Skip to content
Databasezy

Network security

Only the clients you expect get through

Every connection is encrypted at the gateway and re-encrypted to the pod. Limit each instance to your own address ranges, require client certificates, and keep staff out unless you issue a time-boxed grant.

Network security, step by step

  1. Step 01

    TLS at the gateway

    Clients connect over TLS 1.2 or 1.3. The gateway re-encrypts to the pod with a per-cell private CA.

  2. Step 02

    Allow-list

    Set up to 50 CIDR ranges per instance. Connections from anywhere else are refused at the gateway.

  3. Step 03

    Require client certificates

    Upload your CA bundle and the gateway only accepts clients with a certificate it signed.

  4. Step 04

    Grant support access

    If you need help inside the database, issue a grant to a named staff member for 1 to 72 hours. It is logged and revocable.

What you get

  • TLS everywhere

    No plaintext listener. Download your org's CA bundle to verify the server, or rely on the system trust store.

  • IP allow-lists

    IPv4 and IPv6 ranges per instance, applied by the gateway on every new connection.

  • Mutual TLS

    Your CA bundle is stored sealed; only its fingerprint and subjects are kept in the clear.

  • Custom domains

    Serve an instance on your own hostname with a managed certificate after a CNAME check. A paid add-on on Solo, Team and Enterprise.

  • Support access grants

    Metadata, read-only or full scope, for 1 to 72 hours. Without an active grant, staff have no path to your data.

  • PrivateLink

    Reach instances from your VPC without crossing the internet, through AWS PrivateLink or GCP Private Service Connect.

    On the roadmap

Try it

Network settings live under Instance → Settings in the portal, and in the API.

shell
# Allow only your office and your app's egress range
zb api PUT /v1/orgs/{org}/instances/inst_7f3k/network \
  -d '{"allow_cidrs": ["203.0.113.0/24", "198.51.100.7/32"]}'

# Verify the server against your org's CA bundle
zb api GET /v1/orgs/{org}/ca.pem > databasezy-ca.pem
zb connect inst_7f3k --ca databasezy-ca.pem

Plan availability

Generated from the same plan catalogue that billing and the API use.

  • Free

    $0 /mo
    Included

    TLS and allow-lists

  • Solo

    $25 /mo
    Included

    TLS, allow-lists and the custom domain add-on

  • Team

    $599 /mo
    Included

    TLS, allow-lists, mTLS and the custom domain add-on

  • Enterprise

    Custom
    Included

    TLS, allow-lists, mTLS, custom domain add-on · PrivateLink on the roadmap

Support access grants are available on every plan. PrivateLink is planned for Enterprise and secure placement.

Compare every plan on the pricing page

Questions

Can I connect without TLS?

No. The gateway only accepts TLS. Most drivers verify against the system trust store; you can also download your org's CA bundle.

What happens if I lock myself out with the allow-list?

Change the list in the portal or through the API. The change reaches the gateway within moments, and every change is audited.

Until PrivateLink ships, how do I keep traffic private?

Use the IP allow-list with a NAT gateway or static egress addresses, and require mTLS on Team and Enterprise.

How do I know when staff accessed my database?

Grants are created by you, are time-boxed and revocable, and creation, use and revocation are written to your audit log.

Create your first database

A free instance, no card. Upgrade when you outgrow it; nothing converts silently.