proof, not logos

We're pre-launch. So here's the proof.

HostSSH hasn't shipped a public release yet, so we won't parade fake customer logos at you. We publish the scope of our recovery rehearsals and the gaps they uncover. Local data recovery is verified; complete production recovery is still being validated.

the round-trip

Verified data recovery. Clear limits.

In September 2026, a local Docker rehearsal restored two PostgreSQL databases with the same name into separate containers. Each retained its own matching data fingerprint. Separate tests verified volume hashes and rejection of corrupt archives, conflicting restores and failed health checks.

That rehearsal also exposed lost access grants. Permission preservation, complete fleet recovery and cross-node relocation remain release blockers. These are synthetic tests, not customer recovery guarantees.

2/2
test databases restored
Pass
data fingerprints
Local
isolated rehearsal
Beta
release status
historical rehearsal · fleet clone

A live data box, cloned onto a fresh server — .211 → .223

An earlier fleet rehearsal captured the machine across six layers — the control-plane brain and its APP_KEY, every application database, volumes, system config, sidecars, and a manifest — into a single encrypted restic snapshot in Cloudflare R2.

That snapshot was then restored onto a brand-new box with an IP-rewrite pass, and all 14 databases came back with matching row counts. The capture scripts remain under regression testing. Matching row counts in that earlier rehearsal does not prove current permission parity, every workload, or a complete production recovery.

  • Six layers captured into one encrypted image
  • Current consistency and permission gates remain under verification
  • IP-rewrite as a first-class, audited restore pass
  • WireGuard off by default on restore — a safety invariant
capabilities · validated

Implemented capabilities, with release gates still open

These mechanisms are implemented. Their presence does not replace workload-specific verification or establish that the complete platform is ready for general availability.

  • ed25519-signed license tokens verified offline by the agent — no phone-home to unlock day-to-day features
  • One-time, scoped transfer keys for moving a workload, instead of handing over standing credentials
  • Boot-time, forward-only schema migrations with a least-privilege migrator role and a self-explaining ownership error
  • Encrypted before it ever leaves the source host — every image is sealed at the source; the storage model is bring-your-own bucket (R2/S3/B2), so your data stays in custody you control
  • Emergency restore even on an expired license — your ability to get your data back is never revocable
why trust us

Dogfooded on a real production fleet

HostSSH is built by Sevak Girard at Girard Media. The engine began life as our own internal fleet scripts and still runs our production servers — the deploy, backup, clone and relocate paths run our real infrastructure before they run yours.

Coolify deploys your apps; HostSSH runs your server — and makes the whole thing portable, restorable, and impossible to hold hostage. We'd rather earn that reputation on verifiable engineering than borrow it from a wall of logos we haven't earned yet.

  • Built from battle-tested fleet automation, not a fresh prototype
  • Every consequential action written to an append-only audit log
  • Portable images you can restore yourself — your data, your bucket, your exit
built on proven infrastructure

Standing on technology you already trust.

HostSSH doesn't reinvent the foundations — it builds on the same battle-tested infrastructure that runs the modern web, and stays compatible with the storage you already own.

early access

See the proof become your default.

HostSSH is in private build on a real production fleet. Get on the early-access list and put your servers somewhere they can be captured, restored and relocated in one command — and never held hostage.