New · Doxentriq is now open source — follow the road to 1.0 on GitHub →
OPEN SOURCE Self-hosted AI application platform · early access

Build business apps by chat. Ship only what's proven.

Doxentriq runs on your own server. Describe a change in plain language. Doxentriq writes the code in an isolated sandbox, tests and scans it, and shows you a live preview. Nothing is published until you approve that exact release.

  • Apache 2.0 licensed
  • Your VM, your data
  • Works with your OpenAI or Anthropic key

Built on proven open-source foundations

  • TypeScript
  • Go
  • React
  • Fastify
  • gVisor
  • MySQL
  • RabbitMQ
  • Redis
  • Keycloak
  • Caddy
  • Prometheus
  • Grafana
  • Loki
Why Doxentriq

AI can write the code.
Someone still has to trust it.

AI app builders are fast. But speed without control is a risk your company can't afford with real data and real users.

Your data, someone else's cloud

Hosted AI builders keep your applications, your databases and your business logic on their platform, under their terms.

Generated code is untrusted code

Model output can be wrong, vulnerable or simply surprising. It should never run with access to your servers or credentials.

"Looks good" is not a release process

Without tests, scans, a rehearsed migration and an approved artifact, every deploy is a gamble with your users' data.

Doxentriq puts a full, evidence-based release process between the AI model and your production apps. And it runs on hardware you control.

How it works
How it works

From a sentence to a verified release

Your administrators work in a chat. Doxentriq does the engineering work and collects the proof. You make the final decision.

01

Describe

Ask for a new app or a change the way you would brief a developer. Doxentriq asks follow-up questions when something is unclear and reads official documentation before planning integrations.

02

Build in a sandbox

Code is generated and built inside gVisor containers with no network, no Docker socket, no credentials and hard CPU, memory and disk limits.

03

Verify & preview

Eight mandatory stages produce the evidence: tests, security scans, image packaging and a database migration rehearsal. You also get a private live preview.

04

Approve & publish

Approve the exact artifact hash with MFA. Doxentriq publishes with health checks and keeps every release for safe rollback. Your data is preserved.

  1. 1 dependencies
  2. 2 build
  3. 3 application_tests
  4. 4 security
  5. 5 image_packaging
  6. 6 preview
  7. 7 migration_rehearsal
  8. 8 acceptance

Every release passes all eight stages. Only trusted platform services can issue the evidence. Generated code cannot certify itself.

Features

Everything between "we need an app" and "it's live"

A complete, self-hosted platform for building, verifying, publishing and running AI-generated business applications.

Chat-first development

Persistent conversations, clarifying questions and live progress. Work keeps running if you close the browser and resumes where it left off.

Evidence-gated releases

An outdated baseline, a changed artifact, an incompatible schema, an expired approval or any Medium-or-higher finding blocks publication.

Sandboxed generation

gVisor isolation, offline builds and hard disk quotas. Generated Dockerfiles never run. Validated output is packaged onto approved images pinned by digest.

Your models, your budget

Adapters for OpenAI and Anthropic, with economy, balanced and strong tiers. Budget is reserved before each request, caps are hard, and extra spending needs your approval.

Isolation per app

Each app gets its own MySQL database and user, Redis ACL, RabbitMQ vhost, network, TLS certificate and secrets mount.

Identity & MFA built in

OIDC through Keycloak, with TOTP and recovery codes, app-specific roles and single-use invitations. Microsoft and Google directory groups need owner and MFA activation.

Read-only connectors

Reach existing company files safely through Samba shares and approved filesystem sources. Access is scoped per app and read-only, behind isolated TLS adapters. Credentials never reach app code or chat.

Grounded integration research

Before planning an integration, Doxentriq retrieves official documentation from a reviewed catalog (Stripe, Microsoft, Google, Samba, eFactura and more) and keeps dated, hashed evidence.

Rollback & auto-recovery

Every release is kept. Roll back with independent checks, or pre-approve a one-time automatic recovery after repeated health failures. Code rollback preserves your data.

Encrypted, backed up

Everything sits on a LUKS2-encrypted volume, with an AES-256-GCM credential vault and encrypted MySQL. Nightly checkpoints and 15-minute incrementals are restore-tested.

Observability & host security

Prometheus, Grafana and Loki come preconfigured, with redacted logs, host and container telemetry and daily vulnerability reports for images and the running kernel.

App portal & hosted MCP

List public apps in a portal or share private login links. Apps can expose authenticated MCP endpoints, so AI assistants can use them with scoped tokens.

Generates node-web node-api node-worker node-mcp python-api applications on Node.js 24 and Python 3.13.

Security by design

Fail closed. Every time.

