PackDB for Enterprise

The same tenant-isolated, fully managed platform your developers can evaluate self-serve today, with security, deployment, and support terms scoped for procurement.

Isolation and identity

What the platform enforces today.

Authenticated on every transport

HTTP, OTLP gRPC, and Flight SQL all run one auth pipeline: identity resolution, then explicit per-route policy enforcement. No route ships without a declared policy.

Tenant isolation by construction

Customer-facing credentials — tenant-scoped API keys and user sessions — are bound to your workspace's org id, and every query and ingest request is scoped to it server-side. A mismatched tenant header is rejected, not reconciled.

Scoped machine credentials

API keys are issued by the control plane, bound to your workspace, and role-backed (reader, writer, admin) — with last-use tracking for key hygiene.

Per-user query attribution

Dashboard queries run as short-lived per-user tokens rather than a shared workspace key, so query activity attributes to the person who ran it.

Per-workspace limits and usage

Each workspace carries its own resource limits, quota enforcement, and a live usage envelope — visible in the dashboard, enforced at the platform.

How procurement works

  1. 1. Evaluate self-serve

    Start on the free self-serve evaluation — no credit card, no sales gate — and prove the query surfaces and Grafana-compatible datasources against a real workload.

  2. 2. Scope with sales

    Bring your security questionnaire, identity and compliance requirements, and deployment needs. The default is the fully managed cloud; a dedicated cluster, a specific region, or private networking is scoped here. Enterprise pricing is custom, as the pricing page states.

  3. 3. Contract and onboard

    Support terms, response expectations and escalation contacts are written into the contract, and the production setup — workspaces, keys, and retention — is scoped alongside them. Our privacy policy is public.