Your work data on your own server
Bemmoly runs where you put it: a VM in your own cloud account, a server in your rack, or a network with no way out. Your records, files, backups and keys stay in places you own, and the app calls no one you have not configured.
Where everything lives
| What | Where |
|---|---|
| Records | Your Postgres 18: the one the installer runs next to the app, or your own. |
| Files and attachments | The server’s disk under /var/bemmoly/data, or an S3-compatible bucket you own. |
| Backups | The server’s disk under /var/bemmoly/backups, plus an S3-compatible bucket if you add one. |
| Keys | The .env file on your server. It decrypts stored credentials; backups never contain it. |
What leaves the server
- Nothing by default. There is no usage telemetry, and the daily check for new releases stays off until an admin turns it on in Settings › Updates.
- Email goes through the mail server you configure, and nowhere until you do.
- AI, from 0.4, talks only to the provider you connect, which can be a model on your own network. Until you connect one, nothing is sent.
- Metrics for your own Prometheus are off until you set a scrape token.
Controls that ship today
Backups you can trust
Daily at 02:00 by default, kept 7 days, 4 weeks and 3 months, checked as each is written and test-restored every week.
Encrypted off the machine
Backups sent to a bucket are encrypted with AES-256-GCM using a passphrase only your server holds.
Signed updates
Release images are signed; the updater verifies the signature before it installs anything.
Rollback for a week
Every update takes a backup first, rolls back by itself if the health check fails, and can be undone for 7 days.
An audit log
Who changed settings, modules and backups, and when, exportable as CSV.
Single sign-on
OIDC and SAML sign-in, and SCIM to keep people and groups in step with your directory.
No internet at all
built, untested offline
Every release has a bundle with the images, the installer, the Compose file and checksums.
Copy it to a machine that already has Docker and install with
--image-archive; later updates are uploaded the same way. The bundle is built for
each release but has not been tested on an offline network yet.
Self-hosting has the commands.
Reporting a security problem
Report vulnerabilities privately, as the security policy describes. The code is open, so anyone can read exactly what runs on your server.
Run it on your own server
On a fresh Linux VM with a domain pointing at it, one command installs Docker, Postgres, automatic HTTPS, nightly backups and the updater, then prints the address to open.
curl -fsSL https://get.bemmoly.com | sh