End-to-end encryption
The Vault encrypts messages and files with AES-256-GCM before they leave your server. The key stays with you.
Astoris is built so your data never has to leave the server. From the network to the model, you’re in control at every layer.
The Vault encrypts messages and files with AES-256-GCM before they leave your server. The key stays with you.
Astoris runs entirely on your own hardware. Your data, documents and conversations live on your server — nowhere else.
Sign in by password or over your Tailscale mesh. No open port to the internet — only your devices get in.
Every connection is HTTPS-encrypted. Storage is encrypted, and it all runs behind your own network.
How Astoris fits together — from your private network to the choice of which model answers.
Local, in the cloud or on your own GPU — you choose. An example from the high end: the model qwen3.5-35b delivers around 54 tokens per second on an NVIDIA DGX Spark (GB10). That hardware is optional — a cloud free tier or Ollama on a Mac is plenty for fluid streaming.
Open-Core and auditable. Build an engine room you can trust.
Security questions? info@astoris.org