Security & architecture

Sovereignty isn’t a feature. It’s the foundation.

Astoris is built so your data never has to leave the server. From the network to the model, you’re in control at every layer.

End-to-end encryption

The Vault encrypts messages and files with AES-256-GCM before they leave your server. The key stays with you.

Self-hosted

Astoris runs entirely on your own hardware. Your data, documents and conversations live on your server — nowhere else.

Tailscale login

Sign in by password or over your Tailscale mesh. No open port to the internet — only your devices get in.

HTTPS everywhere

Every connection is HTTPS-encrypted. Storage is encrypted, and it all runs behind your own network.

Architecture

Layer by layer, under your control.

How Astoris fits together — from your private network to the choice of which model answers.

Network Your Tailscale mesh Only your devices
Access HTTPS · Login (password / Tailscale) Encrypted connection
Workspace Astoris — nine apps On your hardware
Storage Encrypted storage + Vault (AES-256-GCM) Key stays with you
Model Local (vLLM / Ollama) · or cloud (Anthropic / OpenAI) You decide per task

Local, in the cloud or on your own GPU — you choose. An example from the high end: the model qwen3.5-35b delivers around 54 tokens per second on an NVIDIA DGX Spark (GB10). That hardware is optional — a cloud free tier or Ollama on a Mac is plenty for fluid streaming.

Your AI. Your hardware. Your rules.

Open-Core and auditable. Build an engine room you can trust.

Security questions? info@astoris.org