The DBX homepage
Score6.7
Rank#5 of 22
PriceFree
Free planYes
Runs onWeb

Summary

DBX is a web-based security analysis tool for PostgreSQL and Supabase databases. It examines how identities can reach database objects through RLS policies, grants, functions, storage, relationships, and tenant boundaries. DBX inspects live security objects and uses a deterministic rule engine and permission graph to assess practical access. It groups weaknesses into attack paths and reports severity, confidence, and evidence. Each deterministic finding includes a proposed migration tied to the object involved, with an expected security effect and compatibility risk. Its snapshot contains catalog metadata such as schemas, policies, grants, routines, and relationships, not database rows. DBX says the snapshot workflow needs no database password, persistent connection, agent, or production write access; its scanner is designed for a dedicated least-privilege role with catalog access. A language model explains verified findings and drafts remediation for human review. DBX does not test application code, network controls, or client authorization logic, and it makes no compliance certification claims. Free unlimited introspection is offered; Full Remediation is listed at 195.00 USD per once.

Who it is for

DBX suits developers and teams building PostgreSQL or Supabase applications, including multi-tenant systems and AI-generated SQL workflows. It is relevant to teams that want to inspect database permissions and review proposed remediation.

What is good

  • Maps access through policies, grants, and relationships.
  • Findings include severity, confidence, and evidence.
  • Snapshots contain metadata, not database rows.
  • No persistent connection or production write access required.
  • Free plan offers unlimited introspection.

What to know first

  • Does not test application code or network controls.
  • Does not assess client authorization logic.
  • Makes no compliance certification claims.
  • Full Remediation is 195.00 USD per once.

Verdict

DBX focuses on database-level access paths and connects findings to proposed migrations for human review. Its stated scope excludes application, network, and client authorization testing.

DBX plans and pricing

All plans
Database Scan Free Free Unlimited Introspection Introspect unlimited schemas · View database topology & score · See finding counts and severity · Local analysis (data never leaves browser) dbxray.co · 30 Sept 2026
Full Remediation $195 once Introductory Launch Price Includes 5 unique scans · Exact vulnerability details · Complete attack path graphs · Copy-paste SQL remediation · Verify fixes after remediation dbxray.co · 30 Sept 2026

Compared on database vulnerability scanners

Free plan
Yesdbxray.co
Cloud databases
Yesdbxray.co
Privilege analysis
Yesdbxray.co
Agentless scanning
Yesdbxray.co
Remediation guidance
Yesdbxray.co

Facts

What it does
DBX reconstructs how a PostgreSQL or Supabase database can actually be reached across RLS policies, grants, functions, storage, relationships, and tenant boundaries.dbxray.co · 30 Sept 2026
Analysis method
DBX introspects live security objects and resolves what each identity can reach in practice.dbxray.co · 30 Sept 2026
Findings
DBX connects individual weaknesses into attack paths and reports severity and confidence with evidence.dbxray.co · 30 Sept 2026
Remediation
Each deterministic finding includes a proposed migration tied to the object that produced it, with expected security effect and compatibility risk.dbxray.co · 30 Sept 2026
Data handling
The security snapshot contains catalog metadata such as schemas, policies, grants, routines, and relationships, but never database rows.dbxray.co · 30 Sept 2026
Access model
DBX states that it requires no database password, persistent connection, agent, or production write access for its snapshot workflow.dbxray.co · 30 Sept 2026
Scanner permissions
The scanner is designed for a dedicated least-privilege database role requiring CONNECT, schema USAGE, and SELECT on catalog views.dbxray.co · 30 Sept 2026
Credential handling
Submitted database credentials are sent to server-side functions over TLS, are not rendered back to the browser, and are not written to logs or analytics events.dbxray.co · 30 Sept 2026
Methodology
A deterministic rule engine evaluates introspected facts and a permission graph, while a language model only explains verified findings and drafts remediation for human review.dbxray.co · 30 Sept 2026
Limitations
DBX does not test application code, network controls, or client authorization logic and makes no compliance certification claims.dbxray.co · 30 Sept 2026
Supported platforms
DBX lists Supabase, PostgreSQL, Neon, AWS, GCP, Azure, Render, and DigitalOcean under its platform links.dbxray.co · 30 Sept 2026
Support
Security issues can be reported to [email protected] with reproduction steps, and DBX says it will acknowledge receipt and provide investigation updates.dbxray.co · 30 Sept 2026
Intended users
DBX is positioned for developers and teams building PostgreSQL or Supabase applications, including multi-tenant systems and AI-generated SQL workflows.dbxray.co · 30 Sept 2026

Best DBX alternatives

See all 12

Where it ranks on Everything Xiaomi

Is DBX yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources