Skema Host — WebOS for Your Private Network

The Linux serverin your browser.Your keys. Your network.

A real Linux server in your own container — desktop, database, and an AI Host — reached from any browser, phone included. The Host runs on whatever model you point it at, from wherever you get it. We don't sell the intelligence. We build the ground it stands on, and the ground doesn't care.

$10 of compute credit when you sign up.

The Skema desktop — the app grid, the dock, and the Host's live status bar with its compute meter
The same Skema desktop on a phone
YOUR APPSYOUR HOSTYOUR PLATFORM
Always onAlways yoursAny model, any sourceBilled for compute — never tokens

The Server

The machine is real.

Not a workspace styled to look like one. Skema is a web operating system over a real Linux container you own — a desktop, a dock, over twenty applications — served to any browser, phone included. Nothing installs on your machine, nothing runs there, and nothing behind the glass is a simulation. It boots, it holds state, and it keeps running with the tab closed.

Open it from a laptop, a desktop, or a phone: same server, same session, same everything. The screen is just a screen.

A server first

Strip away the desktop and what remains still runs: a hardened Linux container with its own PostgreSQL — vector, graph, and time-series extensions included — its own certificate identity, its own network edge, and a policy engine gating every privileged action. The interface is a convenience. The server is the product.

That database matters more than it sounds. Your Host's memory, your context, your policies, your history — all of it lives in a database inside your container. Not rows in our multi-tenant store. A database you hold, that moves when you move.

  • Hardened by default
    Non-root, read-only root filesystem, every Linux capability dropped, a custom seccomp profile, no cluster credential mounted. A compromised container has nothing to move sideways with.
  • Apps ask in writing
    Every application declares the permissions it needs in its manifest, and the kernel enforces them at the route. An app cannot reach data it didn't declare.
  • No listening ports
    The server dials out to one governed gateway over mutual TLS. There is no inbound port to scan — on it, or on the machines you join to it.
  • Agents don't run here
    Nothing that executes code runs on your server. Code goes to a disposable pod that's thrown away after. A mistake is a bad call you can revoke, never a broken machine.

What's installed

Memory · Context · Network · Keys · Orchestrator · Workbench · Sites · Gitea · VS Code · Artifacts · Designs · Community · App Store · Publisher · Compute · Security · Settings — and more. Each opens in a pane, and each answers to the same permission system. The App Store adds to the set; the Publisher lets you sell your own.

What it won't do

It doesn't run on your hardware. It runs on ours, in a container whose keys we can't open — and your own machines join its network without ever hosting it.

The Host

The layer the industry skipped.

Everyone shipped the model and called it done — a text box over a session that forgets. The layer they all skipped is the one that makes it yours: governance over what it may do, privacy over what it may see, and a resident identity that outlives any single conversation. That layer is the Host.

Its memory is persistent and sessionless — it survives every restart and it isn't a transcript you scroll back through. It carries across every app on your server, and each turn is rebuilt from only what's relevant to that moment: scoped, governed, and lean, so you're not paying to re-read the whole history on every message.

Swap the model underneath and it's still your Host — change providers, go local, go back. The intelligence is rented; the identity, the memory, and the rules are yours.

Its disposition is tuned, not prompted

How your Host thinks is ten weighted dimensions stored in its own database, bounded by an envelope you set. There is exactly one path that changes them: it proposes, you approve. No other code path can write those weights, and the gate is checked on every apply. Drift is measured against the seed, continuously — a Host that wanders past its envelope gets flagged, not excused.

This is the cognition, not the rulebook. The rules your Host lives by — never impersonate you, and the rest — are a separate, read-only layer it can't edit. Tuning changes how it sounds and reasons; the rules stay fixed underneath.

Its mood is computed, not performed

Eight state variables move as it works. Four readouts — energy, warmth, focus, strain — are derived from them by a fixed formula. No model is ever asked how it feels, the state decays on its own, and the indicator always says what drove it.

This is deliberate. A mood a model performs is a lever for keeping you in the app. A mood derived from state is a gauge on a machine you own. We built the gauge, and the formula is inspectable.

