Fully-Integrated Open Source Productivity Stack

All-in-One Files, Conferencing, & Mail Server

Sovereign replacement for Google Workspace, Zoom, & Office 365

A complete suite that replaces the functionality of the Google and Microsoft ecosystems with open source alternatives that meet the strictest data protection requirements.

Defguard Vaultwarden Enterprise VPN, SSO, & Vault

Defguard protects the appliance’s network perimeter and applications by issuing WireGuard VPN profiles and OIDC authentication tokens – based on a single source of truth for user identity.

The Defguard core and backend Postgres DB remain isolated from the public Internet, while the gateway & the proxy containers provide the WireGuard endpoint and enrollment URL.

All applications in the appliance use Defguard for Single Sign-On. We chose Defguard because it’s the only solution of its kind that integrates biometric-gated WireGuard access with hardware key (FIDO2/Webauthn) and TOTP 2FA for application authentication.

Single-Pane User Lifecycle: Onboard or offboard a team member once to instantly provision or revoke access across your VPN perimeter, cloud storage, and team chat.

Vaultwarden provides a zero-knowledge enclave for artifacts such as Matrix recovery keys, identity and credit cards, SSH keys, as well as time-based (TOTP 2FA) authenticator tokens.

Element X Matrix Server with WebRTC Infrastructure

Tuwunel is a Matrix homeserver implemented in Rust, listed by the Matrix.org Foundation. Its development was primarily supported by the Swiss Post, which runs Tuwunel underneath its ePost deployment – providing secure messaging for Swiss residents.

Our appliance includes a ready-to-use private Tuwunel server for your team, isolated by default from other Matrix servers for zero leakage of your user directory, presence status, & room metadata. We also built in a self-hosted Ntfy server, eliminating dependency on Google Play Services for push notifications and call ringing.

It is pre-integrated with LiveKit and Coturn, supporting E2EE voice and video calls with metadata remaining strictly within your own infrastructure – using the Element (web and desktop) and Element X (mobile) clients. The LiveKit JWT sidecar container automatically facilitates secure authentication to Element calls using short-lived access tokens.

Matrix & WebRTC calls provide face-to-face equivalent privacy for your most sensitive business conversations, supporting the use of secure endpoints such as Linux desktops and GrapheneOS phones, for resistance against Chat Control and global “Online Safety” acts.

Office Private File Sync & Share + Office

Nextcloud is the world’s most deployed self-hosted cloud storage server. We pre-configured the Files High-Performance Backend so all users’ sync clients establish a long-lived WebSocket connection, reducing battery drain and server load from polling.

The latest sync clients now support Virtual Files, allowing users to browse their share on the desktop without using local disk space. Zero-knowledge encryption with file-level granularity can be achieved with the use of the companion application, Cryptomator.

Integrated with OnlyOffice or Euro-Office for collaborative editing of office file formats (.docx, .xlsx, .pptx, .pdf) in high fidelity, ensuring that sensitive documents are never processed by Google Docs, Microsoft 365, or Adobe Document Cloud. Euro-Office is a fork of OnlyOffice supported by a consortium of companies including IONOS, Proton, and Tuta.

The File Locks engine built into the Nextcloud core, allows both WebDAV and WOPI clients to establish an exclusive lock over an Office document, to minimize the risk of cross-user merge conflicts from simultaneous online & desktop editing. Additionally, Transactional File Locking, memory caching, and Notify Push are pre-configured with an in-memory Redis backend for instant sync and a responsive web experience.

In the appliance, the performance optimizations built into the application proxy in front of Nextcloud ensure that large files sync at near line speed with an intelligent chunking algorithm adapting to Internet connection speeds at your HQ, branch offices, and remote sites.

Stalwart Email Server with Native PGP Support

Stalwart provides a modern, secure-by-default mail server — the first self-hosted option achieving parity with ProtonMail in security and usability for E2EE email. It also supports CalDAV for calendar & meeting invitations, and CardDAV for contacts.

Standard, unencrypted messages received from external domains are automatically encrypted at rest using the user’s uploaded PGP public key. Furthermore, integration with Web Key Discovery (WKD) allows compatible clients like Thunderbird and em Client to automatically negotiate end-to-end encryption, eliminating the friction of manual key exchanges.

The body & attachments of E2E encrypted emails are protected even from the server’s storage layer itself. Compared to “click-to-view” encrypted email solutions such as Purview in Microsoft 365, there is no reliance on third-party key escrow. It also eliminates the dark anti-pattern of training employees to click links in untrusted emails.

For authentication to the Stalwart self-service & admin UIs, we integrated with Defguard IdP using a custom Traefik middleware to inject the required Base64-encoded OIDC client secret for the Single Page Application (SPA).

The available add-on mail server is written in Rust, a memory-safe language, reducing the risk of software vulnerabilities while maintaining an incredibly light memory footprint.

Ready to Secure Your Infrastructure?

View system requirements and deployment paths here.