Source code, container images, secrets and security events. The systems an auditor asks about first, kept where you can show them.
Forgejo
Git hosting, code review, issues, packages and CI in one service, run in Switzerland, the EU or your own datacentre, with CI runners on machines of their own.
Replaces GitHub, GitLab.com, Bitbucket
GitLab
Git repositories, merge requests, CI/CD pipelines and registries in one application, run on your own hardware or in Swiss and EU regions, with runners on machines you place.
Replaces GitHub Enterprise Cloud, GitLab.com, Azure DevOps
Harbor
A private container registry that scans and replicates your images and caches Docker Hub, run in Switzerland, the EU or your own datacentre.
Replaces Docker Hub, Amazon ECR, Azure Container Registry
OpenBao
Secrets, certificates and encryption keys for your applications, run on your own hardware or in a Pilae region, with the unseal keys held by you rather than by us.
Replaces HashiCorp Vault, HCP Vault Dedicated, AWS Secrets Manager
Wazuh
Security monitoring with an agent on every server and workstation: logs, file changes, vulnerabilities and configuration checks, analysed and kept in Switzerland, the EU or your own datacentre.
Replaces Splunk Enterprise Security, Microsoft Sentinel
NetBird
Access to internal systems over WireGuard, granted by the groups in your directory, with the control plane run in Switzerland, the EU or your own datacentre.
Replaces Tailscale, Zscaler Private Access, Cisco AnyConnect
GlitchTip
Error tracking and uptime monitoring that takes events from the Sentry SDKs, run in Switzerland, the EU or your own datacentre so stack traces and the user data in them stay with you.
Replaces Sentry, BugSnag
Choosing among the engineering and security apps
This group is what engineering and security teams run for themselves, and what an auditor asks about first. Forgejo and GitLab host source code: Forgejo is light and quick to operate, GitLab brings CI/CD and issue tracking in one larger system. Harbor stores container images and scans them for known vulnerabilities before they reach production. OpenBao keeps secrets, certificates and encryption keys out of configuration files, with the unseal keys held by you. Wazuh collects security events and flags the ones that need a person. NetBird gives people access to internal systems over WireGuard, granted by the groups in your directory, and GlitchTip catches application errors from the Sentry SDKs.
Teams usually start with source code and secrets, because that is where a leak costs most, then add Harbor once there is a pipeline to protect and Wazuh once there is an estate to watch.
All of it runs inside your perimeter, behind the same private network as the rest of your apps, with every change approved and recorded in the control plane.
Need an app that is not listed?
We scope any open-source app: what it needs, how we run it, what it costs.