Secure hosting and the BAA
Tested with: Portal compliance flow · API 1.0.0 (placement: secure) · Team and Enterprise
Secure hosting is a placement option on an instance, not a plan. Any org on Team or Enterprise signs the BAA once, then
chooses secure placement only for the databases that hold PHI. Everything else stays on shared standard cells at
normal prices.
Signing the BAA
Section titled “Signing the BAA”- An org owner opens Compliance → Enable secure hosting (HIPAA) in the portal.
- The current BAA (versioned PDF) is shown; enter the legal entity and signatory. Team signs by click-through; Enterprise signs electronically through the contract flow.
- On acceptance the API records
baa_signed_atandbaa_version, emitsorg.baa_signed.v1, and:- MFA becomes mandatory for every member with access to secure instances;
- the
secureplacement appears in the instance wizard and the API with its add-on price; - secure-only settings unlock (customer-managed keys, log routing, extended retention);
- audit export becomes available.
The API refuses placement: secure until the BAA is signed (422 baa_required).
What secure placement changes
Section titled “What secure placement changes”| Control | Shared (standard cell) | Secure (HIPAA cell) |
|---|---|---|
| Nodes | Shared node pool | Node pool dedicated to your org, dedicated hosts; no spot, no CPU over-commit, no auto-pause |
| Encryption at rest | Per-tier KMS key | Per-org CMK, or your own KMS key via grant, for volumes and backups |
| Backups | Per plan | Hourly + PITR, Object Lock (immutable), cross-region, 35-day default |
| Logs | Engine logs in shared storage, statement logging off | Statement logging off; if enabled, only to your own bucket |
| Network | Default-deny NetworkPolicy | Plus Hubble flow logs kept 6 years, optional required mTLS, optional PrivateLink |
| Access | Staff cannot read data | Plus break-glass needs a second approver and notifies you |
| Audit | Org audit log | Audit export / SIEM streaming, 6-year retention |
| Residency | Region of choice | Region pinned; backups and copies stay in-country |
Billing: secure_instance_hours plus dedicated node hours on top of the normal compute, storage, egress and backup
meters. The wizard shows the total before you create.
Creating or migrating a secure instance
Section titled “Creating or migrating a secure instance”zb instances create --engine postgres --size m2 --region us-east --placement secure --name phi-recordszb api PATCH /v1/orgs/{org}/instances/pg-prod -d '{"placement": "secure"}' # backup → restore into the HIPAA cell → route flipMigrating a shared instance shows the downtime and the new price first; the route flip keeps the hostname. A move needs a secure (HIPAA) cell in the instance’s region: where there is none yet, the API refuses it with that reason and Instance → Settings → Placement says so instead of offering the move.
Customer-managed keys
Section titled “Customer-managed keys”Under Instance → Settings → Encryption choose the per-org CMK Databasezy manages, or grant our KMS role access to your own key (AWS KMS key policy snippet is shown). Revoking the grant makes the instance and its backups unreadable; the portal warns twice.