onboard · backup · restore · move · cloud · AI

Any hardware. Fully portable. Never held hostage.

One control plane for every machine you run — cloud VPS, bare metal, office PCs, GPU rentals. Capture the whole box into an encrypted .hsi, restore or relocate with IP rewrite, deploy apps through HostPack → Docker → Traefik, and turn capacity into a usable OpenAI-compatible API. Files, DB, Workers, Storage — and Inference on the path to fleet proof. Your data, your bucket, your exit.

$ curl -fsSL https://get.hostssh.com | sh
// any hardware · cloud · office · GPU// files · db · workers · inference · storage// encrypted .hsi · your bucket · your exit
hostssh — migrate
$ hostssh migrate prod --new-ip auto
→ capturing brain · 14 databases · volumes · config …
image sealed & encrypted → r2 · 1 snapshot
→ provisioning fresh VPS (Ubuntu 24.04 + HostSSH) …
restored · 14/14 databases · row counts match
IP rewritten 31.220.104.211 → 31.220.104.223
Traefik routes re-bound · TLS re-issued · health 200
migration complete in 4m 12s
$
two ways to use it

Managed hosting — or license the engine on hardware you already own.

Same control plane. Same agent. Same portability and AI path — whether we host the box or you bring cloud, colo, office machines, or GPU rentals.

Host-first

Managed hosting, un-trappable by design

Buy capacity from us and the whole stack is baked in: deploy, managed databases, backup, clone, one-click relocate. Portability is the product — not an upsell.

Any hardware

License it wherever you already compute

Install the agent on Hostinger, Hetzner, DigitalOcean, Vultr, AWS, bare metal, office PCs, or a rented GPU. Fleet-aware, provider-agnostic — one dashboard for every machine you refuse to lose.

the true gap

Deploy tools don't move you.
Backup tools don't run your fleet.
AI APIs don't run on your metal.

The market is sliced into panels, snapshot products, GPU marketplaces, and foundation APIs. Nobody owns the full loop: onboard any machine → protect it → move it → provision cloud when you need it → expose inference to your apps without binding to a vendor. That loop is HostSSH.

Fragmented stack (today)

  • PaaS deploys apps — then traps you at renew time
  • SQL dumps & disk snapshots — volumes or IPs break the story
  • Office GPUs and Vast boxes live outside the control plane
  • Inference apps hardcode a vendor URL you can't swap

What HostSSH unifies

  • Any hardware joins one fleet (cloud, bare metal, desk, rental)
  • Full-server .hsi — brain, DBs, volume bytes, config — restore / clone / relocate with IP rewrite
  • Files · DB · Workers · Storage day one; Inference API over your capacity
  • Apps talk to HostSSH — never to a box IP or a single GPU vendor
the deploy pipeline

Push code. We build, ship and route it.

A managed HostPack → Docker → Traefik path takes your repo to a live, TLS-terminated URL — no Nix, no Dockerfile required, no hand-wired reverse proxy.

step 01 — hostpack

Detect & build

HostPack inspects your repo, picks the runtime and produces a lean, reproducible OCI image — Node, Python, Go, Rust, static and more. No Dockerfile to maintain, no Nix to learn.

// buildpacks without the lock-in
step 02 — docker

Run & supervise

The image runs as a supervised Docker container with health checks, sealed-secret injection, resource caps, persistent volumes and health-gated deploys so a bad build never silently goes live.

// versioned, reversible deploys
step 03 — traefik

Route & secure

Traefikbinds your domain, issues and renews Let's Encrypt TLS (HTTP-01 today; DNS-01 for wildcards and pre-cutover certs as nodes upgrade), and load-balances traffic. Routes are declarative, so a relocated box re-binds automatically.

// automatic HTTPS, every service
out of the box

Files. DB. Workers. Inference. Storage.

The relocate engine is the moat — but every node also runs a full day-to-day platform. These five primitives ship with the agent; you don't bolt them on later.

Files

Any file type, in the image

Named volumes survive redeploys. The .hsi captures volume data — uploads, media, SQLite, WordPress, MinIO blobs — binary-safe, not SQL dumps only.

DB

Managed databases

One-click Postgres (pgvector), MariaDB, and Redis— generated creds, internal networking, included in full-server capture & restore.

Workers

Same pipeline, no proxy

Background workers and queue consumers deploy like web apps — --command, Slot caps, sealed secrets — without a public route. Spin on-demand workers from MCP too.

Inference early

Your capacity, one API

OpenAI-compatible gateway routes model names to CPU fleet, office GPUs, or rentals — apps never see upstream hosts. Today: Copilot + MCP. Gateway + templates in product; live fleet completion proof on the path.

Storage

Your bucket — and MinIO

BYO R2/S3/B2 for encrypted .hsi backups (zero-egress restores). Need app object storage? One-click MinIO beside your apps.

the whole platform

Every surface. Including the one in the name.

From the first deploy to a 3am disaster recovery — capture, restore, relocate, provision and prove it, all from one control plane or one Go binary.

[ deploy ]

One-click deploy pipeline

HostPack builds it, Docker runs it, Traefik routes it. Push to ship, with health checks, secrets and versioned images you can roll back to.

