Opt-in client-side encryption for your most sensitive fields. The key lives in your infrastructure, not ours, so WattleDB stores only ciphertext and one-way hashes. Our staff, our backups, and any subpoena served on us see gibberish. And you can still search it.
See it work end-to-end — an interactive preview: encrypt a record, watch only ciphertext cross the wire, then search it without ever decrypting.
Try the live preview →Encryption only means "the provider can't read it" if the provider never holds the key. So the crypto happens in your trust domain, and WattleDB only ever receives the output:
Built on Acra, open-source, audited field encryption, with keys you generate and keep. It layers on top of the WattleDB Postgres you already run, on higher plans, opt-in per database.
WattleDB staff, a server compromise, a stolen backup, and a subpoena served on WattleDB all see only ciphertext and hashes. We can't produce your customers' personal data, because we don't hold the key.
Exact-match lookups (by email, by member number, by name) work server-side through blind indexes, so your app's search and login flows keep working.
If you lose the key, the data is unrecoverable, by design. Key custody becomes your most important operational task. We'll document it thoroughly.
The first release is equality search only (no LIKE/range), and you choose which fields to encrypt versus leave plaintext for querying. We help you choose.
First release is a self-managed beta for developers and builders. The strongest, formally-audited enterprise guarantee follows, we'll be clear at every step about which stage we're at.
Tell us what you're building. We're onboarding a small group of early customers, migrating apps that hold personal data are the best fit, and your feedback shapes what ships.
Australian-owned, Australian-hosted managed Postgres. Start free today; add client-held encryption when it lands.
Get started →