Vulos OS

The operating system you own.

Vulos OS is a web-native desktop that boots on your own hardware and streams to any browser — windows, dock, files, terminal, and every app in the suite. It’s the sovereign foundation everything else runs on, and it manages itself: accounts, device enrollment, routing and admin all live in the box, not in a separate control plane.

Open your OS Read the source ↗
MIT-licensedBoots on bare metalSelf-manages · no control-plane productYour data, your bucket
on device
Vulos OS — a web-native desktop with a briefing, an assistant composer, a live agenda and pending invites
The desktop

A coherent OS, not a bag of tabs.

Four things make Vulos an operating system rather than a web app: a real shell, a verifiable boot chain, a unified store, and a private-AI seam — all on hardware you control.

A real desktop, in the browser.

Windows, a dock, a file manager, a terminal — a coherent web-native shell, not a launcher of tabs. Everything the suite runs in is here, and it renders on any device with a browser.

Boots on your own hardware.

Vulos ships as a signed squashfs image with an Ed25519 trust key baked in. Boot from USB or over netboot; the loader verifies the image before the kernel runs. No mutable rootfs, no post-install drift.

Files live inside the OS.

A unified per-account store — folders, versions, sharing — that lives on your box, not in a vendor bucket. Bring your own S3-compatible storage; egress is free, so leaving costs nothing.

Your own private AI.

llmux runs on your box against a model you choose, with a sovereignty gate that blocks remote egress unless you opt in — explicitly and logged. We never sit in the loop and never meter your inference.

Management, built in

Your box manages itself.

There is no separate control-plane product any more — the management plane folds into the OS. Accounts, device enrollment, routing, settings and the admin console ship inside the open-source platform, for one box or a whole fleet. Billing and bucket provisioning are optional cloud seams; the OS never depends on them.

Accounts & identity

Sign-up, sign-in, passkeys, 2FA, linked Google/Microsoft identities, sessions and org roles — the anchor that proves who you are and routes you to your box.

Device enrollment

Boxes self-enroll with a client-generated ID and per-device certs. Bind a device to an account, name it, group it, decommission it — no truck rolls.

OS routing

One entry, many boxes: your session resolves to the best box in your cluster — home-region aware, health-gated, direct when it can be.

Settings & admin console

An instrument-panel console over the whole box or fleet — health, rollouts, quotas, exportable audit logs. Every action is auditable, and it ships in the open-source build.

Fleet self-management

Run one box or manage many centrally — policy, RBAC, audit logs, SSO — while your data stays in your own buckets. The management plane lives with the OS, not in a separate product.

Recovery & updates

Signed over-the-air updates with atomic rollback, and an opt-in encrypted recovery channel that restores a locked-out box without a factory reset. Off by default, per device.

Sovereign by exit

Run it yourself. Owe us nothing.

The OS and its management plane are open source and free to run. The access-cloud is a convenience — login and bucket provisioning — never a lock. Self-host the whole thing the day we stop being worth it.

  • MIT-licensed, open source. Read every line, fork it, ship a build that disagrees with ours. The OS repo is the spec.
  • The management plane is in the box. Accounts, routing and the admin console are part of the open-source platform — there is no separate control-plane product to buy.
  • Bring your own storage. Files default to your own S3-compatible bucket. Your data never lands in someone else’s store just to use the OS.
  • Your cluster, your regions. Point your boxes at your own infrastructure. The cloud is an optional convenience for reachability and provisioning — never a requirement.
  • Sovereign by exit. Export your Ed25519 identity and your bytes any time. Zero egress on the way out — convenience, never lock-in.

Boot it on your own hardware.

Flash the signed image, enroll your box, and open it from any browser. Self-host for $0, or lean on the optional cloud for zero-config reachability and backups.

First-boot guide Explore the suite