Hosting Options

The RemoteRails Appliance, providing a complete digital office-in-a-box, can be hosted on any modern VPS, cloud instance, dedicated server, or on-premises / co-located hardware. This provides maximum flexibility for individuals & small teams to entire organizations. Each hosting option has different capacity, cost, and security trade-offs.

The options are listed in order of ascending sophistication, in terms of ease of deployment versus hardware isolation, performance, and security requirements.

For deploying RemoteRails on any of the hosting options discussed below, get in touch with Sales Engineering who would be pleased to provide an unbiased recommendation based on your capacity (number of users + volume of data), monthly budget, and data residency needs.

RemoteRails Hosting Tiers: Security Feature Matrix

Security FeatureCloud / VPS TierDedicated Bare MetalDedicated Hypervisor (Tier 1)Dedicated Hypervisor (Tier 2 Enclaves)
Workload SegmentationDocker ContainersDocker ContainersHypervisor-Fenced VMsHardware-Fenced VMs
Physical Single Tenancy
At-Rest Storage Encryption (LUKS)✅ (Unified Drive)✅ (Host-Level RAID)✅ (Host-Level RAID)✅ (Guest-Level Isolated)
Automated Crypto-Shredding
Direct Memory Access (DMA) Protection✅ (IOMMU)✅ (IOMMU)✅ (IOMMU)
Unified Kernel Image (UKI) Boot
Hardware Memory Encryption✅ (AMD SME / Intel TME)✅ (AMD SME / Intel TME)✅ (AMD SME / Intel TME)
Cryptographic VM Enclaves✅ (AMD SEV-SNP / Intel TDX)
Cryptographic Attestation✅ (Hardware-Backed)
Primary Threat Model AddressedSoftware vulnerabilities & basic data scrapingPhysical drive theft & hardware tamperingContainer escape & cross-workload interferenceHypervisor compromise & untrusted datacenters

VPS & Cloud

VPS & cloud instances are discussed in the same section, as they both represent a virtual machine primitive – simply provided under a different delivery model.

Classic virtual private servers (VPS) are virtually isolated slices of physical servers rented to multiple tenants for a monthly or lengthier subscription period. Cloud instances are on-demand VMs, which can be provisioned and terminated by the customer, through a self-service control panel – billed hourly or on an even shorter period of granularity.

Compute instances at hyperscale cloud providers, such as AWS, Azure, or Google Cloud, are typically positioned at much higher monthly costs and with variable bandwidth costs 20-100x higher than an equivalent VPS, due to their highly flexible utility-style billing model, and premium privately-owned fiber-optic backbones.

But cloud instances at competitive clouds such as Akamai, Hetzner, or Vultr have in many cases reached price parity with generous pools of included, high-quality bandwidth, making them a highly attractive alternative to a traditional VPS.

The RemoteRails Appliance can be deployed with any of the hyperscalers, but many of our customers consider & choose independent alternatives for data residency, governance, and cost reasons.

For example, cloud providers, such as Infomaniak Public Cloud (Switzerland), OVHcloud (France), UpCloud (Finland), legally headquartered outside the US sidestep the jurisdiction of the U.S. CLOUD Act for their non-US datacenter locations. This might, for example, be desirable if one is storing or processing the data of European data subjects covered under the EU GDPR. By shielding the exposure of PII from US extraterritoriality, it eliminates the need to rely on the tenuous EU-U.S. Data Privacy Framework, or incorporate complex Standard Contractual Clauses (SCCs) into a service’s terms & conditions.

A VPS or cloud instance is the quickest way to launch your RemoteRails Appliance with the shortest set-up turnaround time. A zero-trust network access (ZTNA) security model through WireGuard VPN + SSO (Defguard), and LUKS encryption at-rest of your Chat (Matrix), Drive (Nextcloud), E-Mail (Stalwart), & Vault (Vaultwarden) data is fully supported.

Although the kernel-based isolation between VMs on a multi-tenant physical host in a public cloud is “fit for purpose” for most business applications, the Dedicated or On-Premises deployment options for the RemoteRails Appliance provide additional guarantees, including against:

  • Performance degradation from CPU or I/O steal of “noisy neighbors”
  • Hypervisor compromise, such as RAM dumping, at the cloud provider level
  • “Side channel” attacks from vulnerable CPU microcode – similar to Spectre or Meltdown

Dedicated Server

server room aisle with metal equipment racks

Hosting the RemoteRails Appliance on a dedicated server is what we recommend for most use cases beyond individuals & small teams. In addition to the peace of mind that your server is exclusively executing the code for your Appliance’s workloads, dedicated servers provide more performant and voluminous directly-attached storage options than cloud provider network-based block storage.

