What technical controls to limit data exfiltration from servers?

Our contact completing the security review says that we need a little more information on this. Is there something specific that we can use on Render that would prevent someone with access to the production database from downloading data from it?

Also, if it is not possible to limit downloads, is it possible to log who has accessed the data to download?

Note: This is time-sensitive, so we really appreciate your clarification!