World's first sealed Postgres
The Cellar
The Cellar is Zipper’s sealed Postgres. Queries arrive as HTTP statements through Zipper A. There is no Postgres wire protocol, no long-lived connection string, and no public :5432. Every client holds a capability seal (role, tables, ops, TTL). Branches are overlay copies — a preview fork writes only the rows that change. Tenant SQL is parsed in Zipper’s dialect and never sent to the host Postgres parser. Default-deny row policies, envelope encryption, and plan row caps are on. It is not Amazon RDS and it is not Neon’s storage split; it is production sealed-query Postgres on two VPS nodes.
Sealed query
World's first sealed Postgres
No port 5432. Tenant SQL is parsed on Zipper A and never sent to the host Postgres parser. Overlay branches write only changed rows.
Public sealed sandbox — statements never persist. Sign in to open a workspace cellar.
- ▸ World’s first sealed Postgres (no :5432)
- ▸ Capability seals, not connection strings
- ▸ Overlay branches (copy-on-write rows)
- ▸ Tenant SQL never reaches host Postgres
Auto-provisioned on every new zone. Read the The Cellar docs, including use cases and API examples. Manage it from the dashboard after you create an account.
Create an account