[ databases ]

Managed databases

Provision Postgres, MariaDB or Redis in a click — connection strings, internal networking, and inclusion in full-server capture & restore.

[ files · volumes ]

Persistent files, any type

Named volumes survive redeploys. The .hsi captures the bytes inside — uploads, media, SQLite, WordPress — not empty mount names.

[ workers ]

Background workers

Same HostPack → Docker path as web apps, with a command override and no public route — queue consumers and cron-style processes with Slot caps.

[ capture ]

Full-server capture

The whole box — platform brain & master key, every database, Docker volume data, system config & sidecars — not just a SQL dump.

[ drills ]

Restore-drills & backup health

Integrity drills verify your backup repository is readable and restorable. Full sandbox row-verify is on the roadmap — a backup you haven't tested is still a rumour.

[ relocate ]

Automatic IP-rewrite

A deterministic pass flips every public reference; internal services ride a stable WireGuard overlay — so a moved box just works.

[ provision ]

Provisioning queue

Hostinger + bring-your-own machine today; the same queue expands across Hetzner, DigitalOcean, Vultr and AWS as drivers land.

[ crypto ]

Encrypted, your bucket

Images sealed before they leave the host. R2, S3, MinIO, B2, Wasabi, SFTP or local — you own the storage, zero-egress restores.

[ license · fleet ]

License-gating & fleet awareness

ed25519 license tokens unlock features per tier; the control plane keeps every agent and server in one fleet view — even across providers.

[ cli · mcp · copilot ]

CLI, MCP & Fleet Copilot

One Go binary drives everything; MCP + Copilot let AI agents diagnose and operate the fleet through the same RBAC-gated actions you use.

[ inference ]

Inference API over your metal

Issue sealed keys, map models to fleet upstreams, and call an OpenAI-compatible base URL — swap office GPU for cloud rental without changing app code.

[ any hardware ]

Office, colo, rental, cloud

Same agent join path whether the box is a Hostinger VPS, a desk PC behind NAT, or a Vast GPU — no public IP required when you tunnel.

[ slots ]

Slots & capacity

Pack apps onto a box with hard CPU/memory/PID caps in four sizes — a real isolation unit you can meter, place, and move between machines.

[ harden ]

One-click hardening

Default-deny firewall baseline today; full Security Score, granular profiles and armed auto-revert rolling out behind the security spine.

[ monitor · alerts ]

Monitoring & delivered alerts

Auto uptime monitors on every routed domain, plus disk, backup and cert watches — that page you on Slack, PagerDuty, webhook or email, not just draw a red dot.

[ web-ssh ]

Browser root SSH

Keyless, audited root access from the browser through an mTLS relay — private beta; session recording and pentest before general availability.

// see them all on the features deep-dive →
not vaporware

Built on an engine that already does this.

A real capture → restore round-trip across a live fleet: a whole data box cloned onto a fresh server, every database verified to the row — engine proof we dogfood before we sell. Scheduled integrity drills keep the backup repo honest; full sandbox row-verify is next.

Built by Sevak Girard at Girard Media and dogfooded on our own production fleet — the deploy, backup, and relocate paths run our real servers before they run yours.

14/14
databases restored
100%
row-count match
1
command
pricing

Per fleet. Bring your own bucket.

You pay for the software; storage stays on your own R2/S3/B2. No surprise egress, no data hostage — emergency restores work even on an expired license.

Solo
$29/mo
One box — onboarded, protected, movable.
  • 1 server (any hardware)
  • Capture · restore · relocate
  • Inference gateway path
  • Restore-drills · BYO R2/S3
  • Community support
Team
$99/mo
A small mixed fleet — cloud and BYO.
  • 3 servers included
  • 5 seats
  • MCP + AI ops
  • Inference gateway path
  • Keep-all retention · Email support
Business
$349/mo
Production fleets that must not go down — or stay trapped.
  • 10 servers included
  • 10 seats
  • Priority restore · Audit + RBAC
  • Cross-provider provisioning
  • Priority support
MSP · White-label
$1,290/mo
Resell the any-hardware control plane under your brand.
  • 50 servers included
  • White-label brand + domain
  • Per-client orgs
  • Resold-VPS margin
  • Slack / PagerDuty
Enterprise
Custom
Self-hosted control plane, SSO, custom terms — still portable.
  • Unlimited servers
  • White-label + custom domains
  • Sub-accounts / org hierarchy
  • Self-hosted control plane
  • SSO / SCIM · SLA + dedicated
// overage billed per server beyond the included count · full breakdown on the pricing page →
install in one line

Load the agent on any VPS.

One command installs the agent, prompts for your license key, and unlocks Files, DB, Workers, Storage, the deploy pipeline, backup, clone, relocate & Web-SSH — on any provider.

$ curl -fsSL https://get.hostssh.com | sh
early access

Stop dreading the migration.

HostSSH is in private build, dogfooded on a real production fleet. Early access includes the proven relocate engine plus the day-to-day platform — Files, DB, Workers, Storage, Copilot, slots, and git-push deploys as they land.

// status: private beta · engine proven · platform in build