Your data, someone else's cloud
Hosted AI builders keep your applications, your databases and your business logic on their platform, under their terms.
Doxentriq runs on your own server. Describe a change in plain language. Doxentriq writes the code in an isolated sandbox, tests and scans it, and shows you a live preview. Nothing is published until you approve that exact release.
002_project_code.sql, a search filter and an upload field. Existing documents are preserved.Built on proven open-source foundations
AI app builders are fast. But speed without control is a risk your company can't afford with real data and real users.
Hosted AI builders keep your applications, your databases and your business logic on their platform, under their terms.
Model output can be wrong, vulnerable or simply surprising. It should never run with access to your servers or credentials.
Without tests, scans, a rehearsed migration and an approved artifact, every deploy is a gamble with your users' data.
Doxentriq puts a full, evidence-based release process between the AI model and your production apps. And it runs on hardware you control.
How it worksYour administrators work in a chat. Doxentriq does the engineering work and collects the proof. You make the final decision.
Ask for a new app or a change the way you would brief a developer. Doxentriq asks follow-up questions when something is unclear and reads official documentation before planning integrations.
Code is generated and built inside gVisor containers with no network, no Docker socket, no credentials and hard CPU, memory and disk limits.
Eight mandatory stages produce the evidence: tests, security scans, image packaging and a database migration rehearsal. You also get a private live preview.
Approve the exact artifact hash with MFA. Doxentriq publishes with health checks and keeps every release for safe rollback. Your data is preserved.
Every release passes all eight stages. Only trusted platform services can issue the evidence. Generated code cannot certify itself.
A complete, self-hosted platform for building, verifying, publishing and running AI-generated business applications.
Persistent conversations, clarifying questions and live progress. Work keeps running if you close the browser and resumes where it left off.
An outdated baseline, a changed artifact, an incompatible schema, an expired approval or any Medium-or-higher finding blocks publication.
gVisor isolation, offline builds and hard disk quotas. Generated Dockerfiles never run. Validated output is packaged onto approved images pinned by digest.
Adapters for OpenAI and Anthropic, with economy, balanced and strong tiers. Budget is reserved before each request, caps are hard, and extra spending needs your approval.
Each app gets its own MySQL database and user, Redis ACL, RabbitMQ vhost, network, TLS certificate and secrets mount.
OIDC through Keycloak, with TOTP and recovery codes, app-specific roles and single-use invitations. Microsoft and Google directory groups need owner and MFA activation.
Reach existing company files safely through Samba shares and approved filesystem sources. Access is scoped per app and read-only, behind isolated TLS adapters. Credentials never reach app code or chat.
Before planning an integration, Doxentriq retrieves official documentation from a reviewed catalog (Stripe, Microsoft, Google, Samba, eFactura and more) and keeps dated, hashed evidence.
Every release is kept. Roll back with independent checks, or pre-approve a one-time automatic recovery after repeated health failures. Code rollback preserves your data.
Everything sits on a LUKS2-encrypted volume, with an AES-256-GCM credential vault and encrypted MySQL. Nightly checkpoints and 15-minute incrementals are restore-tested.
Prometheus, Grafana and Loki come preconfigured, with redacted logs, host and container telemetry and daily vulnerability reports for images and the running kernel.
List public apps in a portal or share private login links. Apps can expose authenticated MCP endpoints, so AI assistants can use them with scoped tokens.
Generates node-web node-api node-worker node-mcp python-api applications on Node.js 24 and Python 3.13.
Doxentriq treats every model output as untrusted, and every missing proof blocks the release. If evidence is unavailable, the operation pauses with an actionable reason. It never fakes a result.
Fixed platform commands fetch dependencies through an approved-host proxy, without lifecycle scripts. Generated code then runs offline.
Generated code never sees the Docker socket, a host shell or production credentials. Only the trusted Go broker talks to the container runtime.
A daemonless packager appends validated output to company-approved runtime images, pinned by digest and signature-verified.
Each approval is bound to artifact hashes and the current baseline. It expires and can be used once. A new verification makes older approvals invalid.
Credentials go into protected forms. Models only see redacted, app-specific context with logical aliases. Endpoints, secrets and business records are never included.
An unavailable scan, a stale feed or an uncertain outcome stays visible and blocks progress. It is never treated as a pass.
{
"release": "documents@14",
"artifact": "sha256:9c1e4b…a07f",
"baseline": "documents@13",
"stages": {
"build": "passed",
"application_tests": "passed",
"security": { "critical": 0, "high": 0, "medium": 0 },
"migration_rehearsal": "additive",
"acceptance": "passed"
},
"approval": {
"mfa": true,
"singleUse": true,
"boundTo": "artifact+baseline"
},
"decision": "publishable"
}
Simplified example. Real evidence receipts are machine-readable and kept for every release. Every claim in the repository links to its receipt.
