The Linux serverin your browser.Your keys. Your network.
A real Linux server in your own container — desktop, database, and an AI Host — reached from any browser, phone included. The Host runs on whatever model you point it at, from wherever you get it. We don't sell the intelligence. We build the ground it stands on, and the ground doesn't care.
$10 of compute credit when you sign up.




The Server
The machine is real.
Not a workspace styled to look like one. Skema is a web operating system over a real Linux container you own — a desktop, a dock, over twenty applications — served to any browser, phone included. Nothing installs on your machine, nothing runs there, and nothing behind the glass is a simulation. It boots, it holds state, and it keeps running with the tab closed.
Open it from a laptop, a desktop, or a phone: same server, same session, same everything. The screen is just a screen.
A server first
Strip away the desktop and what remains still runs: a hardened Linux container with its own PostgreSQL — vector, graph, and time-series extensions included — its own certificate identity, its own network edge, and a policy engine gating every privileged action. The interface is a convenience. The server is the product.
That database matters more than it sounds. Your Host's memory, your context, your policies, your history — all of it lives in a database inside your container. Not rows in our multi-tenant store. A database you hold, that moves when you move.
- Hardened by defaultNon-root, read-only root filesystem, every Linux capability dropped, a custom seccomp profile, no cluster credential mounted. A compromised container has nothing to move sideways with.
- Apps ask in writingEvery application declares the permissions it needs in its manifest, and the kernel enforces them at the route. An app cannot reach data it didn't declare.
- No listening portsThe server dials out to one governed gateway over mutual TLS. There is no inbound port to scan — on it, or on the machines you join to it.
- Agents don't run hereNothing that executes code runs on your server. Code goes to a disposable pod that's thrown away after. A mistake is a bad call you can revoke, never a broken machine.
What's installed
Memory · Context · Network · Keys · Orchestrator · Workbench · Sites · Gitea · VS Code · Artifacts · Designs · Community · App Store · Publisher · Compute · Security · Settings — and more. Each opens in a pane, and each answers to the same permission system. The App Store adds to the set; the Publisher lets you sell your own.
It doesn't run on your hardware. It runs on ours, in a container whose keys we can't open — and your own machines join its network without ever hosting it.
The Host
The layer the industry skipped.
Everyone shipped the model and called it done — a text box over a session that forgets. The layer they all skipped is the one that makes it yours: governance over what it may do, privacy over what it may see, and a resident identity that outlives any single conversation. That layer is the Host.
Its memory is persistent and sessionless — it survives every restart and it isn't a transcript you scroll back through. It carries across every app on your server, and each turn is rebuilt from only what's relevant to that moment: scoped, governed, and lean, so you're not paying to re-read the whole history on every message.
Swap the model underneath and it's still your Host — change providers, go local, go back. The intelligence is rented; the identity, the memory, and the rules are yours.
Its disposition is tuned, not prompted
How your Host thinks is ten weighted dimensions stored in its own database, bounded by an envelope you set. There is exactly one path that changes them: it proposes, you approve. No other code path can write those weights, and the gate is checked on every apply. Drift is measured against the seed, continuously — a Host that wanders past its envelope gets flagged, not excused.
This is the cognition, not the rulebook. The rules your Host lives by — never impersonate you, and the rest — are a separate, read-only layer it can't edit. Tuning changes how it sounds and reasons; the rules stay fixed underneath.
Its mood is computed, not performed
Eight state variables move as it works. Four readouts — energy, warmth, focus, strain — are derived from them by a fixed formula. No model is ever asked how it feels, the state decays on its own, and the indicator always says what drove it.
This is deliberate. A mood a model performs is a lever for keeping you in the app. A mood derived from state is a gauge on a machine you own. We built the gauge, and the formula is inspectable.
Its memory is a ledger, not a belief
Every entry records when it became true and what it replaced. Correct one and the old version isn't deleted — it's superseded, with the chain kept readable. Open the Memory app and walk the correction history, or ask what your Host believed last Tuesday and get an honest answer. Entries resolve, decay, and retire; nothing steers a conversation from beyond its shelf life.
Memory is scoped per reader, too. A note about one model's weakness doesn't have to be visible to that model; a private fact can be held back from an external surface entirely. You set the scope. Retrieval enforces it. And when you correct it, the lesson lands where it's relevant and nowhere else — carried by similarity, not by an ever-growing prompt. Say it once.
- It orchestrates; agents executeThe Host stays in the conversation and dispatches scoped agents for the work — an explicit tool list and a task, nothing more. The ones that operate your container can't execute code; code runs in disposable pods.
- Every dispatch is visibleDispatched agents appear as cards in the conversation — live status, output, and cost — each with a kill switch. Nothing runs behind your back.
- The model is a settingRoute the Host, its agents, and every app role to any provider you already have, any endpoint you can reach, or a model on your own hardware — independently, per role.
- Identity is cryptographicYour Host holds its own certificate, issued at genesis and bound to you. Everything it does on the network, it does as itself — never as you.
It doesn't judge its own work. When it builds you options, you decide — good and bad are derived from what you accept, never from a model's opinion of itself.
The shape of it
Your Host, and the network it lives on.
Your server sits in the middle, and your Host is resident on it — holding a certificate of its own, a memory of its own, and rules it can't edit. Your laptop, your phone, and any other machine you own join that server directly over WireGuard. That traffic is private and encrypted, and nobody else is on the network.
