The most dangerous database is not the one that goes down. It is the one everyone is afraid to touch. Somewhere inside a company, a developer needs to reproduce a customer bug, a tester needs believable records, and an AI agent wants to alter a schema with the confidence of a toddler holding a permanent marker. Production contains the truth. Production is also the one room where experiments are forbidden.
The short branch
- Xata makes isolated, copy-on-write branches of real PostgreSQL databases, with anonymization for sensitive data.
- Its cloud starts at $0.012 per compute hour plus $0.28 per GB-month; scaled-to-zero branches do not consume compute.
- The company rebuilt its original serverless database around vanilla Postgres, open-source tools, and storage separated from compute.
- The idea fits CI, preview environments, AI agents, and database-per-tenant platforms. It is less compelling for one small, always-on database with no branching problem.
Xata's answer is charmingly literal: make another room. A branch carries the production schema and data but lives behind its own credentials. Mask the personal information. Let the developer, preview deployment, or coding agent work there. Keep only the blocks that change. When the job is finished, delete the room.
This is what Xata does now. The phrase now matters. Founded by Monica Sarbu in 2020, the company first arrived as a serverless database with the usability of a spreadsheet. It offered an elegant interface, a unified API, search, analytics, and database branches. In 2022, that proposition helped it raise a $30 million Series A from Redpoint and Index Ventures, following a $5 million seed round. The funding bought ambition. Experience supplied an edit.
Act IThe spreadsheet was lovely. The problem was sharper.
Sarbu had found the original problem while building Tupu.io, a nonprofit that matched underrepresented people in technology with mentors. She wanted little operational fuss. Her database options supplied rather a lot of it. The first Xata pitch followed naturally: a database friendly enough for developers and non-developers alike.
But “friendly database” is a crowded party. Supabase offered a whole backend around Postgres. Neon made serverless Postgres and branching legible. AWS, Google, and Microsoft already rented databases by the hectare. Xata listened to customers and rebuilt. In May 2025 it relaunched as “Postgres at scale,” centered on copy-on-write branching, anonymization, and cloud-agnostic deployment. Sarbu later described the messaging revelation plainly: the uniqueness was not managed Postgres. It was real data.
“Our uniqueness isn't managed Postgres. It's real data.”Monica Sarbu, founder and CEO
That changed the product's job. Xata no longer had to persuade a cautious CTO to move the production database merely to improve development. An RDS or Aurora customer could keep production where it was, replicate into Xata, anonymize the stream, and create branches from the safe copy. This was less romantic than replacing the incumbent and considerably easier to approve.
The production database keeps serving customers. The experiments inherit its shape, not its danger.
The mechanismPostgres stays boring. The floor moves.
Xata does not fork PostgreSQL. It runs vanilla Postgres in containers managed by Kubernetes and CloudNativePG. The invention sits underneath. Storage and compute are separated, with logical volumes delivered over NVMe-oF. A branch is a storage-level copy-on-write snapshot: it sees the parent's data immediately but consumes new storage mainly when its contents diverge. Standard Postgres tools and extensions continue to behave like standard Postgres tools.
The latest storage system is Xatastor, built with ZFS and NVMe-oF for an odd workload: enormous numbers of mostly sleeping volumes. Classic high-performance storage likes a few hot volumes. Xata wants thousands of idle database branches to occupy disk without also reserving fleets of compute. Its warm pools keep prepared Postgres environments near the starting line. According to Xata, branch provisioning fell from more than 20 seconds to roughly one or two.
About 1,000 micro branches, each awake for five minutes.
Compute is billed by the minute and disappears at scale-to-zero. A child branch pays storage mainly for its changes, not for another full copy of the parent.
That is the price that makes the product more than a nicer staging database. Enginy creates a branch on every CI build. Runner, an AI e-commerce builder, lets autonomous agents divide work, open pull requests, and create thousands of branches a week. Xata says Runner's monthly bill is under $30, versus an estimated $600-plus without scale-to-zero. The claim is specific to short-lived, lightly changed branches. Leave every branch running, write large deltas, or push sustained heavy workloads, and the fairy tale returns to accounting.
The useful failureWhat lost first - and what the loss taught
Infrastructure companies rarely volunteer a clean defeat. Xata did. Its pgstream tool replicates PostgreSQL data and schema changes, with transformations such as anonymization. Early snapshot performance lagged behind the venerable pg_dump and pg_restore. The read side looked healthy. Observability exposed the write path as the bottleneck.
The repair was not mystical. The team switched bulk loading to PostgreSQL's COPY FROM, then postponed indexes, constraints, and triggers until after the data arrived - the same old trick used by the tools it was trying to beat. On the team's IMDb benchmark, pgstream moved ahead. The lesson worth stealing is not “use COPY,” although one should. It is to instrument before inventing and to copy mature software without vanity when its choices have survived a decade of abuse.
Better telemetry identified writes, not reads, as the first constraint.
Bulk snapshots needed a different writer from continuous replication.
Indexes and constraints moved until after ingestion, when they were cheaper.
Once the target was met, the team deferred extra tuning instead of polishing indefinitely.
The marketA crowded field, a narrower promise
Neon is the obvious branching comparison. Supabase couples Postgres with authentication, storage, and edge functions. Hyperscalers sell trusted managed databases. Xata's distinction is the bundle: storage-layer branches of unmodified Postgres, anonymization, scale-to-zero, self-hosting, and BYOC across AWS, Azure, or Google Cloud. Its open-source core, pgroll, and pgstream are Apache 2.0. The company charges for managed cloud usage, enterprise operations, compliance, multi-region deployment, and support.
| Choice | Natural strength | The Xata counterpoint |
|---|---|---|
| Neon | Serverless Postgres and mature branching | BYOC, self-hosting, integrated anonymization, storage-layer vanilla Postgres |
| Supabase | Full backend platform and preview workflows | A narrower database infrastructure layer built for data-heavy branches |
| RDS / Aurora | Operational familiarity and cloud integration | Keep production there; add replicated, masked branches beside it |
| Self-managed | Maximum control | Open source remains available, while Cloud and BYOC sell the operations |
The business has three doors. Self-managed Xata OSS is free. Xata Cloud starts at $0.012 per compute hour plus $0.28 per GB-month of storage, with no fee per user or branch. BYOC is quoted as a management fee on cloud spend and adds dedicated engineering, 24/7 support, and enterprise compliance. This model works best where branches are numerous, temporary, and lightly changed. It is a weaker bargain for a team with one modest database, stable test fixtures, no sensitive production data, and no desire to operate Kubernetes. Nor does branching remove the need to test migrations, govern access, or understand PostgreSQL. It merely gives those activities somewhere safer to fail.
What to copyGive each risky idea a cheap room of its own
There is a general principle hiding inside Xata's machinery. When coordination is expensive, isolation can be cheaper. A shared staging database forces developers to queue, reset data, negotiate migrations, and wonder which colleague broke the fixture. A branch lets each job proceed independently. The copyable playbook is simple: use production-shaped data, remove what is sensitive, create an environment per unit of work, measure its active life in minutes, and delete it automatically.
AI agents make that principle urgent. An agent is productive precisely because it acts without waiting for every human confirmation. That is also why production credentials in its context are absurd. Xata's newer MCP and GitHub workflows give the agent a temporary branch, let it run migrations and tests, and destroy the branch when the pull request closes. The permission is broad because the blast radius is small.
Xata began by trying to make databases less intimidating. It has arrived at a more grown-up proposition: fear is sometimes useful, but it belongs at the boundary. Inside the branch, curiosity may make a mess.