IOanyT Innovations
AWS AMI Database v1.0.2

IOanyT Secure PostgreSQL 16

CIS-hardened PostgreSQL 16 that sets itself up securely on first boot.

Delivery method

AWS AMI

Operating system

Ubuntu 24.04 LTS

Architecture

x86_64

Ubuntu 24.04 LTS hardened to CIS Benchmark Level 1, with a documented exceptions list
TLS 1.2+ only network access and SCRAM-SHA-256 passwords
Unique passwords and TLS certificate generated on each instance's first boot
pgAudit logging and opt-in encrypted backups to your own S3 bucket

What it is

IOanyT Secure PostgreSQL 16 is a ready-to-run database server for AWS. It combines PostgreSQL 16 with an operating system hardened to the CIS Benchmark Level 1.

On its first boot, each instance creates its own database cluster, TLS certificate and passwords, so no two customers share a credential. The database accepts only encrypted connections, records schema and role changes with pgAudit, and can back itself up to your own S3 bucket with one command.

Supported instance types: t3 (medium and larger), m6i, m7i, r6i and r7i families. Recommended: t3.medium for development; m7i.large or larger for production; r7i for memory-heavy workloads. Memory settings tune themselves to the instance size on first boot.

IOanyT Innovations is certified to ISO/IEC 27001:2022 and ISO 9001:2015.

Who it's for

Teams that need a self-managed PostgreSQL server that passes a security review on day one.

Regulated environments (SOC 2, ISO 27001, PCI DSS) that need audit logging and hardening evidence.

Developers who want PostgreSQL on EC2 without spending a day on TLS, authentication and backups.

Workloads that must keep data inside their own AWS account and VPC.

Why it's different

Secure by default

Plain-text connections are refused, older password methods are disabled, and there are no default passwords anywhere in the image.

Unique per instance

Credentials, the TLS certificate and the database cluster itself are created on your instance at first boot, never baked into the image.

Backups you control

One command turns on encrypted pgBackRest backups to your own S3 bucket, using the instance's IAM role. No access keys are stored on the server.

Evidence included

Each release ships with a CIS audit report, a documented exceptions list and a package inventory, so your security review starts with facts.

ISO-certified publisher

Built and supported by IOanyT Innovations, certified to ISO/IEC 27001:2022 and ISO 9001:2015.

Security & compliance

Ubuntu 24.04 LTS hardened to CIS Benchmark Level 1 with ansible-lockdown, then checked with 593 automated audit tests. Every remaining finding is documented with its reason.

PostgreSQL accepts TLS 1.2 or newer only; SCRAM-SHA-256 is the only password method; MD5 and trust authentication are disabled.

pgAudit logs schema changes (DDL) and role changes, plus every connection and disconnection.

SSH is key-only and limited to the ubuntu user. The root account is locked.

Backups are encrypted with AES-256 before they leave the server.

No hardcoded credentials: every secret is generated on your instance.

Shared responsibility: IOanyT hardens and maintains the image; you control network access, IAM, operating-system patching and your data.

What's included

Software Version
Ubuntu (CIS Benchmark Level 1 hardened) 24.04 LTS
PostgreSQL (official PostgreSQL apt repository) 16 (16.15 at release)
pgAudit 16.1
pgBackRest 2.59
OpenSSL 3.0

Recommended instances

t3.mediumm7i.largem6i familyr6i familyr7i family

Ports

  • 5432/tcp — PostgreSQL (TLS 1.2+ only)
  • 22/tcp — SSH (key-only, ubuntu user)

Pricing

Pay-as-you-go — $0.06/hr

Hourly (pay-as-you-go)

Billed through AWS Marketplace, on top of standard EC2 charges.

Annual subscription — about $449/yr

Annual contract

Billed through AWS Marketplace, on top of standard EC2 charges.

Frequently asked questions

How is it delivered?

As an Amazon Machine Image (AMI). You launch it in your own AWS account, and your data never leaves your account.

Where do I find the database password?

On the instance, in /root/ioanyt-credentials.txt. It is created on first boot and is readable only by root. See the deployment guide.

Can I connect without TLS?

No. Network connections must use TLS 1.2 or newer. Use sslmode=require or stricter in your client.

Are backups included?

The backup tooling is installed and off by default. Run one command to turn on encrypted backups to an S3 bucket you own.

Is it CIS certified?

It is hardened to the CIS Benchmark Level 1 and audited with 593 automated checks. A small set of controls is documented as exceptions where they don't fit a single-disk cloud image (for example, separate disk partitions). The exceptions list is included with each release.

Can I run Docker or mount EFS/NFS on it?

Not by default: CIS hardening disables unused filesystem modules, including NFS, FUSE and overlay. The deployment guide shows how to re-enable them if you need them.

How much does it cost?

Pay-as-you-go: $0.06 per hour, billed through AWS Marketplace, on top of standard EC2 charges. An annual subscription is available at about $449 per year.

What support is included?

Email support from IOanyT at aws-marketplace-support@ioanyt.com, with a response within one business day.

Support

Email support from IOanyT, with a response within one business day.

Questions or issues? Email aws-marketplace-support@ioanyt.com.

Ready to deploy?

Launch it in your own AWS account, or talk to our team about a custom hardened image for your stack.

Request early access

Runs entirely inside your AWS account