Its memory is a ledger, not a belief

Every entry records when it became true and what it replaced. Correct one and the old version isn't deleted — it's superseded, with the chain kept readable. Open the Memory app and walk the correction history, or ask what your Host believed last Tuesday and get an honest answer. Entries resolve, decay, and retire; nothing steers a conversation from beyond its shelf life.

Memory is scoped per reader, too. A note about one model's weakness doesn't have to be visible to that model; a private fact can be held back from an external surface entirely. You set the scope. Retrieval enforces it. And when you correct it, the lesson lands where it's relevant and nowhere else — carried by similarity, not by an ever-growing prompt. Say it once.

  • It orchestrates; agents execute
    The Host stays in the conversation and dispatches scoped agents for the work — an explicit tool list and a task, nothing more. The ones that operate your container can't execute code; code runs in disposable pods.
  • Every dispatch is visible
    Dispatched agents appear as cards in the conversation — live status, output, and cost — each with a kill switch. Nothing runs behind your back.
  • The model is a setting
    Route the Host, its agents, and every app role to any provider you already have, any endpoint you can reach, or a model on your own hardware — independently, per role.
  • Identity is cryptographic
    Your Host holds its own certificate, issued at genesis and bound to you. Everything it does on the network, it does as itself — never as you.
What it won't do

It doesn't judge its own work. When it builds you options, you decide — good and bad are derived from what you accept, never from a model's opinion of itself.

The shape of it

Your Host, and the network it lives on.

Your server sits in the middle, and your Host is resident on it — holding a certificate of its own, a memory of its own, and rules it can't edit. Your laptop, your phone, and any other machine you own join that server directly over WireGuard. That traffic is private and encrypted, and nobody else is on the network.

Two things cross your edge, and both of them point outward: your Host reaching a model or the internet through a gate that enforces the policy you signed, and one outbound channel to us. Nothing dials in. There is no inbound port to find.

Your Host on your private networkYour server sits at the centre of a private WireGuard network. Your laptop, your phone, your other machines and any bastion you stand up join it directly, and traffic between them is encrypted. Your Host lives on that server, holding its own certificate, its own memory, and rules it cannot edit. Two channels cross the edge outward and none come back in: your Host reaches models and the internet through an egress gate that enforces the policy you signed, and the server holds one outbound mutual-TLS channel to the platform. There is no inbound port on any of it.YOUR PRIVATE NETWORKLAPTOPany browserPHONEsame serverMACHINESjoinedYOUR SERVERLinux container · your database · your keysYOUR HOSTits own certificate · its own memoryrules it can't editany model you point it atBASTIONa machine you own — an optional way outYOUR EDGEEGRESS GATEyour signed policyMODELS & THE INTERNETany provider, your own keys,or a model on your own hardwarewe count the bytes. we never see the destination.THE PLATFORM — THAT'S USone outbound channel, mTLS —no inbound port to scan
  • Ingress
    Denied by default
    Who reaches in. Nothing does, until you write a rule that says so.
  • Management
    Denied by default
    Who operates your machines. A fixed list of operations, never a shell.
  • Egress
    Open, and yours to close
    What your Host reaches. Open on day one — narrow it whenever you like.

The Network

A VPN you own, with policy you write.

Your server runs a WireGuard hub. Your laptop, your phone, your other boxes join it — and so does your Host, holding a certificate of its own. This isn't a metaphor for a network. It's a network, and you administer it: ingress, egress, and management policy, written by you. Your Host reaches the internet through machines you own, over connections you control, under rules you signed. We meter how much passes. We can't see where it goes.

Your files stay where you put them. What travels is an index — so the Host knows what exists and where, and asks for a specific range when it genuinely needs to read something. Nothing gets hoovered into a vendor's bucket to make search work.

  • Three lanes, denied by default
    Ingress — who reaches in: denied. Management — who operates your machines: denied. Egress — what your Host reaches: open, and yours to close. A proposal is inert until you approve it.
  • Widening asks for your code
    Anything that grants more reach requires your second factor. Anything that takes reach away happens immediately, free, no confirmation. The safe direction never has friction.
  • Machines join without a door
    A bastion dials out. It never listens for us — there is no port to find. Management is a fixed list of operations, not a shell, so there is nothing to inject.
  • It watches for AI on your machines
    The bastion reports agent activity and sorts it against what you authorized. Anything unrequested is flagged — acknowledge it, authorize it, or contain it. Containing it stops the process.

