Skip to content

Secure hosting and the BAA

Tested with: Portal compliance flow · API 1.0.0 (placement: secure) · Team and Enterprise

Secure hosting is a placement option on an instance, not a plan. Any org on Team or Enterprise signs the BAA once, then chooses secure placement only for the databases that hold PHI. Everything else stays on shared standard cells at normal prices.

  1. An org owner opens Compliance → Enable secure hosting (HIPAA) in the portal.
  2. The current BAA (versioned PDF) is shown; enter the legal entity and signatory. Team signs by click-through; Enterprise signs electronically through the contract flow.
  3. On acceptance the API records baa_signed_at and baa_version, emits org.baa_signed.v1, and:
    • MFA becomes mandatory for every member with access to secure instances;
    • the secure placement appears in the instance wizard and the API with its add-on price;
    • secure-only settings unlock (customer-managed keys, log routing, extended retention);
    • audit export becomes available.

The API refuses placement: secure until the BAA is signed (422 baa_required).

ControlShared (standard cell)Secure (HIPAA cell)
NodesShared node poolNode pool dedicated to your org, dedicated hosts; no spot, no CPU over-commit, no auto-pause
Encryption at restPer-tier KMS keyPer-org CMK, or your own KMS key via grant, for volumes and backups
BackupsPer planHourly + PITR, Object Lock (immutable), cross-region, 35-day default
LogsEngine logs in shared storage, statement logging offStatement logging off; if enabled, only to your own bucket
NetworkDefault-deny NetworkPolicyPlus Hubble flow logs kept 6 years, optional required mTLS, optional PrivateLink
AccessStaff cannot read dataPlus break-glass needs a second approver and notifies you
AuditOrg audit logAudit export / SIEM streaming, 6-year retention
ResidencyRegion of choiceRegion pinned; backups and copies stay in-country

Billing: secure_instance_hours plus dedicated node hours on top of the normal compute, storage, egress and backup meters. The wizard shows the total before you create.

shell
zb instances create --engine postgres --size m2 --region us-east --placement secure --name phi-records
zb api PATCH /v1/orgs/{org}/instances/pg-prod -d '{"placement": "secure"}' # backup → restore into the HIPAA cell → route flip

Migrating a shared instance shows the downtime and the new price first; the route flip keeps the hostname. A move needs a secure (HIPAA) cell in the instance’s region: where there is none yet, the API refuses it with that reason and Instance → Settings → Placement says so instead of offering the move.

Under Instance → Settings → Encryption choose the per-org CMK Databasezy manages, or grant our KMS role access to your own key (AWS KMS key policy snippet is shown). Revoking the grant makes the instance and its backups unreadable; the portal warns twice.