Why Sovereign Features Architecture For Developers FAQ Industries
Australia's First Sovereign Backend-as-a-Service
Sandbox Waitlist Open — AU Developers Only

Build like it's Supabase.
Comply like it's the Privacy Act.

Instant Postgres REST & GraphQL APIs, authentication, object storage, and transactional email — on 100% Australian-owned infrastructure. No CLOUD Act exposure. No foreign jurisdiction. Open source at the core.

Sydney & Canberra zones · 100% Australian-owned · Open source stack

You're on the list

We'll be in touch with sandbox access details shortly.

terminal — ~/my-saas-app
$ npx wattledb init --region=au-syd
Provisioning sovereign Postgres instance...
✓ Database ready — Sydney Zone
✓ Auth service active — GoTrue (local)
✓ REST API live — PostgREST
✓ Storage bucket created — S3-compat
API: https://myapp.wattledb.com.au/rest/v1
Your backend is live. Zero data leaves Australian soil.
100%
Australian owned
& operated
$50M+
Max Privacy Act
penalty per breach
0
Foreign jurisdictions
over your data
Jul 2026
Gov cloud-first
policy takes effect

A Sydney Data Centre Doesn't Make You Sovereign

Most Australian developers pick "ap-southeast-2" and assume they're compliant. But if your backend provider is a US-incorporated company, your data is legally reachable under the US CLOUD Act — regardless of where the servers sit. American authorities can compel disclosure without going through Australian courts.

The Australia-US CLOUD Act agreement came into force in May 2026, formalising cross-border data access between the two governments. Meanwhile, the Privacy Act 2024 amendments introduced penalties of up to $50 million, three times the benefit obtained, or 30% of adjusted turnover — whichever is greatest — per contravention of a serious interference with privacy.

And from 1 July 2026, the Whole-of-Government Cloud Computing Policy mandates cloud-first for all new federal digital and ICT initiatives. Agencies must use infrastructure hosted in certified, sovereignty-compliant facilities.

Sources: Privacy and Other Legislation Amendment Act 2024 (Cth) · OAIC Regulatory Action Guide · DTA Cloud Computing Policy (Dec 2025)

Sovereignty Checkpoint US-Owned BaaS(Firebase, Supabase Cloud, etc.) WattleDB
Servers physically in Australia Yes Yes
Parent entity 100% Australian-owned No — US parent Yes — AU Pty Ltd
Outside reach of US CLOUD Act No Yes
All support staff Australian citizens Global workforce Onshore only
Transactional email routed locally Offshore relays AU-only SMTP
Object storage under AU jurisdiction US entity control S3-compat, AU-only
Architected for IRAP assessment Not applicable ISM-aligned controls

Everything You Need to Ship. Nothing That Leaves the Country.

The developer experience of a modern BaaS, backed by battle-tested open-source components, inside a sovereignty perimeter no foreign law can pierce.

Instant Postgres REST & GraphQL APIs

Point WattleDB at your PostgreSQL schema and get auto-generated, production-ready REST endpoints via PostgREST. Full CRUD, filtering, pagination, and OpenAPI docs — zero backend code required.

PostgREST · Open Source
🔒

Sovereign Auth & Row-Level Security

User registration, login, password recovery, and JWT issuance — all running locally on GoTrue. Pairs natively with Postgres RLS so your access policies live in the database, not in application code.

GoTrue · Open Source
📨

Local-Only Transactional Email

Signup confirmations, password resets, and magic links routed exclusively through Australian SMTP infrastructure. Verification tokens never traverse overseas relays or foreign-owned mail networks.

AU SMTP · On-Soil Routing
📦

S3-Compatible Object Storage

Upload and serve files with full S3 API compatibility. Patient records, government documents, user assets — stored with data residency guarantees and fine-grained access control via storage policies.

S3 API · AU Residency
🔄

Realtime Subscriptions

Listen to database changes over secure WebSocket connections. Build collaborative features, live dashboards, and notification systems — all traffic stays within Australian network boundaries.

Coming Soon
⚙️

Edge Functions (AU Nodes)

Deploy server-side logic to Australian edge nodes. Run custom business rules, webhooks, and integrations close to your users without data ever leaving the sovereignty perimeter.

Coming Soon

Every Layer. Australian Soil.

From your frontend to the database — every hop, every byte, every service stays within Australian jurisdiction.

