We run it for you.
Spin up a fully managed PostgreSQL cluster — high availability, backups and monitoring included. More engines on the way.
Provision, manage and monitor your databases — and govern who connects. Every developer gets access by identity, with sensitive data masked and every query on the audit trail.
Relay provisions, manages and monitors your databases. And when a developer, analyst or teammate needs to query one, Relay secures that access by identity — masking sensitive data per person and auditing every query. It governs the people who connect, not your apps.
People connect by name — not your apps. Every developer, analyst and teammate carries an identity Relay recognizes before a single query runs.
Relay sits in the middle. It authenticates each identity, masks sensitive columns per person, and audits every query that passes through.
Postgres and Mongo that Relay provisions, manages and monitors — reached only through Relay, never connected to directly.
However your data needs to live, Relay runs it.
Spin up a fully managed PostgreSQL cluster — high availability, backups and monitoring included. More engines on the way.
Register an existing database wherever it lives. Relay adds identity, masking and audit — without moving your data.
Relay provisions into your own AWS or GCP account and runs day-2 for you. You keep ownership, we keep it healthy.
When you hire your first analyst, support agent, or contractor, they need to query production. Relay’s AI automatically detects sensitive columns — PII, secrets, financials — and masks them per-column based on identity: your admin sees real values, your developers see masked ones, your auditor sees nothing.
| user | phone | card | ssn | |
|---|---|---|---|---|
| alice | alice@acme.io | +1 415 555 4821 | 4242 4242 4242 4242 | 078-05-1120 |
| marcus | marcus@acme.io | +1 312 555 7727 | 5500 0000 5555 5559 | 141-92-7731 |
| priya | priya@acme.io | +44 7700 900812 | 3782 822463 10005 | 205-31-6649 |
Clusters start in one region. When you need global reach, flip it on: pick regions across AWS, GCP and Azure and Relay places electable nodes, read replicas and failover for you.
Single-region by default. Go global in a few clicks — Relay handles the topology.
Relay watches every cluster and keeps it healthy — so you don't get paged.
Storage, compute and read replicas grow with load — no manual resize, no downtime.
Scheduled backups and point-in-time recovery, ready before you ever need them.
Live metrics, health checks and automatic failover — Relay reacts before you do.
Relay’s agent does the work a DBA would: it reads your schema, flags what’s sensitive, and drafts the masking and access policy. You review and approve from the CLI or dashboard — Relay applies it and keeps the audit trail.
Reads your schema and tags PII, secrets, and financial columns — no manual lists to maintain.
Proposes per-role masking and access grants from what it found — ready for you to review.
Nothing changes until you sign off, from the CLI or the dashboard.
Then logs every query against the identity that ran it — who saw what, and when.
Preview — today you drive Relay from the CLI and dashboard.
Connections, a wire-protocol security layer, and self-hosted agent pools — three facets of one product. They work together because they're built together, around a single proxy.
Provision a new PostgreSQL instance or register the MongoDB you already run — wherever it lives. Relay holds the credentials, your team gets a single endpoint that respects identity, role, and policy.
The agent speaks the database wire protocol natively. AI flags the sensitive columns, they get masked before they leave the agent, queries get logged with the identity that ran them, and your app never sees a different driver.
Group lightweight agents into pools — one per region, one per VPC, one per environment. The agents sit next to your databases. Your data plane stays inside your network; only encrypted control traffic crosses the boundary.
There’s no setup ceremony. Provision, grant access, connect — that’s it. New teammate? They run one command and they’re in, with the right masking applied automatically.
Provision a fresh PostgreSQL instance, or point Relay at the MongoDB cluster you already run. Credentials are stored in the vault and never exposed to end users.
AI flags the sensitive columns; you set per-column masking and per-role grants. Every query inherits the policy of the identity running it.
A local port comes up. psql, mongosh, DBeaver, your ORM — all work unchanged.
Relay speaks PostgreSQL at the wire protocol, so psql, your ORM and every client connect unchanged. More engines are on the way. Run the agent next to your databases — no SDKs, no driver swaps, no app changes.
When your security team asks how database access actually works, you have answers — not a Slack channel of one-off scripts. Identity-tied audit, role-based access, and team-scoped grants come standard.
The agent emits one event per connection and query — identity, source, columns touched, what got masked. Append-only JSONL you can ship anywhere downstream.
Connection groups, team grants, environment scoping. Owner / Admin / Member / Viewer roles baked in. Sign in with Google.
mTLS in flight. Masking enforced inside the agent — sensitive bytes never leave it unmasked. No app-side trust required, no SDK to import.
Whether you’re shipping your first MVP solo, growing a team past five, or running a platform with hundreds of databases — Relay scales with you. Same product, different defaults.
The day you give your first contractor access to production, masking is already wired in. Define a grant, share the connection name — they connect with their own client and only see what their role allows.
Get early access →Your support team needs queries. Your analysts need real numbers. Nobody needs raw PII. Per-column masking and per-query audit make that the default, not the exception.
Get early access →One control plane across PostgreSQL and MongoDB. Self-host the agent pools next to each environment. Drive everything from the CLI or the dashboard.
Get early access →Connections, agent pools, column-level masking, and per-query audit are live — provision PostgreSQL or connect your existing MongoDB, with more engines on the way. Drop your email and we’ll reach out as slots open up.