Isolation you can explain to your auditor.
Every service isolated at the operating system, least-privilege access for your team, and a complete audit trail — including every time our engineers touch your service.
Example view with sample data.
Isolation
One service, one boundary.
Every Balta service runs as its own operating-system user, in its own control group, on its own storage volume. Services never share a PostgreSQL instance, a filesystem or a process, and no customer has access to the host.
Your team gets a managed admin role rather than superuser, and extensions come from a curated catalogue — so nothing running in your database can reach outside it.
Access
The right access for everyone on your team.
Invite your team with one of five roles — Owner, Admin, Developer, Billing and Viewer — and give developers access to exactly the projects they work on. Require multi-factor authentication for your whole organisation.
Sensitive actions — revealing credentials, deleting a service, changing payment details — ask you to confirm your identity again, even in an active session.
| Name | Role | Projects |
|---|---|---|
| Maria K. | Owner | All |
| Jonas P. | Admin | All |
| Aiste R. | Developer | Client A, Client B |
| Tomas V. | Billing | — |
| Guest | Viewer | Client A |
Multi-factor authentication required for this organisation.
Example view with sample data.
Accountability
Every access, on the record.
Every significant action in your organisation is recorded in an audit log you can read: who changed what, and when.
When a Balta engineer needs to access your service — to help with a ticket, for example — they must record a reason, and their access expires on its own. That access appears in your audit log, with the reason, just like your own team’s actions.
Example view with sample data.
Security built in, not bolted on.
- Its own operating-system user, resources and volume per service
- A managed admin role, never superuser
- No host access for any customer
- Multi-factor authentication, which you can require
- Five team roles and per-project access
- Identity confirmed again for sensitive actions
- Staff access with a recorded reason and automatic expiry
- TLS required on every connection
- Connections limited to the addresses you choose
- Backups written by a separate process with per-service encryption
Data residency
Your data stays in Europe.
Your databases run on dedicated hardware in the EU, and every backup is written to two separate EU countries. We sign a Data Processing Agreement with every customer, our subprocessor register is public, and we give 30 days’ notice before adding a new subprocessor.