Your App
React · Next.js · Flutter · Mobile · Any Client
TLS 1.3 · HTTPS / WSS
WattleDB Platform
PostgRESTREST API
GoTrueAuth & JWTs
SMTP RelayAU-Only Mail
Storage APIS3-Compat
Encrypted Private Network
Sovereign Infrastructure
Sydney (Primary)
Canberra (DR/Backup)

Ship Your SaaS in Days, Not Months

If you've used Supabase or Firebase, you already know how WattleDB works. Same developer speed — sovereign by default.

app.js
import { createClient } from '@wattledb/js'

const db = createClient(
  'https://myapp.wattledb.com.au',
  'your-anon-key'
)

// Fetch all active users
const { data, error } = await db
  .from('users')
  .select('id, name, email')
  .eq('active', true)

// Data never left Australia ✓
🚀

Familiar API, Zero Migration Pain

Supabase-compatible client libraries for JavaScript, Python, Dart, and Swift. Switch your connection string and you're sovereign.

🛠️

Your Schema Is Your API

Define tables in Postgres. WattleDB auto-generates type-safe REST endpoints, handles auth, and enforces RLS — no ORM, no route files.

📊

Dashboard & CLI

Web-based dashboard for database management, user admin, and storage browsing. CLI for local development, migrations, and CI/CD pipelines.

🌍

Build for Australia, Sell Globally

Start sovereign for your AU customers. Your architecture doesn't change when you expand — just add regions later.

Win Deals That Demand Sovereignty

Tick the compliance box on day one. Close contracts your US-hosted competitors can't touch.

🏥

HealthTech & MedTech

Meet My Health Records Act residency requirements and pass hospital procurement audits. Patient data stays under Australian jurisdiction — no CLOUD Act loophole.

OAIC · My Health Records Act
🏛️

GovTech & Defence

Align with the Whole-of-Government Cloud Policy (effective Jul 2026) and the Hosting Certification Framework. Build on infrastructure designed for IRAP assessment at PROTECTED level.

DTA · ISM · PSPF
💳

FinTech & InsurTech

Satisfy APRA CPS 234 information security requirements and demonstrate data sovereignty to enterprise clients. Win RFPs that require 100% Australian jurisdictional control.

APRA CPS 234 · Privacy Act

No Lock-in. Full Transparency.

WattleDB is built on proven open-source components. Audit every line. Export your data any time. No proprietary black boxes.

🐘

PostgreSQL

The world's most advanced open-source database

PostgREST

Auto-generated REST API from your schema

🔐

GoTrue

JWT-based auth & user management

📦

S3-Compatible

Standard object storage protocol

Questions From the Waitlist

How is WattleDB different from self-hosting Supabase on AWS Sydney?

Self-hosting on AWS Sydney puts your data in Australia physically, but AWS is a US-incorporated company subject to the CLOUD Act. A US warrant can compel AWS to hand over data from any region without notifying you or going through Australian courts. WattleDB is a 100% Australian Pty Ltd — no foreign parent entity, no foreign legal exposure. The entire stack, including support personnel, is onshore and under Australian law.

What does "architected for IRAP assessment" actually mean?

IRAP (Infosec Registered Assessors Program) is not a certification you pass or fail — it's a risk-based assessment framework run by the Australian Cyber Security Centre. Our infrastructure is designed from the ground up to align with the Australian Government Information Security Manual (ISM) controls, making the path to a successful IRAP assessment at PROTECTED level substantially shorter and cheaper for your organisation.

Can I use WattleDB if my app also serves users outside Australia?

Absolutely. WattleDB gives you sovereign infrastructure for your Australian data and compliance requirements. Your frontend can serve users globally — API responses are delivered over standard HTTPS. Many SaaS companies need AU sovereignty for domestic customers while operating internationally. Start sovereign, scale globally.

I already use Supabase. How hard is migration?

WattleDB uses the same open-source stack that Supabase is built on — PostgreSQL, PostgREST, and GoTrue. Our client libraries are API-compatible. In many cases, migration is as simple as updating your connection string and API URL. We provide migration tooling and guides, and our onshore team helps with hands-on support during the transition.

What's the pricing model?

We'll share detailed pricing with our sandbox cohort. Expect a usage-based model similar to what you're used to from Supabase, with a free tier for development. Sovereign infrastructure has a cost premium over hyperscale providers, but it's a fraction of the compliance cost — and a rounding error next to a $50M penalty.

Who is behind WattleDB?

WattleDB is built by RR Sols Pty Ltd, a 100% Australian-owned company. Our team are Australian citizens with backgrounds in cloud infrastructure, database engineering, and regulated-industry compliance. We're building the tool we wished existed when selling SaaS into Australian government and healthcare.

Limited initial cohort — applications reviewed weekly

Ready to Build Without Border Risk?

We're onboarding our first cohort of Australian developers and startups. Get sandbox access, shape the product roadmap, and be first to market with a sovereign backend.

No credit card · Free sandbox tier · Cancel any time

You're on the list

We'll be in touch with sandbox access details shortly.

Disclaimer: Information on this page about Australian regulations, penalties, and compliance requirements is provided for general informational purposes only and does not constitute legal advice. Regulatory frameworks evolve and individual circumstances vary. Consult a qualified legal professional for advice specific to your situation.
You're on the waitlist!