Native multimodel database
One engine for SQL, JSON, vectors, search, and geo.
Relational data, native JSON, full-text, vectors, and geo share one WAL, one MVCC, and one optimizer. Install the engine and run it.
CREATE TABLE products (
id UUID PRIMARY KEY DEFAULT UUID(),
account_id UUID NOT NULL,
name STRING NOT NULL,
description TEXT,
price DECIMAL(12,2),
metadata JSON,
embedding VECTOR<F32,1536>,
location POINT,
created_at TIMESTAMPTZ DEFAULT NOW()
);
CREATE INDEX ix_category ON products (metadata.category);
CREATE FULLTEXT INDEX ix_desc ON products (description);
CREATE VECTOR INDEX ix_emb ON products (embedding) USING HNSW;
SELECT id, name, price
FROM products
WHERE metadata.category = 'headphones'
AND price <= 15000
SEARCH description FOR 'wireless noise cancelling'
NEAREST embedding TO $query
LIMIT 20;Crypto
AES-256-GCM envelope
Wire
NSQL v1 · TLS 1.3
Page
16 KiB logical
HA
Raft, 3 voters
Search
BM25 + HNSW + IVF
Platform
Built as one engine. Operated with the safety still on.
- 01
One system of record
Relational columns, JSON, vectors, full-text, and geo live in the same table and the same transaction.
- 02
Encrypted by default
Pages, WAL, UNDO, indexes, vectors, full-text trees, backups, and spills. Established AES-256-GCM only.
- 03
Keys stay off the disk
Root unlock is a --key-file you keep off the data volume. Drivers reject keys and passwords in a URL.
- 04
Durable writes
Group-commit WAL plus fsync before commit is acknowledged. Stolen files stay ciphertext.
- 05
Hybrid in one plan
Filters, BM25, and ANN share the cost model. Reciprocal rank fusion, then LIMIT. EXPLAIN shows the path.
- 06
Honest operations
Official benches keep encryption, WAL, fsync, checksums, MVCC, and auth on. Overload returns unavailable.
Multimodel
Five models. One physical plan.
That hybrid SELECT is not a federated query. Filters, BM25, and ANN participate in the same cost model. The write path is the same WAL, MVCC, and encryption as a DECIMAL update.
- RelationalClustered B+Tree, FK, RANGE/HASH/LIST
- JSONBinary NSJB, path extract, path indexes
- Full-textBM25, analyzers, prefix, fuzzy, facets
- VectorsF32/F16/I8, sparse, HNSW/IVF/IVF-PQ
- GeoWGS84 shapes + GEOMETRY / GEOGRAPHY
# same table, same transaction
SELECT id, name
FROM products
WHERE metadata.category = 'headphones'
SEARCH description FOR 'noise cancelling'
NEAREST embedding TO $query
LIMIT 20;
EXPLAIN → Candidates, Rerank bm25+vector
Threat model
Encryption protects files at rest. It does not hide plaintext from a live process.
Envelope: external root → KEK → database master → separate DEKs for pages, WAL, UNDO, backup, vector, full-text, temp, and replication. Security docs
Architecture
Catalog, HNSW, and inverted postings go through the same WAL.
- 01Native wire protocol → TLS 1.3 → authn → RBAC
- 02SQL parser → binder / catalog → planner → cost optimizer
- 03Vectorized executor: relational · JSON · vector · full-text · geo · collections
- 04MVCC + row/range locks + UNDO
- 05REDO WAL (group commit, page deltas, fsync)
- 06Buffer manager → AES-256-GCM sealed pages
Drivers
Native NSQL. No keys in the URL.
Official drivers speak NSQL v1. TLS 1.3 is required off loopback.--insecureis loopback-only.
Install
Install, init, serve.
Install the nextsql and nextsqld binaries, then initialize a data directory. Keep the root unlock key off the data volume. Loopback may run without TLS; any other bind needs --tls-cert and --tls-key.
go install github.com/bzync/nextsql/cmd/[email protected]
go install github.com/bzync/nextsql/cmd/[email protected]
printf 'secret\n' > /tmp/nextsql.pw && chmod 600 /tmp/nextsql.pw
nextsql init --data-dir /var/lib/nextsql \
--key-file /etc/nextsql/root.key \
--user app --password-file /tmp/nextsql.pw \
--database app
nextsqld --data-dir /var/lib/nextsql \
--key-file /etc/nextsql/root.key \
--listen 127.0.0.1:7210 \
--user app --password-file /tmp/nextsql.pwStatus
0.0.5 is the current release. Run it on your machine.
One encrypted ACID engine for SQL, JSON, full-text, vectors, and geo — with WAL, MVCC, hybrid plans, workflows, CDC, partitioning, backup/PITR, and Raft HA in nextsql and nextsqld. Linux packages and Docker are on Downloads. On Windows, run those Linux packages inside WSL 2. Treat the release as an engine under measurement until you have run nextsql-bench --slo on your hardware.