Skip to content
Databasezy

Secure hosting

HIPAA-ready hosting, one database at a time

Secure hosting is a placement on an instance, not a separate plan. Sign the Business Associate Agreement once, then put only the databases that hold PHI in the HIPAA cell. Everything else stays on standard cells at normal prices.

The BAA workflow, secure placement, dedicated node pools and per-org keys are built. The first HIPAA cell opens after the external penetration test. On the roadmap

Secure hosting, step by step

  1. Step 01

    Sign the BAA

    An org owner signs under Compliance in the portal. MFA becomes mandatory for everyone with access to secure instances.

  2. Step 02

    Choose secure placement

    The secure option appears in the instance wizard and the API. The API refuses it until the BAA is signed.

  3. Step 03

    Run in the HIPAA cell

    The instance lands on a node pool dedicated to your org, with a per-org key for volumes and backups and immutable backups.

  4. Step 04

    Export evidence

    Stream the audit log to your SIEM or export it, and review backup health and compliance status in the portal.

What you get

  • Dedicated nodes

    A node pool tainted for your org only, never on spot capacity, with dedicated hosts in the HIPAA cell.

  • Per-org encryption key

    Volumes and backups for secure instances use a key that belongs to your org, separate from the per-tier keys on shared cells.

  • Immutable backups

    Hourly backups with PITR, Object Lock and cross-region copies, kept 35 days.

  • A BAA you can read first

    The agreement is published. Team signs by click-through; Enterprise signs through the contract flow.

  • MFA for everyone with access

    Signing the BAA turns on mandatory MFA for every member who can reach a secure instance.

  • Use your own KMS key

    Grant our KMS role access to a key in your own cloud account, so revoking the grant makes the data unreadable.

    On the roadmap

Try it

After the BAA is signed, secure placement is one flag.

shell
zb instances create --engine postgres --size m2 \
  --placement secure --name phi-records --wait

Plan availability

Generated from the same plan catalogue that billing and the API use.

  • Free

    $0 /mo
    Not available

    Upgrade to Team to sign the BAA

  • Solo

    $25 /mo
    Not available

    Upgrade to Team to sign the BAA

  • Team

    $599 /mo
    Add-on

    Per instance, with a signed BAA

  • Enterprise

    Custom
    Add-on

    Per instance, with a signed BAA

Secure placement adds $0.10 per instance-hour plus dedicated node hours, on top of normal usage. The wizard shows the total before you create.

Compare every plan on the pricing page

Questions

Do I need to move my whole org to a HIPAA plan?

No. Secure hosting is chosen per instance. Databases without PHI stay on shared standard cells at normal prices.

What does the BAA cover?

Instances with secure placement, the control plane, the admin portal and the backup accounts for HIPAA buckets. Free and standard cells are out of scope by design, and the portal labels which instances are covered.

Which plans can use it?

Team and Enterprise. Solo and Free orgs upgrade to Team first, then sign the BAA.

Is it certified?

HIPAA has no certification. We sign a BAA and publish a shared responsibility matrix. An external penetration test and SOC 2 Type I are scheduled; see the security page for the timeline.

Create your first database

A free instance, no card. Upgrade when you outgrow it; nothing converts silently.