A distributed multimodal database, run for you, inside your region.
Rows, vectors, full-text, graph and natural language on one engine — one atomic commit per write, replicated from the writer to standbys on the active-passive path, and operated as a single-tenant service with the availability terms, recovery objectives and paperwork an enterprise procurement team expects.
- 1 Contractual — Enterprise agreement. /terms § Availability — monthly uptime on Enterprise.
- 2 Control plane `MAX_PITR_RETENTION_DAYS = 35` (operation-backend src/instances/handlers.rs); the console offers 7- and 30-day windows.
- 3 Measured — YCSB, client fan-out; hardware and client count in the methodology section. /benchmarks § 01 YCSB — 50,000 ops across workloads A–F on a 20K-row table, zero errors.
One engine. Every guarantee written down.
Every figure below is drawn from the canonical claims sheet that also feeds our pricing page, FAQ and terms — the same figure appears everywhere, or it appears nowhere.
Dedicated, in your region
Every dedicated configuration is single-tenant, region-isolated: its own compute, storage, hostname and bearer token. Data, transaction logs, backups and the natural-language compile step stay inside the region you choose.
Distributed by design
Active-passive replication is the shipped path and the default: one node holds the writer lease while provisioned standbys tail its stream and can be promoted. Promotion is operator-run by default. An opt-in automatic path can promote a standby once the writer's lease has expired — it stays off unless enabled, relies on an external restart hook, and refuses to promote a standby that is not fully caught up. Quorum-commit replication is roadmap and not scheduled: a request to run a database that way is refused rather than accepted and degraded, and a running database cannot be switched into a quorum group today.
Contractual availability
99.9% on HA, 99.95% on HA+ and 99.99% on Enterprise, with a pro-rata service credit against the next invoice. Summarised on /sla; /terms governs.
Recovery you can put in a runbook
encrypted nightly snapshots, included. Opt-in point-in-time recovery restores to a roll-up boundary, and the spacing of those boundaries follows a configured shipping interval that the Intra-Segment PITR add-on tightens. Retention up to 35 days.
Transactions when you need them
single-row atomic writes with optimistic concurrency (If-Match / _oc_row_version), included. Add multi-row transactions under snapshot isolation with the Transactions add-on.
Security controls on every configuration
TLS 1.2+ in transit · AES-256 at rest · customer-managed keys on Enterprise. per-request audit log on every configuration. HIPAA BAA and GDPR DPA are available on Enterprise agreements.
Built to pass the review.
Security, legal and finance each get a document they can file. Anything not listed here is scoped in the first call.
- Agreement
- Annual contract with negotiated quotas, custom retention and a named support engineer.
- Availability
- 99.99% monthly uptime target on Enterprise; credits per /terms.
- Data protection
- GDPR DPA and HIPAA BAA on request; sub-processor details are provided with the DPA.
- Security review
- Security questionnaire, architecture walkthrough and current SOC 2 letter (audit in progress) on request.
- Keys
- Customer-managed encryption keys on Enterprise.
- Deployment
- Managed in-region by default; private deployments are scoped per engagement.
A pilot with success criteria, not a demo.
We stand up a dedicated instance against your workload shape, agree the numbers that matter before the first byte lands, and hand you a written report at the end. The structure is on the pilot page.
Talk to an engineer, not a deck.
A technical walkthrough is a working session on your workload: data shapes, query patterns, availability target, region. You leave with a sized configuration and a written quote.