Free SQL Server Security Tools & Checklists

Professional-grade tools and foundational checklists to safely audit and secure your SQL Server environment.

Get-SqlSafe.ps1: The Sarpedon SQL Server Security Community Assessment

Run 25 core SQL Server security checks, completely free.

Get-SqlSafe Community Edition is a free PowerShell-based assessment for Microsoft SQL Server 2016 through 2025 that checks 25 core SQL Server security indicators and generates an HTML report with a visual summary.

The Community Edition focuses on selected baseline areas that frequently reveal broader security hygiene issues: auditing gaps, NTLM usage, excessive privileges, risky role memberships, orphaned users, invalid ownership mappings, and security-relevant configuration choices.

It comes with a simple visual connection dialog and is designed to be transparent, built around a least-privilege execution model, and does not change SQL Server configuration or data. It runs read-only under a least-privilege model, making it safe for production environments.

This Community Edition does not replace a full SQL Server Security Assessment. It is intended to provide a practical first look at SQL Server’s high-level security posture and help start the conversation on securing your database server.

Get-SqlSafe Community Edition, free SQL Server security assessment tool HTML report

The Database Application Vendor’s SQL Server Security & High Availability Checklist

A blueprint for secure-by-default, resilient data applications.

As a database application vendor, the security and reliability of your software are key competitive differentiators. As a Database Administrator, your priority is ensuring that hosted databases do not expose data or the environment to risk. We developed this checklist to bridge that gap. Following this guidance not only helps align with ISO 27001 controls, but ensures that your product can be trusted against the backdrop of a demanding enterprise environment and an evolving threat landscape.

View the Checklist online: The Database Application Vendor’s SQL Server Security & High Availability Checklist​

Need help interpreting your script results or auditing a complex environment?