Doxentriq treats every model output as untrusted, and every missing proof blocks the release. If evidence is unavailable, the operation pauses with an actionable reason. It never fakes a result.

  • No network during build and test

    Fixed platform commands fetch dependencies through an approved-host proxy, without lifecycle scripts. Generated code then runs offline.

  • No host access

    Generated code never sees the Docker socket, a host shell or production credentials. Only the trusted Go broker talks to the container runtime.

  • No generated Dockerfiles

    A daemonless packager appends validated output to company-approved runtime images, pinned by digest and signature-verified.

  • Exact approvals

    Each approval is bound to artifact hashes and the current baseline. It expires and can be used once. A new verification makes older approvals invalid.

  • Secrets stay out of chat

    Credentials go into protected forms. Models only see redacted, app-specific context with logical aliases. Endpoints, secrets and business records are never included.

  • Unknown never counts as passed

    An unavailable scan, a stale feed or an uncertain outcome stays visible and blocks progress. It is never treated as a pass.

release-gate.jsonillustrative
{
  "release": "documents@14",
  "artifact": "sha256:9c1e4b…a07f",
  "baseline": "documents@13",
  "stages": {
    "build": "passed",
    "application_tests": "passed",
    "security": { "critical": 0, "high": 0, "medium": 0 },
    "migration_rehearsal": "additive",
    "acceptance": "passed"
  },
  "approval": {
    "mfa": true,
    "singleUse": true,
    "boundTo": "artifact+baseline"
  },
  "decision": "publishable"
}

Simplified example. Real evidence receipts are machine-readable and kept for every release. Every claim in the repository links to its receipt.

Reference application

Starts with documents

Doxentriq ships with a document-management reference app. It shows what a well-built generated application looks like, and it's the template the AI follows.

  • Single sign-on or local accounts, with read, search, write and admin roles enforced by the backend
  • Folders, uploads, metadata search and downloads
  • Immutable versions, restore and archive. Routine updates never physically delete data
  • Transactional audit trail and SHA-256 integrity checks
  • Read-only access to approved Samba shares
  • MCP endpoint, so AI assistants can search documents with scoped tokens
Explore the template
Architecture

One VM per customer. Clear trust boundaries.

Fifteen private core services on a single encrypted Linux VM. Only the trusted runtime can create containers, and generated code always runs inside the sandbox boundary.

PeopleWho uses it
AdministratorsReact admin · chat, releases, access Staff & customersApp portal · published apps AI assistantsAuthenticated MCP endpoints
Edge & identityTLS everywhere
CaddyTLS routing · health-checked switches KeycloakOIDC · PKCE · TOTP · app realms CertificatesRoute 53 · Google DNS · cPanel · private CA
Control planeDurable, resumable work
Control APIFastify · sessions · approvals · budgets WorkersLeases · outbox · per-app serialization OpenAI / AnthropicRedacted context only
Trusted runtimeWritten in Go
BrokerOnly holder of the container socket OCI packagerDaemonless · digest-pinned bases Private registryImmutable images Dependency proxyApproved hosts only ScannerImages · host · kernel
Sandbox boundarygVisor · untrusted code
Build & testOffline · quotas · read-only root PreviewsOne authenticated preview per app Published appsOwn DB, network, secrets, certificate Connector adaptersRead-only Samba / filesystem
Data & operationsOn an encrypted volume
MySQLTLS-only · encrypted tablespaces RabbitMQAMQPS · confirmed dispatch RedisTLS · ACLs Prometheus · Loki · GrafanaMetrics, logs, dashboards BackupsEncrypted · restore-verified
Trusted platform code Untrusted, sandboxed code External service you configure
Compare

Where Doxentriq fits

It's as easy to use as a hosted AI app builder, with the control of self-hosting and the release discipline of a professional engineering team.

Capability Doxentriq Hosted AI
app builders
Self-hosted
PaaS
Traditional custom
development
Build and change apps by chatting Yes Yes No No
Runs entirely on your own infrastructure Yes Usually not Yes Varies
Generated code built offline in a sandbox Yes Varies n/a n/a
Mandatory tests and security scans before publishing Built in Rarely Add-on Varies
Approval bound to the exact release artifact Yes Rarely Partial Varies
Choice of AI provider, with hard spending caps Yes No n/a n/a
Business records stay on your server* Yes No Yes Yes
Open-source codebase Yes Rarely Often No

* The AI provider you configure receives your chat messages and a redacted, app-specific context. Credentials, endpoints and business records are excluded. Columns describe typical offerings in each category, not any specific product.

Get started

Run it yourself

Try the administration interface locally in minutes. When you're ready for a server, the guided installer sets up a hardened, encrypted VM.

