Secure hosting
HIPAA-ready hosting, one database at a time
Secure hosting is a placement on an instance, not a separate plan. Sign the Business Associate Agreement once, then put only the databases that hold PHI in the HIPAA cell. Everything else stays on standard cells at normal prices.
The BAA workflow, secure placement, dedicated node pools and per-org keys are built. The first HIPAA cell opens after the external penetration test. On the roadmap
How it works
Secure hosting, step by step
- Step 01
Sign the BAA
An org owner signs under Compliance in the portal. MFA becomes mandatory for everyone with access to secure instances.
- Step 02
Choose secure placement
The secure option appears in the instance wizard and the API. The API refuses it until the BAA is signed.
- Step 03
Run in the HIPAA cell
The instance lands on a node pool dedicated to your org, with a per-org key for volumes and backups and immutable backups.
- Step 04
Export evidence
Stream the audit log to your SIEM or export it, and review backup health and compliance status in the portal.
What you get
-
Dedicated nodes
A node pool tainted for your org only, never on spot capacity, with dedicated hosts in the HIPAA cell.
-
Per-org encryption key
Volumes and backups for secure instances use a key that belongs to your org, separate from the per-tier keys on shared cells.
-
Immutable backups
Hourly backups with PITR, Object Lock and cross-region copies, kept 35 days.
-
A BAA you can read first
The agreement is published. Team signs by click-through; Enterprise signs through the contract flow.
-
MFA for everyone with access
Signing the BAA turns on mandatory MFA for every member who can reach a secure instance.
-
Use your own KMS key
Grant our KMS role access to a key in your own cloud account, so revoking the grant makes the data unreadable.
On the roadmap
Try it
After the BAA is signed, secure placement is one flag.
zb instances create --engine postgres --size m2 \
--placement secure --name phi-records --waitPlan availability
Generated from the same plan catalogue that billing and the API use.
- Not available
Free
$0 /moUpgrade to Team to sign the BAA
- Not available
Solo
$25 /moUpgrade to Team to sign the BAA
- Add-on
Team
$599 /moPer instance, with a signed BAA
- Add-on
Enterprise
CustomPer instance, with a signed BAA
Secure placement adds $0.10 per instance-hour plus dedicated node hours, on top of normal usage. The wizard shows the total before you create.
Questions
Do I need to move my whole org to a HIPAA plan?
No. Secure hosting is chosen per instance. Databases without PHI stay on shared standard cells at normal prices.
What does the BAA cover?
Instances with secure placement, the control plane, the admin portal and the backup accounts for HIPAA buckets. Free and standard cells are out of scope by design, and the portal labels which instances are covered.
Which plans can use it?
Team and Enterprise. Solo and Free orgs upgrade to Team first, then sign the BAA.
Is it certified?
HIPAA has no certification. We sign a BAA and publish a shared responsibility matrix. An external penetration test and SOC 2 Type I are scheduled; see the security page for the timeline.
Related features
-
Isolation
Free, standard and HIPAA workloads run in physically separate cells, and every instance gets its own namespace.
Learn more about Isolation -
Backups and PITR
Scheduled backups to object storage, point-in-time recovery where the engine supports it, and restores rehearsed every week.
Learn more about Backups and PITR -
Network security
TLS on every connection, per-instance IP allow-lists, optional mTLS and support access only with your grant.
Learn more about Network security
Start today
Create your first database
A free instance, no card. Upgrade when you outgrow it; nothing converts silently.