Deployment Options

Choose your deployment path

The Hyper-Converged Virtual Appliance supports any cloud instance, VPS, or dedicated server running a distribution of Linux with the latest stable Docker Engine.

System Requirements

Minimum: 4 vCPUs / 8 GB RAM / 160 GB SSD.

Typical: 6 (Dedicated) vCPUs / 12GB RAM / 240 GB SSD

Connectivity: 1 x public IPv4 address required

Cloud Instance / VPS


Dedicated Server

Single-tenant performance & advanced security.

Best price/performance


On-Premises VM

For existing KVM, Proxmox, VMware environments


On-Premises Bare Metal

For institutional and regulated environments

Self-Hosting Made Easy. Early Access Pricing.

Hyper-Converged Sovereign Appliance

All-in-one private cloud, E2EE messaging, & vault, protected by WireGuard

$4,950

$3,396

set up

Cloud / VPS

Essential protection for individuals and small teams, deployed on a logically isolated virtual machine.

VPN Gateway + OpenID SSO


WireGuard Biometric 2FA


Private Cloud Storage


Office Document Co-Editing


Rust-based Matrix Homeserver


Self-Hosted Push Gateway


SFU for WebRTC Conferencing


Zero-Knowledge Password Vault

$8,090

$5,560

& up

Dedicated

Runs on single-tenant bare metal for maximum protection from noisy neighbors & side-channel attacks.

Everything in Cloud plus…


VM Isolation in Own Hypervisor


Custom LVM or ZFS Partitioning


Cold Boot Protection via RAM encryption (SME/TME) *


Confidential VMs via Hardware Isolation (SEV/TDX) *


DMA Attack Protection via Hardware IOMMU *


vTPM Measurement & UKI Remote Attestation (on request) *

$3,500

$2,882

add-on

E2EE Email Server

The only self-hosted PGP mail server with automated key discovery and incoming email encryption.

End-to-end Encryption with PGP


Zero Access Storage of Mail


IMAP and JMAP Syncing


Automated SPF/DKIM/DMARC Management


Outgoing Mail with Smart Hosts


Web Key Discovery (WKD)


Interoperates with ProtonMail and any other PGP mail client

Why is a sovereign appliance this affordable?
Traditional enterprise IT vendors charge exorbitant, recurring per-user fees to fund massive sales teams and bloated support desks. We don’t do that. Because RemoteRails is built on a highly optimized, semi-automated provisioning pipeline, we have eliminated traditional deployment overhead. We pass that architectural efficiency directly to you. You pay a single, flat deployment fee for the machine—no ongoing software tax, no mandatory retainers, and no bloated corporate infrastructure.

We use TLS encryption in transit and LUKS encryption at rest to protect all tiers. Additionally, Matrix, Vault, and Mail are protected by zero-knowledge encryption.

* Requires hardware support for AMD SME, SEV/SNP and Intel TME/TDX features.