The price/performance ratio of dedicated servers, both in terms of compute & storage, quickly surpasses that of cloud instances, beyond that of the smallest use cases. We recommend AMD Ryzen PRO or AMD EPYC platforms if you require AMD SME/TSME (Ryzen PRO) or AMD SEV-SNP (EPYC Zen 3 and newer) support. While Intel Xeon E-series (Raptor Lake-E and newer) processors support basic Intel TME, advanced confidential computing capabilities like Intel TDX are tiered strictly to higher-end enterprise server processors (such as Xeon Scalable and Xeon 6 families) – unlike AMD, where these features come more uniformly standard across their entire business and data center portfolios.

For a single-tenant deployment of the RemoteRails Appliance with the Docker option, the memory encryption provided by AMD SME/TSME or Intel TME, configured in conjunction with AMD-Vi or Intel VT-d, defends effectively against Direct Memory Access (DMA) and cold boot attacks. This thwarts attempts to extract sensitive information, such as LUKS encryption keys, whether using a forensic device or by physically removing the server’s memory modules.

For more complex RemoteRails deployments with a dedicated Proxmox hypervisor, stepping up to hardware with AMD SEV-SNP or Intel TDX cryptographically isolates each virtual machine from the hypervisor itself, anchoring VM trust directly in the processor.

You also have the flexibility of formatting your NVMe or SATA SSDs and SATA or SAS HDDs in any software RAID configuration that you wish. In most cases, for two-drive pairs we recommend RAID 1 (mirroring) and four-drive arrays RAID 10 (mirroring + striping) or RAID 6 (double parity), depending on the performance and redundancy required.

For the RemoteRails Appliance, we recommend at least 2 x 480 GB SSDs formatted in RAID 1 for the operating system, application containers, PostgreSQL and RocksDB databases. Additionally, it’s recommended to have 2 – 4 datacenter HDDs of at least 2 TB each for Nextcloud data and Stalwart Mail attachment storage.

The network uplink of the dedicated server should be a minimum of 250 Mbps guaranteed, with 1 Gbps preferable for a large number of concurrent Element calls through LiveKit and Matrix.

Because of the RemoteRails Appliance’s focus on data storage & archival across its collaboration and communication applications, we recommend looking at storage-tier servers at dedicated providers such as OVHcloud and Hetzner, or customizing your own server with additional storage. The -STOR servers in OVH’s SYS, RISE, and ADVANCE lineups are popular options, as well as the AX- series at Hetzner.

On-Premises / Co-Located Hardware

Building on the advantages of hosting the RemoteRails Appliance on a rented dedicated server, hosting on on-premises or co-located hardware provides even greater control over your Appliance. This deployment model is ideal for organizations bound by strict regulatory mandates, internal data governance policies requiring physical custody of hardware, or high-throughput local network environments.

When deploying to your own hardware, you maintain absolute control over the physical supply chain and components. This eliminates third-party datacenter vendor access to host machines, mitigates risks associated with managed remote hands, and lets you implement physical tamper-evident measures. Organizations can specify exact enterprise components, including Hardware Security Modules (HSMs) or FIPS 140-3 validated Self-Encrypting Drives (SEDs), to meet specialized compliance frameworks.

For organizations with heavily centralized physical offices, an on-premises RemoteRails Appliance keeps high-volume file synchronization (Nextcloud) and intra-office communication on local gigabit or 10-gigabit LANs. This delivers maximum throughput with near-zero latency while substantially reducing outbound internet bandwidth consumption. Remote team members can continue to access all services securely through the integrated WireGuard ZTNA gateway.

Depending on your office infrastructure and rack footprint, we recommend:

  • 1U/2U Rackmount Servers: Enterprise platforms such as Dell PowerEdge (R360/R660/R760), Supermicro, or HPE ProLiant servers equipped with dual redundant power supplies, hot-swappable drive bays, and ECC memory.
  • Compact / Microservers: For branch offices or quiet environments without dedicated server rooms, compact enterprise workstations or purpose-built microservers (such as Minisforum or Supermicro embedded systems) offer lower power draw and near-silent operation.
  • Out-of-Band Management: Ensure hardware includes dedicated remote management interfaces (such as Dell iDRAC, HPE iLO, or IPMI) connected to a restricted management VLAN, isolated from general office traffic.

While self-hosting offers maximum sovereignty, it shifts the responsibility of physical infrastructure maintenance to your internal team:

  • Power Redundancy: Deploy an Uninterruptible Power Supply (UPS) with automated safe-shutdown signaling to prevent filesystem corruption during power loss.
  • Network & Static IP: Ensure your uplink includes a dedicated static IPv4 address and proper DNS routing, along with adequate symmetrical upload bandwidth for remote users accessing LiveKit video conferencing or large files.
  • Off-Site Backups: To maintain resilience against site-level disasters, combine local snapshotting with automated, client-side encrypted off-site replication to an S3-compatible cold storage provider or secondary RemoteRails instance.