Doxentriq ships with a document-management reference app. It shows what a well-built generated application looks like, and it's the template the AI follows.
read, search, write and admin roles enforced by the backend| Document | Version | Status |
|---|---|---|
| Supply agreement 2026.pdf | v4 | Current |
| Annex B pricing.xlsx | v2 | Current |
| \\fileserver\contracts | — | Read-only share |
| Offer draft.docx | v7 | Archived |
Fifteen private core services on a single encrypted Linux VM. Only the trusted runtime can create containers, and generated code always runs inside the sandbox boundary.
It's as easy to use as a hosted AI app builder, with the control of self-hosting and the release discipline of a professional engineering team.
| Capability | Doxentriq | Hosted AI app builders |
Self-hosted PaaS |
Traditional custom development |
|---|---|---|---|---|
| Build and change apps by chatting | Yes | Yes | No | No |
| Runs entirely on your own infrastructure | Yes | Usually not | Yes | Varies |
| Generated code built offline in a sandbox | Yes | Varies | n/a | n/a |
| Mandatory tests and security scans before publishing | Built in | Rarely | Add-on | Varies |
| Approval bound to the exact release artifact | Yes | Rarely | Partial | Varies |
| Choice of AI provider, with hard spending caps | Yes | No | n/a | n/a |
| Business records stay on your server* | Yes | No | Yes | Yes |
| Open-source codebase | Yes | Rarely | Often | No |
* The AI provider you configure receives your chat messages and a redacted, app-specific context. Credentials, endpoints and business records are excluded. Columns describe typical offerings in each category, not any specific product.
Try the administration interface locally in minutes. When you're ready for a server, the guided installer sets up a hardened, encrypted VM.
One amd64 VM per customer. Minimum 4 vCPU and 16 GiB RAM; 8 vCPU and 32 GiB recommended.
Debian 12/13 or Rocky Linux 9/10, with Docker and gVisor (set up by the installer).
Hostnames for admin, apps portal, identity and app subdomains. Certificates come from Route 53, Google Cloud DNS, cPanel/WHM or a private CA.
Your own OpenAI or Anthropic API key, with spending limits you choose. Models are qualified before use.
$ git clone https://github.com/andreitex/-doxentriq.git doxentriq
$ cd doxentriq && npm ci
$ AUTH_MODE=development PUBLIC_ORIGIN=http://127.0.0.1:5173 npm run dev
# in a second terminal
$ npm run dev:ui
# open http://127.0.0.1:5173 (development sign-in works only on loopback)
$ git clone https://github.com/andreitex/-doxentriq.git doxentriq && cd doxentriq
# review the model qualification cost plan (no charges)
$ npm run qualify:models -- --dry-run
# guided installer: encrypted storage, TLS, identity, services
$ sudo bash scripts/install.sh
$ npm run typecheck
$ npm test
$ npm run build
$ cd services/runtime && go test ./...
Early access. The full production acceptance plan hasn't passed yet. Use Doxentriq in test environments, and read the operations guide and the implementation status before you install on a customer system.
Every claim in the repository is backed by a machine-readable receipt, and every gap is listed. Here's an honest snapshot of where Doxentriq stands today.
Doxentriq is developed by FirstIT (Alttab Profit SRL), an IT consulting and software company in Bucharest with more than 20 years of experience. The software is free. When you want help, we're here.
Yes. The source code is open under the Apache License 2.0, so you can use, modify and run it commercially. You pay only for your own server and for the AI usage your provider bills you. FirstIT offers optional paid services such as installation, support and custom development.
Not yet. Doxentriq is in early access. Many parts have passed on test infrastructure, but the full production acceptance plan (signed images, the complete operating-system matrix and live model qualification) is still in progress. The status section and the implementation status document list exactly what remains.
OpenAI (Responses API) and Anthropic Claude (Messages API), in economy, balanced and strong tiers. Every model must pass qualification before use. Qualification runs bounded evaluation requests within spending limits you set. The bundled catalog marks every model as unqualified until you do this.
Your applications, databases, documents and credentials stay on your VM. The AI provider you configure receives your chat messages and a redacted, app-specific context. Credentials, endpoints, secret references and business records are excluded. The software sends no telemetry to FirstIT.
React and Node.js web apps, APIs, background workers, MCP servers and Python APIs. Examples include document management, internal tools, portals and dashboards. Connectors to existing systems are read-only today (Samba shares and approved filesystem sources). More adapters are on the roadmap.
You pay for a VM (minimum 4 vCPU and 16 GiB RAM) plus model usage. Before every request, Doxentriq reserves budget conservatively. It enforces persistent spending caps and asks for explicit approval before spending more.
Every published release is kept. You can roll back with independent checks, and code rollback preserves your database and documents. When you publish, you can also pre-approve a one-time automatic recovery to the previous release after three measured health failures.
Star the project, open issues and send pull requests on GitHub. Please report security vulnerabilities privately to office@firstit.ro, not in public issues.
Star Doxentriq on GitHub, try it locally and follow the road to 1.0.