One command stands up

Two worlds · one binary

A public world and an anonymous one —

One install switch (VAYUOS_MODE) runs VayuPress as a public Clearnet Space or a fully anonymous, web-only Tor Space — each with its own database, its own identity, and nothing crossing between them. Flip the toggle above to preview each.

Content moves between worlds only through a checksummed, offline-movable vayupress migrate export|import bundle — accounts, mailboxes, PGP keys and chat IDs never cross. Read ADR-0141 →

Why it exists

You don't own your online presence today. You rent it — from five landlords.

A website builder for the site. WordPress and a dozen plugins for the blog. Google or Microsoft for the mail. An analytics vendor watching your readers. A SaaS dashboard tying it together — each its own bill, its own login, its own cloud you don't control. VayuPress is the opposite bet: your website, your blog, your mail, your analytics and your admin in one binary you run yourself — nothing phones home, nothing is rented, nothing can be taken away.

Own your content

A real website and a Ghost-class blog — block editor, whole-site themes, media, members, SEO — with every word in your own SQLite file. No SaaS, no export wall.

Own your communication

A native SMTP/IMAP/POP3 mail server with DKIM and automatic PGP is built into the binary — send and receive from your own domain, read it in the official app, no third-party relay.

Own your privacy

End-to-end PGP, encrypted keys at rest, and cookieless analytics with zero trackers and no PII on your readers. The only outbound calls are the ones you configure.

One command · the whole stack

Your domain. A website, a blog, encrypted mail — and an app in your pocket.

Point yourdomain.com at one VPS, run one install command, and VayuPress stands up your entire online presence — a business website, a blog, and a sovereign mail server with automatic PGP — each on its own subdomain, each with a free Let's Encrypt certificate issued and renewed for you. Then read and send that mail from the official VayuMail app on Android.

yourdomain.com

Business website

Eleven elegant templates — restaurant, shop, studio, clinic, school, portfolio and more. Edit every word from the admin, switch designs live.

blog.yourdomain.com

Your blog

The full publishing engine — Ghost-class editor, whole-site themes, members and analytics. Or keep the blog at the root; it's your call, and updates never change it.

mail.yourdomain.com

Encrypted mail

A DKIM-signing mail server with automatic end-to-end PGP — keys generated per mailbox, messages encrypted when the recipient's key is known.

VayuMail for Android

Official app

Connect a phone in seconds — open the app, enter your domain and sign in once. It provisions a per-device app password (never your real password, revocable any time) and configures IMAP & SMTP for you — no manual server settings. Read, write and send PGP-encrypted mail from your own domain, on the go.

Cookieless analytics and a single control panel (VayuOS) come with it — open source, zero telemetry, all on your own name. Nothing rented, nothing phoning home.

The Vayu suite

One binary. Ten products. Each one, world-class.

Not a bundle of plugins — a single Go process where publishing, mail, chat, bot defense and analytics are first-class citizens. Switch between them below. In the Tor world, VayuMail is webmail-only, VayuTalk is anonymous and rotatable, and VayuTor is already on — the same suite, hardened for anonymity.

Install · one click

Put VayuOS on your home screen. One click. No store. No download.

VayuOS is an installable app (PWA). Open your console and the browser offers Install VayuOS — it lands on your phone home screen or desktop as a standalone, full-screen app that launches instantly. There's an Install button in the console top bar too, so it's always one tap away.

  • Mobile & desktop. One-click install on Android and desktop Chromium; on iPhone/iPad, Share → Add to Home Screen.
  • Always live. A zero-cache worker means an installed VayuOS is never stale — every launch shows exactly what your server serves right now.
  • Sovereign by default. Same origin, same strict CSP, your own icon — nothing rented, with a tiny offline notice as the only fallback.

Turn it on · get paid

Your audience, your revenue — and your own payment keys.

A complete, redirect-based monetization suite is built in — no payment SDK is ever embedded, so your strict CSP stays intact. Take money through your own Stripe & PayPal keys, and audit every sale from one Monetization control centre in VayuOS.

Payments live in the Clearnet Space — the anonymous Tor world stays callback-free by design.

Your keys, your rails

Auto-renewing PayPal subscriptions and instant Stripe one-time checkout over a sovereign payments ledger — idempotent fulfilment, webhook receipts, nothing rented.

