Get access
Opafra, run for you.
You keep the hosts. We run the control plane.
The hosted platform, operated by the team that built it, with roles, approval gates, secret managers and the audit log switched on from the first run.
- Nothing to install
- Opafra reaches your hosts over SSH with the credentials you already manage.
- We run the platform
- Hosting, scaling, backups and upgrades, handled by the team that built it.
- Governed from day one
- Roles, approval gates on protected environments, and an append-only audit log.
- Your data stays yours
- EU or US residency, and execution inside your own network when you need it.
Data in the EU or the US, your choice. Encrypted at rest and in transit. How the product is constrained
What you get
The Opafra platform, run for you.
Draft plans from a request, dry-run them on every host, gate them on protected environments and keep the record, while we handle provisioning, scaling, upgrades and security.
- Fully managed and operated
- Uptime, upgrades and backups are ours to worry about.
- Roles and time-boxed access
- Grants that expire on their own, so two hours of production is a fact on the record.
- Approval gates
- A run against a protected environment stops and waits for the person your environment names.
- Dry run on every host
- See what would change, per host, before anything does. Diff one run against the last.
- Append-only audit log
- Every request, dry run, approval and result, exportable when the auditor asks.
- Secret managers
- Vault and Infisical as providers. Opafra stores the reference, never the value.
- AI composer, your key or ours
- Describe the change and get a plan against your inventory. Bring your own model key.
- Customer-hosted execution
- Run the execution layer in your own network. Credentials never leave it.