Network security
Only the clients you expect get through
Every connection is encrypted at the gateway and re-encrypted to the pod. Limit each instance to your own address ranges, require client certificates, and keep staff out unless you issue a time-boxed grant.
How it works
Network security, step by step
- Step 01
TLS at the gateway
Clients connect over TLS 1.2 or 1.3. The gateway re-encrypts to the pod with a per-cell private CA.
- Step 02
Allow-list
Set up to 50 CIDR ranges per instance. Connections from anywhere else are refused at the gateway.
- Step 03
Require client certificates
Upload your CA bundle and the gateway only accepts clients with a certificate it signed.
- Step 04
Grant support access
If you need help inside the database, issue a grant to a named staff member for 1 to 72 hours. It is logged and revocable.
What you get
-
TLS everywhere
No plaintext listener. Download your org's CA bundle to verify the server, or rely on the system trust store.
-
IP allow-lists
IPv4 and IPv6 ranges per instance, applied by the gateway on every new connection.
-
Mutual TLS
Your CA bundle is stored sealed; only its fingerprint and subjects are kept in the clear.
-
Custom domains
Serve an instance on your own hostname with a managed certificate after a CNAME check. A paid add-on on Solo, Team and Enterprise.
-
Support access grants
Metadata, read-only or full scope, for 1 to 72 hours. Without an active grant, staff have no path to your data.
-
PrivateLink
Reach instances from your VPC without crossing the internet, through AWS PrivateLink or GCP Private Service Connect.
On the roadmap
Try it
Network settings live under Instance → Settings in the portal, and in the API.
# Allow only your office and your app's egress range
zb api PUT /v1/orgs/{org}/instances/inst_7f3k/network \
-d '{"allow_cidrs": ["203.0.113.0/24", "198.51.100.7/32"]}'
# Verify the server against your org's CA bundle
zb api GET /v1/orgs/{org}/ca.pem > databasezy-ca.pem
zb connect inst_7f3k --ca databasezy-ca.pemPlan availability
Generated from the same plan catalogue that billing and the API use.
- Included
Free
$0 /moTLS and allow-lists
- Included
Solo
$25 /moTLS, allow-lists and the custom domain add-on
- Included
Team
$599 /moTLS, allow-lists, mTLS and the custom domain add-on
- Included
Enterprise
CustomTLS, allow-lists, mTLS, custom domain add-on · PrivateLink on the roadmap
Support access grants are available on every plan. PrivateLink is planned for Enterprise and secure placement.
Questions
Can I connect without TLS?
No. The gateway only accepts TLS. Most drivers verify against the system trust store; you can also download your org's CA bundle.
What happens if I lock myself out with the allow-list?
Change the list in the portal or through the API. The change reaches the gateway within moments, and every change is audited.
Until PrivateLink ships, how do I keep traffic private?
Use the IP allow-list with a NAT gateway or static egress addresses, and require mTLS on Team and Enterprise.
How do I know when staff accessed my database?
Grants are created by you, are time-boxed and revocable, and creation, use and revocation are written to your audit log.
Related features
-
Isolation
Free, standard and HIPAA workloads run in physically separate cells, and every instance gets its own namespace.
Learn more about Isolation -
Secure hosting
HIPAA-ready placement you turn on per database, under a signed BAA, with dedicated nodes and per-org keys.
Learn more about Secure hosting -
Teams and roles
Roles that mean something, project-scoped access, budgets, approval requests and SSO on Team and Enterprise.
Learn more about Teams and roles
Start today
Create your first database
A free instance, no card. Upgrade when you outgrow it; nothing converts silently.