Server

One amd64 VM per customer. Minimum 4 vCPU and 16 GiB RAM; 8 vCPU and 32 GiB recommended.

Operating system

Debian 12/13 or Rocky Linux 9/10, with Docker and gVisor (set up by the installer).

DNS & TLS

Hostnames for admin, apps portal, identity and app subdomains. Certificates come from Route 53, Google Cloud DNS, cPanel/WHM or a private CA.

AI provider

Your own OpenAI or Anthropic API key, with spending limits you choose. Models are qualified before use.

bash · Node.js 24 LTS (22.19+ for local dev)
$ git clone https://github.com/andreitex/-doxentriq.git doxentriq
$ cd doxentriq && npm ci
$ AUTH_MODE=development PUBLIC_ORIGIN=http://127.0.0.1:5173 npm run dev
# in a second terminal
$ npm run dev:ui
# open http://127.0.0.1:5173 (development sign-in works only on loopback)

Early access. The full production acceptance plan hasn't passed yet. Use Doxentriq in test environments, and read the operations guide and the implementation status before you install on a customer system.

Project status

We publish the evidence, gaps included

Every claim in the repository is backed by a machine-readable receipt, and every gap is listed. Here's an honest snapshot of where Doxentriq stands today.

8mandatory release stages
15hardened core services
370+automated TypeScript & Go tests
0Medium+ findings allowed in a release

Verified on test infrastructure

  • Encrypted LUKS2/XFS foundation that survives reboots (Rocky Linux 10.2)
  • gVisor sandbox with no network, a read-only root and hard disk quotas
  • All 15 private core services healthy, with TLS between them
  • TLS-only, encrypted MySQL with isolated per-app grants
  • Encrypted point-in-time MySQL and document recovery into an isolated clone
  • Recovery from worker, Redis and RabbitMQ interruptions

In progress

  • Clean-install matrix on Debian 12/13 and Rocky Linux 9/10
  • Signed, scan-qualified company images
  • Live model qualification and end-to-end chat-to-publish acceptance
  • Customer SSO, Microsoft/Google consent and live invitations
  • Host kernel remediation workflow

Planned

  • Email, Stripe and eFactura runtime adapters
  • Webhook deduplication and safe external actions
  • Multi-epoch database migrations
  • Complete platform restore and off-VM recovery
  • Broader SDK and MCP qualification
Backed by FirstIT

Open source, with professionals behind it

Doxentriq is developed by FirstIT (Alttab Profit SRL), an IT consulting and software company in Bucharest with more than 20 years of experience. The software is free. When you want help, we're here.

  • Installation & hardening
  • Support & maintenance
  • Managed hosting
  • Custom development
  • Connectors & integrations
  • Security reviews
FAQ

Frequently asked questions

Is Doxentriq really free?

Yes. The source code is open under the Apache License 2.0, so you can use, modify and run it commercially. You pay only for your own server and for the AI usage your provider bills you. FirstIT offers optional paid services such as installation, support and custom development.

Can I use it in production today?

Not yet. Doxentriq is in early access. Many parts have passed on test infrastructure, but the full production acceptance plan (signed images, the complete operating-system matrix and live model qualification) is still in progress. The status section and the implementation status document list exactly what remains.

Which AI models does it support?

OpenAI (Responses API) and Anthropic Claude (Messages API), in economy, balanced and strong tiers. Every model must pass qualification before use. Qualification runs bounded evaluation requests within spending limits you set. The bundled catalog marks every model as unqualified until you do this.

Does my data leave my server?

Your applications, databases, documents and credentials stay on your VM. The AI provider you configure receives your chat messages and a redacted, app-specific context. Credentials, endpoints, secret references and business records are excluded. The software sends no telemetry to FirstIT.

What kind of applications can it build?

React and Node.js web apps, APIs, background workers, MCP servers and Python APIs. Examples include document management, internal tools, portals and dashboards. Connectors to existing systems are read-only today (Samba shares and approved filesystem sources). More adapters are on the roadmap.

How much does it cost to run?

You pay for a VM (minimum 4 vCPU and 16 GiB RAM) plus model usage. Before every request, Doxentriq reserves budget conservatively. It enforces persistent spending caps and asks for explicit approval before spending more.

What happens if a release breaks something?

Every published release is kept. You can roll back with independent checks, and code rollback preserves your database and documents. When you publish, you can also pre-approve a one-time automatic recovery to the previous release after three measured health failures.

How can I contribute or report a vulnerability?

Star the project, open issues and send pull requests on GitHub. Please report security vulnerabilities privately to office@firstit.ro, not in public issues.

Own the software your AI builds

Star Doxentriq on GitHub, try it locally and follow the road to 1.0.