Spec takes a full copy of your company’s data out of Amazon Web Services (AWS) and keeps it on a computer you own. Then your people can search all of it there, even with the internet switched off.
It copies your PostgreSQL databases (Amazon RDS for PostgreSQL, or any Postgres) and your files in S3.
Every file gets a fingerprint as it arrives, and the whole copy gets one too, so you can check the copy at any time.
After the first copy, Spec fetches only what changed.
Search finds records and the text inside Word, Excel, PowerPoint, OpenDocument and PDF files.
Spec only reads. It asks for read-only access and never changes or deletes anything in your AWS account.
What Spec doesn’t do
It doesn’t run your app or its live database. They stay where they are, on AWS, and keep working as before. Spec only reads, and keeps its copy up to date from there.
It doesn’t delete anything in AWS. Whether to switch anything off in AWS is your decision.
It isn’t a whole plan for leaving AWS. It does the data part: a complete, checked copy you own.
A Spec computer. A computer your company owns, which holds the copy. We agree the right one with you, sized for your data.
Disk space. About the size of your data in AWS for the full copy, plus room for the search copy, plus a second disk for backups. We size it with you on a sample of your own data.
Read-only access to your AWS data. Someone who manages your AWS account sets it up in a few minutes: see step 1.
An internet line at the Spec computer to copy from AWS. Searching doesn’t need it.
Accounts for your people. Your Spec admin adds them; nobody can sign up on their own. See People and roles.
What it costs
Spec for AWS costs a fifth of what AWS charges each month to keep the same amount of data in S3 Standard, AWS’s normal storage. For 1 TB, that’s $4.71 a month with Spec, where AWS charges $23.55. For 10 TB, $47.10.
The same in every country. Spec for AWS is for companies. The free countries on our pricing page are for Spec on phones only.
Phones are priced separately: see the Spec app user guide.
AWS charges its own fee to download data out of AWS, paid to AWS. When you are leaving AWS, AWS says it waives that fee on request.
This compares prices, not bills. You also need the Spec computer, and your AWS bill only goes down if you delete the data in AWS.
Step 1: Give Spec read-only access
Spec needs to read your data, and nothing more. Your AWS admin sets this up once.
For a database
Make a login that can only read. Run this in your database as its admin. If your tables are in another schema than public, repeat the two GRANT lines with that schema’s name.
-- Run as your database's admin. Choose a long password of your own.
CREATE ROLE spec_reader LOGIN PASSWORD 'a-long-password-you-choose';
GRANT USAGE ON SCHEMA public TO spec_reader;
GRANT SELECT ON ALL TABLES IN SCHEMA public TO spec_reader;
ALTER ROLE spec_reader SET default_transaction_read_only = on;
On Amazon RDS you can use an AWS login (IAM database authentication) instead of a password. We set that up with you.
For files in S3
Give Spec an AWS login with this policy. Replace your-bucket with your bucket’s name. It lets Spec list the files and read them, nothing else.
Open Data. Your database is listed under Configured sources. (Sources are added on the Spec computer; during early access, we add them with you.)
Tap Review migration, then Run preflight.
Wait for Preflight passed. It shows the number of tables, an estimate of the size, the working space and the free disk.
The check looks at access to the database, the tables and their keys, the column types, the search model and the free disk. If it fails, it says why: see If something goes wrong.
Step 3: Copy your data
After Preflight passed, tap Start migration. Spec checks again, then starts copying.
Open Activity to follow each stage. The copy runs on the Spec computer and carries on if you close the page. The page refreshes every five seconds.
When every check has passed, the copy says Ready for review. Open it and tap Review publication, then confirm.
Publishing switches your search to the new copy. Until then, your people keep searching the previous one, and the previous one is kept so it can be switched back.
Cancel migration stops a copy at its next safe point. Retry migration starts a fresh attempt after a failure.
The first copy takes as long as your internet line needs to move the data. For scale: at 10 Mbit/s, about 4.5 GB an hour.
