Your host. Your data. Nothing leaves the building.
FFS ships as sealed container images that run entirely on hardware you control. There’s no vendor cloud in the data path, no telemetry, no license phone-home, and no “anonymous usage statistics.” If you unplug the internet, FFS keeps working.
Sealed images, clean installs, versioned releases.
Sealed delivery
You receive sealed, versioned images and a minimal install. No source tree, no build step, no external package installs on your host.
Clean-install provisioning
Fresh signing keys, encryption material, and audit chain are generated at install on your hardware. Your deployment’s secrets never exist anywhere else.
Versioned releases
Fixes and features arrive as versioned image releases with a manifest of exact digests. Every deployment is reproducible; nothing is ever live-patched on your host.
Self-contained stack
Everything FFS needs ships and runs together on one machine, including backup and recovery. There’s nothing to assemble and nothing to subscribe to.
Your identity, your keys
Bring your own identity provider (SAML/SCIM) and your own key-management provider for PII encryption. FFS integrates; it doesn’t take custody.
Operator-sized
One host and a documented runbook set, designed so your IT team can run it without giving a vendor standing access.
Why this matters to your reviewers
Every question that starts with “where does the data go?” has the same answer: it doesn’t. The system, the documents, the audit trail, and the keys live on your host, under your controls, inside your perimeter.
Have your infrastructure team join the demo.
We’ll walk the deployment model end to end.
Request a demo