IOanyT Secure PostgreSQL 16
CIS-hardened PostgreSQL 16 that sets itself up securely on first boot.
Delivery method
AWS AMI
Operating system
Ubuntu 24.04 LTS
Architecture
x86_64
What it is
IOanyT Secure PostgreSQL 16 is a ready-to-run database server for AWS. It combines PostgreSQL 16 with an operating system hardened to the CIS Benchmark Level 1.
On its first boot, each instance creates its own database cluster, TLS certificate and passwords, so no two customers share a credential. The database accepts only encrypted connections, records schema and role changes with pgAudit, and can back itself up to your own S3 bucket with one command.
Supported instance types: t3 (medium and larger), m6i, m7i, r6i and r7i families. Recommended: t3.medium for development; m7i.large or larger for production; r7i for memory-heavy workloads. Memory settings tune themselves to the instance size on first boot.
IOanyT Innovations is certified to ISO/IEC 27001:2022 and ISO 9001:2015.
Who it's for
Teams that need a self-managed PostgreSQL server that passes a security review on day one.
Regulated environments (SOC 2, ISO 27001, PCI DSS) that need audit logging and hardening evidence.
Developers who want PostgreSQL on EC2 without spending a day on TLS, authentication and backups.
Workloads that must keep data inside their own AWS account and VPC.
Why it's different
Secure by default
Plain-text connections are refused, older password methods are disabled, and there are no default passwords anywhere in the image.
Unique per instance
Credentials, the TLS certificate and the database cluster itself are created on your instance at first boot, never baked into the image.
Backups you control
One command turns on encrypted pgBackRest backups to your own S3 bucket, using the instance's IAM role. No access keys are stored on the server.
Evidence included
Each release ships with a CIS audit report, a documented exceptions list and a package inventory, so your security review starts with facts.
ISO-certified publisher
Built and supported by IOanyT Innovations, certified to ISO/IEC 27001:2022 and ISO 9001:2015.
Security & compliance
Ubuntu 24.04 LTS hardened to CIS Benchmark Level 1 with ansible-lockdown, then checked with 593 automated audit tests. Every remaining finding is documented with its reason.
PostgreSQL accepts TLS 1.2 or newer only; SCRAM-SHA-256 is the only password method; MD5 and trust authentication are disabled.
pgAudit logs schema changes (DDL) and role changes, plus every connection and disconnection.
SSH is key-only and limited to the ubuntu user. The root account is locked.
Backups are encrypted with AES-256 before they leave the server.
No hardcoded credentials: every secret is generated on your instance.
Shared responsibility: IOanyT hardens and maintains the image; you control network access, IAM, operating-system patching and your data.
What's included
| Software | Version |
|---|---|
| Ubuntu (CIS Benchmark Level 1 hardened) | 24.04 LTS |
| PostgreSQL (official PostgreSQL apt repository) | 16 (16.15 at release) |
| pgAudit | 16.1 |
| pgBackRest | 2.59 |
| OpenSSL | 3.0 |
Recommended instances
Ports
- 5432/tcp — PostgreSQL (TLS 1.2+ only)
- 22/tcp — SSH (key-only, ubuntu user)
Pricing
Pay-as-you-go — $0.06/hr
Hourly (pay-as-you-go)
Billed through AWS Marketplace, on top of standard EC2 charges.
Annual subscription — about $449/yr
Annual contract
Billed through AWS Marketplace, on top of standard EC2 charges.
Frequently asked questions
How is it delivered?
As an Amazon Machine Image (AMI). You launch it in your own AWS account, and your data never leaves your account.
Where do I find the database password?
On the instance, in /root/ioanyt-credentials.txt. It is created on first boot and is readable only by root. See the deployment guide.
Can I connect without TLS?
No. Network connections must use TLS 1.2 or newer. Use sslmode=require or stricter in your client.
Are backups included?
The backup tooling is installed and off by default. Run one command to turn on encrypted backups to an S3 bucket you own.
Is it CIS certified?
It is hardened to the CIS Benchmark Level 1 and audited with 593 automated checks. A small set of controls is documented as exceptions where they don't fit a single-disk cloud image (for example, separate disk partitions). The exceptions list is included with each release.
Can I run Docker or mount EFS/NFS on it?
Not by default: CIS hardening disables unused filesystem modules, including NFS, FUSE and overlay. The deployment guide shows how to re-enable them if you need them.
How much does it cost?
Pay-as-you-go: $0.06 per hour, billed through AWS Marketplace, on top of standard EC2 charges. An annual subscription is available at about $449 per year.
What support is included?
Email support from IOanyT at aws-marketplace-support@ioanyt.com, with a response within one business day.
Support
Email support from IOanyT, with a response within one business day.
Questions or issues? Email aws-marketplace-support@ioanyt.com.
Ready to deploy?
Launch it in your own AWS account, or talk to our team about a custom hardened image for your stack.
Request early accessRuns entirely inside your AWS account