Files in S3: during early access, we run S3 copies with you on the Spec computer. They become searchable in the same way.
Step 4: Check your copy
Open Archive. Every copy keeps an archive of the tables it read, with their rows, files and size, and a manifest that lists the fingerprint of every file.
Button
What it does
Check integrity
Checks every file of the archive against its fingerprint.
Test restore
Loads every table into a separate test database, compares it with the archive row for row, recreates the keys, then throws the test away.
Prepare download
Packs the archive into one file. Then Download archive, and compare the file’s SHA-256 with the one shown.
Remove archive
Deletes that archive from the Spec computer. It can’t be undone: download it first if you need it.
Operators and admins start these. Members can download a prepared archive and read the results.
A passed restore test shows the rows restore exactly. It doesn’t bring back your database’s users, permissions, functions or indexes: those stay in AWS or in your own records.
Step 5: Keep the copy up to date
After the first copy, Spec fetches only what changed since the last one. During early access, we set how often with you.
Admins control copies in Admin → Internet and copies:
Pause copies now stops copies from AWS at once, for example on a backup line. Search and sign-in keep working. Resume copies carries on.
Speed limits for working hours and for nights. Leave a box empty for no limit.
Which internet line the Spec computer uses. With Starlink as a backup, copies wait longer through a drop, then carry on where they stopped.
Type what you’re looking for: a customer’s name, an invoice number, a topic.
Tap Search. Spec lists the closest matching records.
Each result shows where it came from: a row in a database table, or a file.
The similarity score shows how close a match is, not how sure an answer is.
Written answers aren’t switched on yet. Search shows the matching records.
On the Spec computer, search works with the internet switched off.
Searchable: database rows, and the text inside Word, Excel, PowerPoint, OpenDocument, PDF and plain-text files. Your people can also search from their phones: see the Spec app user guide. For Supabase data, see Specbase. More on searching your documents privately.
People and roles
Role
Can
Member
Search and read.
Operator
Also run copies from AWS and look after the archives.
Admin
Also add and remove people, and change the internet and copy settings.
Add a person
Open Admin. Under Add a person, enter their email, a name and a role.
Tap Add and show a password. The temporary password is shown only once.
Give it to them in person or by phone, not by email.
They sign in with it, add Face ID or a fingerprint, and choose their own password in Settings.
Look after people
New password gives someone a new temporary password.
Sign out everywhere signs them out on every device.
Lost device removes all their passkeys and signs them out everywhere. They can still sign in with their password.
Remove takes them out of Spec. Your data is not touched.
What admins changed lists every change admins made.
What is copied, and what isn’t yet
Databases
Copied: every selected table, exactly as it is, in one consistent snapshot.
Searchable column types: numbers, text, dates and times, true/false, JSON, UUIDs, IP addresses, binary data, enums, domains, and lists of these.
Not yet: range, geometric, money, bit-string, text-search (tsvector) and PostGIS columns. A table with them can’t be copied from the app yet.
For copies started in the app, every table needs a one-column primary key, and foreign keys must point to tables that are copied too.
Files in S3
Copied: every file, byte for byte, with its fingerprint.
Only the current version of each file, not older versions.
Files in Glacier or Deep Archive are listed as skipped, with the reason. They are never left out silently.
Files encrypted with keys you supply to each request (SSE-C) can’t be read.
Not searchable yet, but kept in the copy: old .doc, .xls and .ppt files, Apple Pages, Numbers and Keynote files, scanned PDFs without text, and files with more than 20 MB of text.
Your data if you stop
If your licence runs out, you keep your data. Reading and exporting keep working.
The copy is in open formats you can read without Spec: database tables in PostgreSQL’s own COPY format with a manifest, and files exactly as they were in S3.
Spec never deletes anything in AWS.
If something goes wrong
The app says what went wrong. The usual reasons, and what to do:
Spec can’t connect to the database: check its address, the network route to it and the login.
The login can’t read every table: give it read access, as in step 1.
A table is missing, or isn’t a plain table: check the list of tables to copy.