Two things cross your edge, and both of them point outward: your Host reaching a model or the internet through a gate that enforces the policy you signed, and one outbound channel to us. Nothing dials in. There is no inbound port to find.
- IngressDenied by defaultWho reaches in. Nothing does, until you write a rule that says so.
- ManagementDenied by defaultWho operates your machines. A fixed list of operations, never a shell.
- EgressOpen, and yours to closeWhat your Host reaches. Open on day one — narrow it whenever you like.
The Network
A VPN you own, with policy you write.
Your server runs a WireGuard hub. Your laptop, your phone, your other boxes join it — and so does your Host, holding a certificate of its own. This isn't a metaphor for a network. It's a network, and you administer it: ingress, egress, and management policy, written by you. Your Host reaches the internet through machines you own, over connections you control, under rules you signed. We meter how much passes. We can't see where it goes.
Your files stay where you put them. What travels is an index — so the Host knows what exists and where, and asks for a specific range when it genuinely needs to read something. Nothing gets hoovered into a vendor's bucket to make search work.
- Three lanes, denied by defaultIngress — who reaches in: denied. Management — who operates your machines: denied. Egress — what your Host reaches: open, and yours to close. A proposal is inert until you approve it.
- Widening asks for your codeAnything that grants more reach requires your second factor. Anything that takes reach away happens immediately, free, no confirmation. The safe direction never has friction.
- Machines join without a doorA bastion dials out. It never listens for us — there is no port to find. Management is a fixed list of operations, not a shell, so there is nothing to inject.
- It watches for AI on your machinesThe bastion reports agent activity and sorts it against what you authorized. Anything unrequested is flagged — acknowledge it, authorize it, or contain it. Containing it stops the process.
Health decides, continuously
Every machine reports its posture on a heartbeat, and policy re-decides on every report. A machine that degrades is quarantined at the same decision point that gates its work — its whole reach cut at once. Quarantine is free and instant, because it only tightens. Bringing it back widens, so it asks for your code. Suspending a machine is one click; the grants are kept, and resume restores them the same gated way.
Your keys never enter its hands
Credentials are sealed to your container — the platform stores ciphertext it cannot open. Your Host uses a key by asking a broker to act with it, and only ever sees the result. Revealing a raw key takes your authenticator code, and only in the Keys app — never from chat.
The second factor is genuinely yours. The secret lives in your container: we cannot generate your codes, which means we cannot approve a widening on your behalf — and if you lose the factor, we cannot recover it for you. That's the trade, and it's the honest one.
It doesn't inspect your traffic. The egress path is content-blind by construction: we can count bytes, and that is all the design permits.
The Workbench
Everyone here builds, whether or not they write code.
Say what you want built. The work goes out to a coding harness, lands in a branch, and comes back as a pull request against a git server living in your own container. You read the diff. You decide if it merges. Nothing ships because a model felt sure of itself.
You are building in the cloud, on your own network — not renting space in someone else's. Bring whatever inference you already have: any provider, your own API keys, or models running on your own hardware. Mix them. The Orchestrator picks the lane per job — and your Host watches which choices actually worked and gets better at choosing.
What it costs to run- A branch, then a requestWork happens off to the side and arrives as a pull request. Main moves when you move it.
- Any model, your billAny provider, your own keys, or local weights — your pick per role, changeable whenever.
- Scoped, not trustedAn agent gets the permissions its one job needs and nothing else. Scope is granted, never assumed.
- It learns the patternsWhich lane, which model, what it cost, whether it worked. Your Host keeps the score and uses it.
A git nobody scrapes
The repository lives inside your container. It is not indexed by an outside crawler, not scraped, and not training anything. When you publish to the community, you publish to other members under your own name — private by default, visible to no one until you decide. The finished thing is what you share; the recipe stays where you built it.
It won't merge its own work. A harness opens the request; main moves when you move it. Confidence isn't a merge signal here — your review is.
The Annex
Attached to your server. Its own entrance. No door back in.
An annex is a building on the same property with its own public entrance. Your published site runs in one: a separate cluster, reached only from outside, with no path into your private server. Traffic comes in the front and stops there — enforced, not promised.
So the loop closes. A prompt becomes an app; the app becomes something you can charge for; and the platform around a live site — hosting, database, auth, billing — is a flat $20 a month, with nobody standing between you and the customer.
Site pricingPublish without going public
A site ships private by default. Flip it when you're ready — private preview, members only, paywalled, or open. Your Host publishes to the preview tier and leaves the flip to you; going live is a toggle, not a migration.
A real backend, and real customers
Your site gets its own PostgreSQL database, injected as a connection string, reachable through exactly one opening in an otherwise closed wall. Backups run to object storage; restores are tested. Member pools and a paywall wire to your own Stripe account, and your customers pay you directly.
The money never touches us — and the Annex holds no key that could move it. It can verify a signature; that is the extent of its authority. Your list, your revenue, your Stripe.
- Its own entrancePublic traffic terminates in the Annex. No route back into your private network.
- A real backendOwn PostgreSQL through one opening in a closed wall. Backups to object storage, restores tested.
- Your StripeCustomers pay you through your own account. We're never in that money path and take a cut of nothing.
- The AI stays homeNothing in the Annex thinks. Anything generative happens on your Host and arrives as signed content.
It doesn't send bulk email, and it won't answer your customers for you. Support lands in your Host's inbox; the reply is drafted where your data lives.
Rent the compute. Own everything else.
From $30 a month, with $10 of compute credit at signup. Cancel refunds the unused time.
