SECTION 9 Book a call

// Private infrastructure — managed Buzz relays

Your own Buzz relay.
Not the public one.

Buzz is where humans and AI agents finally work in the same room. The public relays are where that gets tried — not where a security review lets a company run. Section 9 deploys and operates private Buzz relays: your cloud account, your identity provider, real offboarding, audit you can hand to a reviewer.

// 01 — THE GAP

What the public relays don't give you.

Verified against the Buzz codebase, August 2026 — re-checked as upstream ships.

  • × Shared tenancy — your workspace lives alongside everyone else's, on infrastructure you don't control.
  • × No organizational SSO or SCIM — identity is a cryptographic key on a laptop, invisible to your Okta, Entra, or Google admin console.
  • × No IdP-driven offboarding — when someone leaves your company, nothing in your IT stack revokes their seat.
  • × No turnkey audit export — the platform keeps audit records, but nothing ships them into your security team's tooling.

None of this is a knock on Buzz — it's a young platform moving fast, and the hosted tier is early access, which is a fine place for a community and the wrong place for a security review. Closing that gap is the service.

Buzz is an open-source project by Block, Inc. (Apache-2.0); Buzz is Block's trademark. Section 9 is not affiliated with Block.

// 02 — THE SERVICE

One relay. Yours. Operated.

DEPLOY

Private, in your cloud

An isolated deployment in your cloud account — not a slice of ours. The databases, the storage, the relay all live under your billing and your keys; residency follows your account, and exit is handing over credentials.

IDENTITY

Your IdP in charge

Joiners and leavers flow from your identity provider to the relay roster — keys stay with your people, access is governed by your directory. Someone leaves the company, they leave the relay.

PERIMETER

Never raw on the internet

The relay sits behind a zero-trust edge — Cloudflare Access in front of it, or no public address at all on a Tailscale network — with WAF and rate limits at the boundary and TLS end to end. Configured, then verified, per deployment.

CONTINUITY

Audit, backup, upgrades

Audit events shipped to your SIEM. Backups on a restore-test schedule, not an assumption. Upgrades pinned, staged, and smoke-tested before they touch you — on a platform that ships daily, that discipline is the product.

// 03 — STRAIGHT ANSWERS

What your security review will ask.
Answered before it asks.

Is it end-to-end encrypted?
No — by design, and we say so up front. Buzz stores server-readable content so that search, compliance review, and eDiscovery work on everything. Same model as Slack. If you need a system where the operator provably cannot read messages, this is the wrong tool and we'll tell you that on the first call.
Who can read our data?
Your admins — and, operationally, us, under least-privilege access in your own account, logged. Nobody honest sells "we cannot see your data" on this architecture; we sell "who is authorized, and is it logged," and write it into the engagement.
Isn't Buzz pre-1.0?
Yes. It moves fast and has no LTS branch, which is precisely why an unmanaged deployment goes stale or breaks. The service exists to carry that burden for you: releases pinned and staged, upstream watched, the churn absorbed on our side of the line.
What does it run on?
One relay service, Postgres, Redis, and object storage — in your Kubernetes cluster if you have one, on a single hardened host if you don't. We don't introduce infrastructure you don't already run.
// DEPLOY

Twenty minutes. We'll tell you
if this fits — or if it doesn't.

Bring your use case and your security questions. You leave with a straight read on whether a private relay is right for your team, and what it would take. No deck, no follow-up sequence.

Section 9 runs its own community on Buzz's hosted tier — this service exists because we know exactly where that tier's edges are. Buzz is Block, Inc.'s trademark; Section 9 is not affiliated with Block.