Health decides, continuously

Every machine reports its posture on a heartbeat, and policy re-decides on every report. A machine that degrades is quarantined at the same decision point that gates its work — its whole reach cut at once. Quarantine is free and instant, because it only tightens. Bringing it back widens, so it asks for your code. Suspending a machine is one click; the grants are kept, and resume restores them the same gated way.

Your keys never enter its hands

Credentials are sealed to your container — the platform stores ciphertext it cannot open. Your Host uses a key by asking a broker to act with it, and only ever sees the result. Revealing a raw key takes your authenticator code, and only in the Keys app — never from chat.

The second factor is genuinely yours. The secret lives in your container: we cannot generate your codes, which means we cannot approve a widening on your behalf — and if you lose the factor, we cannot recover it for you. That's the trade, and it's the honest one.

What it won't do

It doesn't inspect your traffic. The egress path is content-blind by construction: we can count bytes, and that is all the design permits.

The Workbench

Everyone here builds, whether or not they write code.

Say what you want built. The work goes out to a coding harness, lands in a branch, and comes back as a pull request against a git server living in your own container. You read the diff. You decide if it merges. Nothing ships because a model felt sure of itself.

You are building in the cloud, on your own network — not renting space in someone else's. Bring whatever inference you already have: any provider, your own API keys, or models running on your own hardware. Mix them. The Orchestrator picks the lane per job — and your Host watches which choices actually worked and gets better at choosing.

What it costs to run
  • A branch, then a request
    Work happens off to the side and arrives as a pull request. Main moves when you move it.
  • Any model, your bill
    Any provider, your own keys, or local weights — your pick per role, changeable whenever.
  • Scoped, not trusted
    An agent gets the permissions its one job needs and nothing else. Scope is granted, never assumed.
  • It learns the patterns
    Which lane, which model, what it cost, whether it worked. Your Host keeps the score and uses it.

A git nobody scrapes

The repository lives inside your container. It is not indexed by an outside crawler, not scraped, and not training anything. When you publish to the community, you publish to other members under your own name — private by default, visible to no one until you decide. The finished thing is what you share; the recipe stays where you built it.

What it won't do

It won't merge its own work. A harness opens the request; main moves when you move it. Confidence isn't a merge signal here — your review is.

The Annex

Attached to your server. Its own entrance. No door back in.

An annex is a building on the same property with its own public entrance. Your published site runs in one: a separate cluster, reached only from outside, with no path into your private server. Traffic comes in the front and stops there — enforced, not promised.

So the loop closes. A prompt becomes an app; the app becomes something you can charge for; and the platform around a live site — hosting, database, auth, billing — is a flat $20 a month, with nobody standing between you and the customer.

Site pricing

Publish without going public

A site ships private by default. Flip it when you're ready — private preview, members only, paywalled, or open. Your Host publishes to the preview tier and leaves the flip to you; going live is a toggle, not a migration.

A real backend, and real customers

Your site gets its own PostgreSQL database, injected as a connection string, reachable through exactly one opening in an otherwise closed wall. Backups run to object storage; restores are tested. Member pools and a paywall wire to your own Stripe account, and your customers pay you directly.

The money never touches us — and the Annex holds no key that could move it. It can verify a signature; that is the extent of its authority. Your list, your revenue, your Stripe.

  • Its own entrance
    Public traffic terminates in the Annex. No route back into your private network.
  • A real backend
    Own PostgreSQL through one opening in a closed wall. Backups to object storage, restores tested.
  • Your Stripe
    Customers pay you through your own account. We're never in that money path and take a cut of nothing.
  • The AI stays home
    Nothing in the Annex thinks. Anything generative happens on your Host and arrives as signed content.
What it won't do

It doesn't send bulk email, and it won't answer your customers for you. Support lands in your Host's inbox; the reply is drafted where your data lives.

Rent the compute. Own everything else.

Get a Skema Host

From $30 a month, with $10 of compute credit at signup. Cancel refunds the unused time.

Skema Host — WebOS for Your Private Network