Self-hosted & Teams

Your datacenter. Your cloud. Your country.

Static Rust binaries on any KVM-capable Linux host. No Postgres, no Redis, no Kubernetes around them.

click to copy
$ boxd --config /etc/boxd/boxd.toml --init
✓ boxd running. SSH in.
 
$ ssh boxd.your-host.sh new --name=demo
✓ demo.boxd.your-host.sh ready in 50ms

On-prem

One binary, your hardware, no outbound dependencies at runtime.

Sovereign cloud

Deploy into your own AWS, GCP, Azure, OVH, Hetzner, or bare-metal account.

Air-gapped

Nothing phones home. boxd ships as one binary that runs offline.

0
external services
KVM
isolation per VM
EU
by default

What you get

Single-binary install

Drop the Rust binary on a KVM host. Embedded SQLite and Raft do the rest.

Hardware isolation

Every VM gets its own kernel via KVM. Multi-tenant by design.

SSO and audit logs

SAML and OIDC, role-based access, auditable control-plane writes.

EU-native by default

Our production runs on OVH in France. Bring your own region if you prefer.

Self-host without operating a stack underneath it.

boxdCoderDaytona
External servicesNonePostgreSQLDocker daemon (DinD)
Host requirementAny KVM Linux hostLinux + Docker (or K8s)Linux + Docker
IsolationKVM (own kernel)Container by defaultPrivileged container
Audit logsBuilt into the Raft logPremium-only featureCloud product only

Who this is for

Regulated industries

Finance, healthcare, defense. Code that cannot leave your network.

EU sovereignty buyers

Teams under DORA, NIS2, or DSGVO who need data residency by default.

Teams who already build on Firecracker

Stop maintaining the orchestrator. Run boxd on the hosts you already operate.

Book a meeting.

You'll hear back from Hidde or Lore, not a sales funnel. Bring the infra questions.