Or take crypto

Connect a self-hosted BTCPay Server and accept Bitcoin, Monero, Ethereum, and stablecoins — funds settle straight into your own wallet, no processor, no custody, no KYC, and it's the one rail an anonymous or Tor buyer can use.

Tiers & paywalls

Sell membership tiers that unlock member-only posts, or drop a per-post paywall on any single article — a one-time unlock, remembered per member.

Tiers become mailboxes

Each paid tier can provision a real VayuMail mailbox — its own quota, an auto PGP keypair + WKD, and VayuTalk — the moment a member joins.

Premium mail-ID market

Sell reserved and vanity addresses — bought → paid entitlement → the member claims it and sets a password — with operator approve/revoke and a terms-agreement trail.

Members advertise

A self-serve “Advertise here” panel takes a flat fee and drops each image ad into an operator moderation queue — nothing renders until you approve it.

One Orders ledger

Every paid section — subscriptions, premium IDs, paid posts, member ads — flows through a single auditable Orders ledger you can see end to end.

For studios & agencies

Host every client on one box — and hand each owner their own key.

One binary already runs a website, mail, analytics and the admin. It now runs them per domain: every registered domain gets its own website, its own certificate, its own branded mailboxes and its own visitor figures — and the person who owns that domain gets a login that reaches their site and nothing else. No second install, no per-client control panel, no new thing to operate.

one binary one modest VPS one SQLite file
studio.example your install · full VayuOS
client-one.com own website own certificate branded mail own visitors
client-two.co.uk own website own certificate branded mail own visitors
client-three.in own website own certificate branded mail own visitors

Every domain, its own website

Uploaded bundles live per domain, and the site mode, template and content moved into each domain's own record. Before this, one uploaded website served every registered domain — a studio could host exactly one client. The primary domain keeps its historic path, so an install that already deployed a bundle serves the same site after upgrading.

A login confined by refusal

A client is bound to exactly one domain and reaches only the pages explicitly declared for them; anything undeclared is refused. The old default was permissive, so a page added next year would have been reachable by every client with no diff that looked like a security change. A surface entry that declares no audience halts the process at start-up rather than quietly meaning something.

“My site” — the page they own

Their address, whether the connection is secured, whether mail is set up, what the site serves, and the one thing they can change: name, tagline, description and accent colours. Deliberately not an editor — the save and delete primitives are install-wide with no per-record ownership check, so “edit your own pages” would be selling a control the code cannot honour.

Their visitors, not everyone's

Thirty days of page views and their busiest pages, filtered by domain in SQL rather than fetched broadly and narrowed afterwards. Two clients who both published /about previously had their counts added together — not a missing feature but a wrong number, and another client's traffic shown as this one's.

Mailboxes you meter

Grant each domain a number of branded mailboxes; creation refuses at the cap. An allowance of 0 means none granted, never unlimited, and a domain that cannot be resolved fails closed — a limit that depends on a lookup succeeding is not a limit. Creation stays operator-only: mailboxes are made on request, by you. The allowance, the client's login and the handover are all set from the domain's own page — the only thing that needs a shell is the emergency override, deliberately.

Mail you can hand over

Once a mailbox is handed to its owner, six routes into it close and one remains — a command-line override that cannot run without writing a permanent record the client reads on their own page. The difference between an escape hatch and a back door is that both exist, and only one leaves a mark nobody can remove. You hand a mailbox over from its own card in the panel, by retyping the address: it is one-way, and nothing reverses it.

Six doors close

Each one is refused in the store or the engine, not in a handler — there are two handlers and a CLI above most of them, and a refusal in one is a refusal somebody routes around without meaning to.

Reading it from the panel. Every mailbox read now carries a typed authority, and an unset one is refused rather than assumed.

Your own console password over IMAP, POP3 and submission.

Resetting its password from the admin side. The holder's own recovery paths are untouched.

Turning off its second factor — reset, clear, sign in was the whole bypass.

Minting an app password for it — the quiet one. A credential reads the entire mailbox over IMAP with no record at all.

Pointing its mail elsewhere. Forwarding copies every future message without ever opening the box, and leaves the archive looking untouched.

One stays open, and it leaves a mark

A client locked out on a Friday still has to be helped. So the last door is not sealed — it is wired to an alarm that cannot be disconnected.

