensive REST APIs, OCI CLI, and SDKs (Java, Python, Go, .NET, Ruby, TypeScript/JavaScript) automate onboarding, assessments, auditing, discovery, masking, subsetting, and reporting. Integrate with DevOps and SecOps workflows using Terraform via the OCI Provider for infrastructure-as-code deployments.
Multicloud and on-premises database support
Supports registering databases across Autonomous AI Database, Exadata Cloud Service, Base Database Service, Oracle Database@Azure, Oracle Database@Google Cloud, Oracle Database@AWS, Amazon RDS for Oracle, Cloud@Customer, and on-premises databases including Enterprise Edition and Standard Edition for centralized governance.
Resources
AskTOM Oracle Database Security Office Hours
AskTOM Office Hours offers free, open Q&A sessions with Oracle Database experts who are eager to help you fully leverage the multitude of enterprise-strength database security tools available to your organization.

LiveLabs: Oracle Data Safe
This workshop lets you practice the main features in Oracle Data Safe, including activity auditing, alerts, security assessment, user assessment, data discovery, and data masking.

Extend Database Security Across Your Enterprise Manager Estate with Oracle Data Safe
Bettina Schaeumer, Senior Principal Product Manager, Database Security, OracleOrganizations rely on Oracle Enterprise Manager to monitor, manage, and organize large estates of on-premises Oracle databases. With the new integration between Enterprise Manager and Oracle Data Safe, those same customers can more easily extend centralized security assessment, activity monitoring, and sensitive data protection across their database environments.
Featured database security blogs
- July 2, 2026Strengthen Security for On-Premises Oracle Databases with Oracle Data Safe
- October 9, 2025Simplifying Database Security Compliance at Scale with Oracle Data Safe
- Continue readingSee all
Get started with Oracle database security
Try Data Safe LiveLabs #1
Experience Data Safe by configuring your key use cases on LiveLabs. This overview lab covers evaluating database configurations and security controls; assessing user security and privileges; monitoring user activity through auditing and alerts; discovering sensitive data, then masking it and creating subsets for nonproduction use; and using SQL Firewall to mitigate risks from SQL injection and compromised accounts.
Try Data Safe LiveLabs #2
Experience Data Safe by configuring your key use cases on LiveLabs. This lab focuses on establishing secure connectivity to Oracle databases across cloud and on-premises environments using Data Safe private endpoints for databases in OCI or connected via FastConnect/VPNConnect, and Data Safe on-premises connectors for databases outside OCI.
Try Data Safe LiveLabs #3
Experience Data Safe by configuring your key use cases on LiveLabs. This lab focuses on integrating Data Safe with applications and Oracle Cloud Infrastructure services through the Data Safe API, command line interface in Cloud Shell, and event creation for automation and orchestration.
Contact sales
Talk to a team member about Oracle Database security.





