The operating system you own.
Vulos OS is a web-native desktop that boots on your own hardware and streams to any browser — windows, dock, files, terminal, and every app in the suite. It’s the sovereign foundation everything else runs on, and it manages itself: accounts, device enrollment, routing and admin all live in the box, not in a separate control plane.

A coherent OS, not a bag of tabs.
Four things make Vulos an operating system rather than a web app: a real shell, a verifiable boot chain, a unified store, and a private-AI seam — all on hardware you control.
A real desktop, in the browser.
Windows, a dock, a file manager, a terminal — a coherent web-native shell, not a launcher of tabs. Everything the suite runs in is here, and it renders on any device with a browser.
Boots on your own hardware.
Vulos ships as a signed squashfs image with an Ed25519 trust key baked in. Boot from USB or over netboot; the loader verifies the image before the kernel runs. No mutable rootfs, no post-install drift.
Files live inside the OS.
A unified per-account store — folders, versions, sharing — that lives on your box, not in a vendor bucket. Bring your own S3-compatible storage; egress is free, so leaving costs nothing.
Your own private AI.
llmux runs on your box against a model you choose, with a sovereignty gate that blocks remote egress unless you opt in — explicitly and logged. We never sit in the loop and never meter your inference.
Your box manages itself.
There is no separate control-plane product any more — the management plane folds into the OS. Accounts, device enrollment, routing, settings and the admin console ship inside the open-source platform, for one box or a whole fleet. Billing and bucket provisioning are optional cloud seams; the OS never depends on them.
Accounts & identity
Sign-up, sign-in, passkeys, 2FA, linked Google/Microsoft identities, sessions and org roles — the anchor that proves who you are and routes you to your box.
Device enrollment
Boxes self-enroll with a client-generated ID and per-device certs. Bind a device to an account, name it, group it, decommission it — no truck rolls.
OS routing
One entry, many boxes: your session resolves to the best box in your cluster — home-region aware, health-gated, direct when it can be.
Settings & admin console
An instrument-panel console over the whole box or fleet — health, rollouts, quotas, exportable audit logs. Every action is auditable, and it ships in the open-source build.
Fleet self-management
Run one box or manage many centrally — policy, RBAC, audit logs, SSO — while your data stays in your own buckets. The management plane lives with the OS, not in a separate product.
Recovery & updates
Signed over-the-air updates with atomic rollback, and an opt-in encrypted recovery channel that restores a locked-out box without a factory reset. Off by default, per device.
Run it yourself. Owe us nothing.
The OS and its management plane are open source and free to run. The access-cloud is a convenience — login and bucket provisioning — never a lock. Self-host the whole thing the day we stop being worth it.
- MIT-licensed, open source. Read every line, fork it, ship a build that disagrees with ours. The OS repo is the spec.
- The management plane is in the box. Accounts, routing and the admin console are part of the open-source platform — there is no separate control-plane product to buy.
- Bring your own storage. Files default to your own S3-compatible bucket. Your data never lands in someone else’s store just to use the OS.
- Your cluster, your regions. Point your boxes at your own infrastructure. The cloud is an optional convenience for reachability and provisioning — never a requirement.
- Sovereign by exit. Export your Ed25519 identity and your bytes any time. Zero egress on the way out — convenience, never lock-in.
Boot it on your own hardware.
Flash the signed image, enroll your box, and open it from any browser. Self-host for $0, or lean on the optional cloud for zero-config reachability and backups.