A command-line override resets the mailbox password from the host. It refuses to run if the record cannot be written first — a break-glass whose log is optional is an administrator reset with a louder name.

The entry is append-only and hash-chained in the database, the handover itself is one-way, and both are enforced by database triggers — a promise the party running the database can undo with one UPDATE is not a promise.

The client sees it on their own page, a notice goes to a recovery address outside this install, and a copy is filed into the mailbox itself. Every app password on the mailbox is revoked by the same reset.

That outside address is required before a mailbox can be handed over at all. Without one the notice could only be filed into the mailbox — where whoever used the override can delete it, which is the opposite of a record.

And what it deliberately is not

A business model built on a capability nobody has read the edges of is a business model that meets those edges in front of a client. These are the edges, in the same words the design record uses.

Not encryption.

The messages are readable files on a server you operate. Anyone with direct access to that machine, its database or a backup can still read them, and no ledger records that. Only encryption under a key the server does not hold would prevent it — that version is fully designed and deliberately unshipped, on business grounds rather than cryptographic ones: custody, key-loss rates over sixty clients, and no self-service export or import path yet.

One process, one box.

Row scoping is not a sandbox. A remote-code-execution bug reaches every client at once, and a hardware failure takes them all down together. Off-box encrypted backups with rehearsed restores are mandatory here, not optional. The DKIM signing key is one key, shared — deliverability is per-domain and correct, the key is not.

Metadata and routing stay yours.

Sender, recipient, subject, size and delivery logs remain visible regardless of handover. You own MX and address creation, so future mail can be redirected even where the existing archive cannot be opened. Handover is a bound on reading a mailbox, not on running the mail system.

Tamper-evident, not tamper-proof.

You own the database. Chaining the access record makes an edit show up; it does not make one impossible, and the product says so rather than implying otherwise. A record that could be quietly rewritten would be worse than none, because it would be believed.

The full design record — thirty-eight findings from three adversarial lenses, and why cryptographic sealing lost on the business rather than the mathematics — is ADR-0152.

The design contract

Built on a thesis, not a trend.

"Complexity that exists must be visible, bounded, and owned. VayuPress makes nothing disappear — it makes everything observable."

How it compares

What makes VayuPress different.

Most platforms bolt sovereignty, observability and governance on as plugins — or sell them as a hosted tier. VayuPress ships them in a single binary, with every byte of behaviour owned by the operator.

Measured on a live install you can open and re-test yourself — johal.in, running this binary with a quarter of a million posts on one small VPS that also serves a second domain and a full mail server.

Capability

Compares out-of-the-box, self-hosted defaults as of July 2026 — not what each platform can be made to do with enough work. Rows marked “Plugin” are achievable via third-party extensions; Substack is hosted-only and not self-hostable, so infrastructure rows read n/a. Corrections welcome on GitHub.

Companion tools

Bring your content with you. Leave anytime, too.

Ship in minutes

Four commands to a live server.

deploy.sh

Tip · go live with a domain

Point your domain at the VPS and run the installer — it provisions nginx and free Let's Encrypt certificates for your website, blog., and mail. hosts automatically. To add the real-time VayuTalk relay, point one extra record — talk.yourdomain.com → your server, CDN proxy off — and re-run the installer; it adds the certificate, vhost and app advertisement for you. Full steps in the installation guide.

Open source · forever

Built in the open. Owned by you.

Apache-2.0 licensed, dependency-light, documented to the decision level — VayuPress is for operators who refuse to rent their stack.

The licence will not change

VayuPress is Apache-2.0, permanently and unconditionally — not contingent on funding, adoption or acquisition. No reciprocal move, no source-available move, no dual licence, no open-core split. Free for individuals and large companies alike, deliberately: a licence that carves out the powerful still has a gatekeeper.

There is no paid tier and no feature held back. There is no Contributor Licence Agreement and there never will be one — so nobody, including the maintainer, can accumulate the rights needed to sell proprietary licences to this work.

And it does not ask you to trust that: every release already published is irrevocably Apache-2.0 as a completed legal fact, and if a future maintainer ever broke the pledge, forking the last Apache-2.0 release needs nobody's permission. The reasoning, and what structurally backs it.